Compliance is one thing. Control is what really matters.

NIS2 Cyberbeveiligingswet Workshop

Cyberbeveiligingswet Workshop

On 15 August 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet) — the national implementation of the European NIS2 Directive — enters into force. From that date, more than 8,000 Dutch organisations will be expected to demonstrate that they understand their cyber risks and are taking structured action to reduce them. The Cybersecurity Act is not about ticking compliance boxes. It is about being able to show that your organisation is in control.

This does not mean your organisation must be fully compliant on 15 August. What regulators do expect from day one is that you know your risks, have set priorities, and can demonstrate structured progress. For many organisations, that is where the biggest challenge begins. Policies may be in place, but reality often tells a different story: dormant accounts, former employees with lingering access, overprivileged administrators, and service accounts running on years-old credentials. These identity risks are among the most common entry points for cyberattacks and the most visible findings during audits.

This workshop is designed to bridge the gap between policy and practice. It provides clear insight into your Identity & Access Management landscape, identifies the most important identity and access risks, and delivers practical recommendations to help strengthen your cyber resilience. Because in the end, the question is not whether you’re compliant. It’s whether you’re in control.

 

Why identity and access?

Preparing for the Dutch Cybersecurity Act (NIS2) requires organisations to assess risks across the ten security measures defined in Article 21.2, covering everything from incident response and supply chain security to cyber hygiene and access control. For many organisations, that can feel overwhelming.

At Booleans, we believe in doing one thing exceptionally well. We are specialists in Identity & Access Management (IAM), and that is exactly what this workshop focuses on.

Identity and access typically represent around 25% of a NIS2 risk assessment, but it is also the area where requirements are the most tangible, risks are the easiest to identify, and improvements deliver immediate value.

 

Why start with Identity & Access Management?

  • NIS2 explicitly addresses identity. While the directive is largely technology-neutral, it specifically refers to multi-factor authentication (MFA), continuous authentication, access control policies and asset management(Article 21.2). These are among the most concrete and measurable requirements.
    Identity is the foundation of cyber resilience. Most cyberattacks no longer begin by exploiting systems, but by compromising an identity. User accounts, privileged accounts, third-party access and non-human identities have become the primary attack surface.
  • IAM supports multiple NIS2 domains. Joiner, mover and leaver processes, least privilege, privileged access, supplier access, account lifecycle management and governance all contribute directly to meeting broader NIS2 requirements.
  • IAM delivers fast, measurable improvements. Dormant accounts, excessive privileges, shared administrator accounts and missing access reviews are among the most common audit findings. They are also some of the quickest and most impactful risks to address.

This workshop helps you identify those risks, understand their business impact, and define practical next steps. Because before you can demonstrate compliance, you first need to demonstrate control.

The workshop

In this half-day workshop, consisting of two parts, we guide your organization through the identity and access dimension of your NIS2 risk assessment.

Phase 1: Your operation through an identity lens

We map your daily operation and the role access plays in it: who (employees, administrators, suppliers, customers and machines) accesses which systems and data, and what happens when that access is granted too broadly, revoked too late, or taken over by an attacker. Using realistic attack scenarios, such as account takeover, privilege misuse and third-party access abuse, we identify where your organisation is exposed in terms of business continuity and public safety.

Phase 2: Your current IAM landscape

We review the components you use today to control access: authentication (including MFA coverage), the authorization model, privileged access management, account lifecycle and governance (IGA), and access for external parties. We compare current practices against modern security principles such as least privilege, zero trust, and phishing-resistant authentication to identify where there is room for improvement.

Deliverable

Booleans CEO Rob Ojevaar during a meeting

The workshop concludes with a report that maps your identity and access risk areas to the relevant NIS2 Article 21 categories, with prioritized recommendations. The report also includes a scoping overview: which NIS2 domains fall outside the workshop, so you know exactly what still needs to be covered elsewhere in your full risk assessment.

Ready to take control of your NIS2 identity risks?

Every organization’s NIS2 journey is different, but understanding your identity and access risks is one of the most impactful places to start. If you would like to gain a clear view of your current IAM maturity, identify the most important risks, and receive practical recommendations tailored to your organization, get in touch with the experts at Booleans. Together, we will help you build a strong foundation for your NIS2 roadmap and strengthen your cyber resilience where it matters most.

Let’s meet