Governance • responsibility • oversight

NIS2 for executive and supervisory boards

NIS2 brings cyber risk firmly into the boardroom. Executive directors approve measures and oversee implementation. Supervisory boards, advisory boards and audit committees use appropriate knowledge to ask focused questions, assess progress and support sound decision-making.

Roles and responsibilities

The same risks, with different governance roles

Executive and supervisory bodies look at the same material cyber risks, yet their responsibilities remain distinct. Executive directors set direction, allocate resources, approve measures and monitor implementation. Supervisory boards assess whether the executive board has organised this responsibility with sufficient quality, urgency and evidence.

An advisory board primarily acts as a sounding board. An audit committee can provide deeper attention to risk, control and assurance. The training makes these differences explicit and gives each role a practical set of questions.

Executive board and directors

Set risk appetite, approve measures, assign ownership and record decisions.

Supervisory board

Assess the risk picture, management information, assurance, progress and escalation.

Advisory board and audit committee

Strengthen the quality of dialogue, challenge and specialist preparation.

Cybersecurity as a board-level control process

Cybersecurity becomes a demonstrable management process

Technology remains important, while board-level control starts with critical services, protected interests and plausible disruption scenarios. From there, the organisation can decide which measures are proportionate, who owns them, how effectiveness is tested and when residual risk is accepted.

Useful reporting connects technical observations with business impact. It shows trends, exceptions, critical supplier dependencies, incident readiness, overdue decisions and the evidence supporting management's conclusion.

  • material cyber risks and residual risk;
  • critical processes, data, systems and supplier dependencies;
  • incidents, near misses and changes in the threat landscape;
  • progress, exceptions, effectiveness testing and assurance;
  • decisions, owners, deadlines and escalation.

Supervisory questions

Questions that support effective oversight

A supervisory board benefits from questions that reveal the quality of the underlying management process. What could materially disrupt the organisation? Which assumptions underpin the risk assessment? Which measures have been tested? Which suppliers can affect continuity? Which residual risks require explicit acceptance?

When information is incomplete, the next step is a clear request for analysis, evidence or a decision. This keeps supervision constructive and proportionate while maintaining momentum.

Risk picture

Are scenarios, impacts and dependencies current and connected to the organisation's objectives?

Effectiveness

Which tests, exercises, audits and assurance support the conclusion that measures work?

Follow-up

Which actions require a decision, additional resources or closer monitoring?

Choose the depth

A training route for each board objective

The Boardroom Briefing creates a shared foundation in approximately 90 minutes. The Boardroom Masterclass adds governance, risk assessment, reporting and cases. The in-company Boardroom Day applies that knowledge to the organisation and produces a board-level cyber risk profile. Advanced Training provides a deeper, multi-day learning route.

Each format can be delivered in English and aligned with the roles represented in the room.

Questions and answers

Frequently asked questions

Does the statutory NIS2 training duty apply to supervisory directors?

The specific training duty in the Dutch Cybersecurity Act applies to executive directors of essential and important entities. Supervisory directors still need sufficient knowledge to fulfil their own oversight role effectively.

What information should a supervisory board receive?

Reporting should connect material risks, critical processes, incidents, suppliers, progress, exceptions, effectiveness and decisions in a form that supports challenge and follow-up.

Can executive and supervisory boards attend together?

Yes. A joint session creates shared language while preserving the distinction between management, supervision, advice and assurance.

Can the session be delivered in English?

Yes. All boardroom formats are available in English for international and mixed-language boards.

Wouter Parent, NIS2 boardroom trainer and information security adviser

Trainer and adviser

Led by Wouter Parent

Wouter has worked in information security since 2009, with a focus on governance, risk, internal control, supplier assurance and incident management. He translates the legal framework into the decisions and information that boards genuinely need.

About Wouter and his approach

Board session

Discuss a NIS2 session for your board

We align the participants, governance context, learning objective and desired output before confirming the format.