AI Ethiek & Governance

Director Liability One Month into the Cyberbeveiligingswet: Your Legal Duty of Care in Practice

Geert Haisma

Now that the Dutch Cyberbeveiligingswet (NIS2) has been in effect for a month, the focus around cybersecurity is definitively shifting to the boardroom. How do you prove you meet the duty of care and mitigate personal liability?

Director Liability One Month into the Cyberbeveiligingswet: Your Legal Duty of Care in Practice

On August 15, 2026, the Cyberbeveiligingswet (Cbw), the Dutch implementation of the European NIS2 directive, officially went into effect. Now that we have been operating under this new legal regime for exactly one month, its impact on the boardroom is becoming tangible. The focus on cybersecurity is rapidly shifting from the IT department directly to the executive table. The reason is simple: directors can now be held personally responsible and liable for shortcomings in cyber risk management.

Initial signals from the National Cyber Security Centre (NCSC) and other regulators make it abundantly clear that they will no longer settle for paper compliance; regulators are demanding active, demonstrable control from the board.

The new legal reality: duty of care and reporting obligations

Under the Cyberbeveiligingswet, two major obligations apply to entities in essential and important sectors: the duty of care and the reporting obligation. The duty of care requires organizations to conduct a structural risk assessment and continuously implement appropriate technical and organizational measures to secure their information systems.

If incidents occur and it becomes evident that this duty of care was neglected, the strict framework regarding NIS2 director liability in the Netherlands takes effect. In severe cases of gross negligence, directors of essential entities can face temporary suspension from their managerial duties and be held personally liable. It is no longer legally defensible to solely delegate cybersecurity to a CISO without proactive, verifiable executive oversight.

Moreover, this responsibility does not end at your own organizational borders. As we previously highlighted in our article on the necessity of NIS2 clauses in commercial contracts, the board is also held accountable for the digital security of the entire supply chain.

Demonstrably 'in control' with IRMA

The foundation of your defense against potential liability claims lies in your burden of proof. As a board, you must be able to demonstrate that you have made well-considered risk assessments, allocated adequate budget in a timely manner, and acted appropriately. This requires a robust, data-driven Governance, Risk & Compliance (GRC) foundation.

PrudAI's Intelligent Risk Management (IRMA) provides exactly the framework needed to deliver this evidentiary burden. IRMA enables organizations not only to identify risks but also to record mitigating measures structurally and verifiably. By smartly anchoring GRC processes, a watertight audit trail is created. This proves beyond doubt that cyber risks are periodically evaluated at the board level and that the organization consistently acts in accordance with Cbw requirements.

From reactive to proactive governance

The era of a reactive stance toward IT risks definitively ended with the formal introduction of the Cyberbeveiligingswet. The first month has shown that transitioning from paper policy to operational compliance is challenging, yet it remains the only viable path for mitigating legal risks at the executive level.

Would you like to know how you can manage director liability under NIS2 and structurally secure your duty of care using PrudAI's GRC solutions? Explore the possibilities through our AI Services or contact us directly for a confidential consultation with our experts.

PrudAIData PrivacyAI in organizations

Geert Haisma

Director

Geert Haisma is the co-founder and director of PrudAI, an AI specialist that supports organizations in securely and custom-deploying generative AI for improved decision-making and process automation. With a background in public administration and years of experience in making organizations more successful, Haisma is the driving force behind PrudAI's strategic and substantive direction.