Over NIS2 is veel geschreven, en het meeste daarvan is ruis: lange artikelcitaten, dreigende boetebedragen en checklists van honderd punten. Voor een bestuurder komt de richtlijn neer op drie vragen. Wie die kan beantwoorden, is verder dan de meeste organisaties.
Much has been written about NIS2, and most of it is noise: long quotations from articles, threatening fines and hundred-item checklists. For an executive, the directive comes down to three questions. If you can answer them, you are ahead of most organisations.
NIS2 raakt meer sectoren dan zijn voorganger: van energie, zorg en transport tot digitale diensten, productie en de publieke sector. Maar de belangrijkste uitbreiding is de keten. Ook als je organisatie zelf buiten de sectoren valt, kunnen klanten die er wél onder vallen eisen aan je stellen, omdat zij verantwoordelijk zijn voor de risico's van hun leveranciers. In de praktijk komt NIS2 dus vaak niet binnen via de wet, maar via een vragenlijst van je grootste klant.
NIS2 touches more sectors than its predecessor: from energy, healthcare and transport to digital services, manufacturing and the public sector. But the most important extension is the supply chain. Even if your organisation falls outside the sectors, clients who are in scope can impose requirements on you, because they are responsible for the risks of their suppliers. In practice, NIS2 often arrives not via the law but via a questionnaire from your biggest client.
De kern van NIS2 is een zorgplicht voor het bestuur: bestuurders moeten maatregelen goedkeuren, toezien op de uitvoering en zich er aantoonbaar in verdiepen. Dat laatste woord doet het werk. Een firewall hebben is niet hetzelfde als kunnen laten zien waarom juist déze maatregelen bij jouw risico's passen. Wie bij een incident of controle alleen een map met facturen van securityleveranciers kan overleggen, heeft een probleem. Wie een risicoanalyse, een besluit en een geoefend plan kan laten zien, niet.
The core of NIS2 is a duty of care for the board: directors must approve measures, oversee their implementation and demonstrably engage with them. That last word does the work. Having a firewall is not the same as being able to show why these particular measures fit your risks. If, during an incident or inspection, all you can produce is a folder of invoices from security vendors, you have a problem. If you can produce a risk analysis, a decision and an exercised plan, you do not.
NIS2 kent een meldplicht: een vroege waarschuwing binnen 24 uur na een significant incident. Die termijn is korter dan hij klinkt. In de eerste 24 uur van een echt incident is er chaos, onvolledige informatie en druk van alle kanten, precies het moment waarop je niet wilt uitzoeken wie er mag beslissen en wie de toezichthouder belt. De meldplicht is daarmee ongewild een uitstekende test: wie de eerste 24 uur kan draaien, heeft zijn crisisorganisatie op orde.
NIS2 includes a notification duty: an early warning within 24 hours of a significant incident. That deadline is shorter than it sounds. The first 24 hours of a real incident bring chaos, incomplete information and pressure from all sides, exactly the moment you do not want to be figuring out who may decide and who calls the regulator. The notification duty is thus, unintentionally, an excellent test: if you can run the first 24 hours, your crisis organisation is in order.
Niet bij de checklist. Begin bij een risicoanalyse die benoemt wat er bij jou nooit mag uitvallen of uitlekken, kies de maatregelen die daar aantoonbaar bij passen, en oefen het scenario dat je het meest vreest. Wie dat doet, ontdekt dat NIS2-naleving grotendeels vanzelf volgt, omdat de richtlijn uiteindelijk niets anders vraagt dan behoorlijk bestuur over een digitaal risico.
Not with the checklist. Start with a risk analysis that names what must never fail or leak in your organisation, choose the measures that demonstrably fit, and exercise the scenario you fear most. Do that, and you will find NIS2 compliance largely follows, because in the end the directive asks nothing more than proper governance of a digital risk.
Plan een vrijblijvende kennismaking van 30 minuten. Je krijgt geen verkooppraatje, wel drie concrete observaties over je huidige weerbaarheid.
Book a free 30-minute introduction. No sales pitch: you will leave with three concrete observations about your current resilience.