AI Ethiek & Governance

The first month of the Cyberbeveiligingswet: Experiences with incident reporting to the NCSC

Geert Haisma

Since August 15, 2026, the Cyberbeveiligingswet (NIS2) has been in effect. As organizations must now report their first significant incidents within 24 hours, bottlenecks in qualifying threats are emerging. How can you streamline this reporting process?

The first month of the Cyberbeveiligingswet: Experiences with incident reporting to the NCSC

The enactment of the Cyberbeveiligingswet (Cbw) on August 15, 2026, marked a fundamental shift in the Dutch cybersecurity landscape. Now that we are well into September 2026, the practical reality for Chief Information Security Officers (CISOs) and directors is becoming apparent. While the initial registration in the National Entity Register was the first hurdle for many organizations, the current and structurally more complex challenge is the legally correct assessment and logging of security incidents.

The topic of incident reporting to the National Cyber Security Centre (NCSC) is high on the agenda this month because the legislator applies strict frameworks. The NCSC requires organizations to escalate their significant incidents as quickly as possible, and in any case within 24 hours. In practice, however, the exact definition of a significant incident proves to be a gray area.

The bottleneck: qualifying a significant incident

Not every phishing email or repelled DDoS attack triggers the 24-hour reporting obligation. The thresholds for an incident are laid down in ministerial regulations and can vary per sector. The legislator primarily looks at factors such as operational disruption of essential services and potential financial loss.

In this first month of enforcement, many organizations notice that they lack a watertight process to quickly translate technical events into a legal qualification. This introduces compliance risks. If organizations report too much, it creates unnecessary administrative burdens and unrest. If they report too little or too late, directors risk violating their duty of care. This last point directly touches upon director liability after the enactment of this law.

The role of an accurate internal incident register

To meet the tight 24-hour deadline, internal information provision must be in order. Supervisors expect directors to have a clear overview of all potential incidents. This also includes incidents that narrowly failed to trigger the reporting obligation, the so-called near-misses. An adequate internal incident register proves that your organization continuously and professionally weighs threats, even when no formal report follows.

Efficient compliance with IRMA

The translation of raw network data into a formal report does not have to be a manual process. PrudAI's Intelligent Risk Management Agent (IRMA) offers a structured solution for this. Our AI assistant helps classify threats based on current legal thresholds. IRMA structures the facts, links them directly to the correct policy rules, and prepares the necessary documentation. This leaves more time for actual crisis management.

Sources

Would you like to know how IRMA can support your organization in streamlining incident registration under the Cyberbeveiligingswet, and how you can safely unburden your management? Please contact our team for a personal demonstration.

AI in organizationsAutomationAgentic AI

Geert Haisma

Director

Geert Haisma is the co-founder and director of PrudAI, an AI specialist that supports organizations in securely and custom-deploying generative AI for improved decision-making and process automation. With a background in public administration and years of experience in making organizations more successful, Haisma is the driving force behind PrudAI's strategic and substantive direction.