On August 15, 2026, the Cyberbeveiligingswet (Cbw), the Dutch implementation of the European NIS2 directive, officially went into effect. Now that we have been operating under this new legal regime for exactly one month, its impact on the boardroom is becoming tangible. The focus on cybersecurity is rapidly shifting from the IT department directly to the executive table. The reason is simple: directors can now be held personally responsible and liable for shortcomings in cyber risk management.
Initial signals from the National Cyber Security Centre (NCSC) and other regulators make it abundantly clear that they will no longer settle for paper compliance; regulators are demanding active, demonstrable control from the board.
The new legal reality: duty of care and reporting obligations
Under the Cyberbeveiligingswet, two major obligations apply to entities in essential and important sectors: the duty of care and the reporting obligation. The duty of care requires organizations to conduct a structural risk assessment and continuously implement appropriate technical and organizational measures to secure their information systems.
If incidents occur and it becomes evident that this duty of care was neglected, the strict framework regarding NIS2 director liability in the Netherlands takes effect. In severe cases of gross negligence, directors of essential entities can face temporary suspension from their managerial duties and be held personally liable. It is no longer legally defensible to solely delegate cybersecurity to a CISO without proactive, verifiable executive oversight.
Moreover, this responsibility does not end at your own organizational borders. As we previously highlighted in our article on the necessity of NIS2 clauses in commercial contracts, the board is also held accountable for the digital security of the entire supply chain.
Demonstrably 'in control' with IRMA
The foundation of your defense against potential liability claims lies in your burden of proof. As a board, you must be able to demonstrate that you have made well-considered risk assessments, allocated adequate budget in a timely manner, and acted appropriately. This requires a robust, data-driven Governance, Risk & Compliance (GRC) foundation.
PrudAI's Intelligent Risk Management (IRMA) provides exactly the framework needed to deliver this evidentiary burden. IRMA enables organizations not only to identify risks but also to record mitigating measures structurally and verifiably. By smartly anchoring GRC processes, a watertight audit trail is created. This proves beyond doubt that cyber risks are periodically evaluated at the board level and that the organization consistently acts in accordance with Cbw requirements.
From reactive to proactive governance
The era of a reactive stance toward IT risks definitively ended with the formal introduction of the Cyberbeveiligingswet. The first month has shown that transitioning from paper policy to operational compliance is challenging, yet it remains the only viable path for mitigating legal risks at the executive level.
Would you like to know how you can manage director liability under NIS2 and structurally secure your duty of care using PrudAI's GRC solutions? Explore the possibilities through our AI Services or contact us directly for a confidential consultation with our experts.
