NIS2 is not an IT project: why boards and senior management must take the lead

Cybersecurity is still too often regarded as a technical issue. Firewalls, backups, monitoring and access management are important, but under NIS2 this is no longer sufficient. The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw), through which the Netherlands is implementing NIS2 into national law, explicitly makes cyber resilience part of governance, risk management and oversight, as we discussed earlier in this series.
This means that NIS2 does not belong solely on the IT department’s desk. Boards and senior management must understand the cyber risks facing the organisation, which measures are required, and how it is determined whether those measures are actually effective.
Dat betekent dat NIS2 niet alleen op het bureau van IT thuishoort. Bestuur en directie moeten begrijpen welke cyberrisico’s de organisatie loopt, welke maatregelen nodig zijn en hoe wordt vastgesteld of deze maatregelen ook daadwerkelijk werken.

Cyber risk is organisational risk

A cyber incident rarely affects only the IT environment. The consequences can be felt across the entire organisation. Consider service disruption, loss of customer trust, contractual obligations, operational downtime, privacy risks, reputational damage and financial impact.

That is why NIS2 requires a broader approach. Cybersecurity must be linked to the organisation’s critical processes, services and dependencies. Which systems are essential for continuity? Which data is critical? Which suppliers have access to systems or information? And which incidents need to be escalated quickly?

What is expected of boards and senior management?

For organisations that fall within the scope of the Cbw, boards have explicit responsibilities for cyber risk management. Management bodies must approve the measures taken to manage cybersecurity risks, oversee their implementation and have sufficient knowledge to assess cyber risks and security measures. This does not mean that board members need to become technical specialists, but they must be able to ask the right questions and provide direction on risk, priorities and follow-up actions.

Not yet certain whether your organisation falls within the scope of the Cbw? The step-by-step approach outlined in the previous article is a logical starting point.

Relevant questions for boards and senior management include:

  • Do we know whether our organisation falls within the scope of the Cbw?
  • Which processes and systems are critical to our organisation?
  • Which cyber risks are we willing to accept and which are not?
  • Are responsibilities clearly assigned?
  • Do we receive regular reporting on cyber risks?
  • Can we identify, assess and report incidents in a timely manner?
  • Do we have visibility of risks relating to critical suppliers?
  • Is the follow-up of findings documented and evidenced appropriately?

Where do organisations often fall short?

Many organisations have already implemented cybersecurity measures. Yet governance alignment is often lacking: policies without an up-to-date risk assessment, technical measures without clear reporting to senior management or the board, or an incident procedure where it is unclear who should escalate an issue and when.

Supplier risks are also often only partially understood. Organisations may know who their suppliers are, but not always which suppliers are critical to continuity, what access they have, and which security requirements have been contractually agreed.

NIS2 specifically requires this alignment: governance, risk assessment, security measures, incident response, supplier management and reporting must all be connected.

Evidence and accountability are becoming more important

A key area of focus is demonstrability. Organisations must not only implement measures, but also be able to demonstrate that those measures are appropriate, are being followed and are reviewed periodically.

This requires clear documentation and decision-making. Who owns which risk? Which measures have been selected? On what basis were priorities determined? How is effectiveness tested? Which improvement actions remain open and how is follow-up monitored?

For boards and senior management, this means that NIS2 is not only a compliance issue, but also a matter of governance, direction and accountability.

A practical first step

A good starting point is a NIS2 boardroom session or governance review. This helps determine whether the organisation falls within scope, which governance responsibilities are relevant, and which actions are required to demonstrate effective cyber risk management.

The outcome does not need to be an extensive theoretical report. A practical list of priorities is often far more useful: what needs to be addressed first, who owns it, which risk is reduced, and what evidence is required?

Conclusion

NIS2 is not about more IT. It is about manageable, demonstrable and sustainable cyber resilience. IT plays an important role, but boards and senior management set the direction, establish priorities and determine risk appetite.

Organisations that take NIS2 seriously make cybersecurity part of regular decision-making. Not as a standalone project, but as a permanent element of governance, risk management and business continuity.

Forvis Mazars supports organisations through boardroom sessions, NIS2 readiness assessments, governance reviews and practical guidance in translating legal obligations into manageable measures.

 

Want to know more?