Government & open data
Informatiebeveiligingsdienst (IBD)
The Dutch municipal information security service (IBD) was founded in 2013 by all Dutch municipalities and is housed within VNG Realisatie. It advises and supports municipalities on information security and privacy, shares knowledge between municipalities, suppliers and other public bodies, and publishes knowledge products: guidance around the government information security baseline (BIO) and its successor BIO2, material on AI and algorithms such as an explanatory note for DPIAs and a playbook for AI incidents, a monthly monitor and events for the municipal CISO and privacy roles.
Go to the publisher’s websiteWhich products consult this source
BEVER — Direct consultation · Selected documents
The source is consulted directly while the work is being done. A selected set of documents from this source is included and searchable.
IRMA — Direct consultation
The source is consulted directly while the work is being done.
Availability depends on your organisation’s configuration and access rights.
What this source does not give you
The IBD is not a legal source, and since 15 August 2026 it is no longer the statutory CSIRT for municipalities either: the National Cyber Security Centre performs those tasks on behalf of the Ministry of the Interior. IBD products are aids without legal force; the norm itself sits in the baseline and in law and regulation, not in the guidance about it.
Frequently asked questions
- Is the IBD still the CERT for municipalities?
- Not in the statutory sense. Since 15 August 2026 the National Cyber Security Centre performs the statutory CSIRT tasks for municipalities on behalf of the Ministry of the Interior and Kingdom Relations. After that date the IBD remains the point of contact for municipalities on information security and privacy, supporting BIO2 implementation and publishing its knowledge products. Older documents describing the IBD as the municipal CERT are out of date on that point.
- Who are the IBD's products intended for?
- Primarily for municipalities and their IT partnerships: they founded the IBD themselves in 2013. Other organisations, including other municipal partnerships, can use the generic products. The audience-specific services, such as onboarding for new CISOs and privacy officers, are tailored to municipal practice.
- Can I use an IBD knowledge product as evidence that I comply with the BIO?
- No. The IBD's knowledge products help in interpreting and implementing the baseline, but they are not the baseline. An auditor or supervisor tests against the norm and against the law, not against the guidance. So use the material to substantiate choices and structure the implementation, and cite the baseline and the applicable regulation for the requirement itself.
- What is the IBD the right source for, then?
- For translating the norm into municipal practice. Think of products on roles and responsibilities for municipalities under the Dutch cybersecurity act, implementation material for BIO2, knowledge products on AI and algorithms, and the monthly monitor of current signals. That makes it a useful source for how an obligation plays out in municipalities, not for what the obligation precisely is.
- Why is security information listed among legal sources?
- Because information security in the public sector has largely become a legal obligation: the baseline, the privacy rules and cybersecurity legislation run together in questions about processing agreements, DPIAs, incident reporting and liability. The IBD supplies the context and the municipal practice around that. It makes no rulings on legal questions and has no supervisory or enforcement role.