AI Ethiek & Governance

The NCSC Incident Register: Why You Must Log 'Near-Misses' Under the Cyberbeveiligingswet

Geert Haisma

With the Cbw in effect since August 15, 2026, CISOs are wrestling with the classification of security incidents. Discover why high-impact 'near-misses' belong in your internal register and how IRMA automates compliance.

The NCSC Incident Register: Why You Must Log 'Near-Misses' Under the Cyberbeveiligingswet

The Cyberbeveiligingswet (Cbw), the Dutch implementation of the NIS2 directive, officially came into effect on August 15, 2026. Now that the initial registration obligation in the national entity register is underway for many organizations, management teams are hitting the next complex hurdle: interpreting and logging security incidents correctly.

The search for a clear definition of a "significant incident" is dominating boardrooms. There is frequent confusion between the formal obligation to notify the National Cyber Security Centre (NCSC) and the requirement for meticulous internal documentation. It is critical to understand that not only successful breaches but also "near-misses" with high potential impact must be logged in your internal incident register.

When is an incident 'significant'?

Not every stopped phishing email triggers the 24-hour reporting requirement. The legal threshold for a significant incident primarily evaluates actual or potential impact:

  1. Operational disruption: The incident has caused, or has the potential to cause, a severe disruption to the essential services you provide.
  2. Financial and material loss: There is an actual or significant threat of heavy financial or material loss to your organization or third parties.

While a successful ransomware attack is obviously significant, a thwarted attack sits in a gray area. A standard threat blocked by your perimeter firewall is not an incident. But what if attackers breached a critical server via a zero-day vulnerability and were only halted by endpoint security milliseconds before data extraction or encryption? That is a textbook near-miss which, had it succeeded, would have caused maximum operational disruption.

Why your internal register requires near-misses

Under the extensive duty of care provisions of the Cbw, organizations must demonstrate that their risk management functions practically, not just on paper. While near-misses with realistic worst-case scenarios do not necessarily mandate an immediate 24-hour CSIRT notification (unless they qualify as an acute significant cyber threat), the regulator fully expects you to document them internally.

During an enforcement audit, regulators will scrutinize your internal incident log. Presenting a completely empty register in today's complex threat landscape is highly suspect; it typically points to defective detection rather than impenetrable security. Properly logging and analyzing these near-misses provides the hard evidence that your control measures work and that your organization actively learns from targeted threats.

Moving from manual logging to AI-driven GRC

For a Chief Information Security Officer (CISO), manually evaluating every detected threat against the complex legal framework of the Cbw is impossible. Security operations teams are often already overwhelmed by alert fatigue. They lack the capacity to write structured, compliance-grade risk classifications for every network event.

By deploying PrudAI's Intelligent Risk Management Agent (IRMA), you automate this labor-intensive translation process. IRMA continuously maps technical security logs to legal compliance requirements. The AI agent autonomously classifies events, accurately identifies when a near-miss meets the criteria of a potential significant threat, and logs it directly into your internal compliance register in the required executive formats. This ensures your documentation remains audit-ready 24/7, without burdening your operational teams.

Sources

Would you like to know how the IRMA solution can help your organization automate incident administration and proactively meet the documentation requirements of the Cyberbeveiligingswet? Contact our experts directly for an exploratory consultation.

AI in organizationsAutomationPrudAI

Geert Haisma

Director

Geert Haisma is the co-founder and director of PrudAI, an AI specialist that supports organizations in securely and custom-deploying generative AI for improved decision-making and process automation. With a background in public administration and years of experience in making organizations more successful, Haisma is the driving force behind PrudAI's strategic and substantive direction.