The Dutch Cybersecurity Act puts identity at the core.
By Egbert Bremmer, Strategic Identity Solution Specialist
Increasingly, there are also concerns about digital fraud and large-scale data breaches. Threads are increasing as Ai lowers the bar for attackers to scale and sophisticate attacks. Due to increasing digitalization, organizational interdependence is also increasing. Being in control and working as safely as possible is of the highest priority. After all, the chain of suppliers and organizations is only as strong as its weakest link. A hack at a supplier can damage many collaborating organizations simultaneously.
Trends
AI and Cyberattacks
As today hackers use AI and launch attacks faster and easier than ever before, organizations must ask themselves the question: “Are we as an organization really in control when it comes to AI initiatives?”
Policies and processes surrounding AI are often still in a premature state. Within companies, experimentation and research are taking place exploring the possibilities of AI. This often occurs in a fragmented manner across various departments. Consider, for example, a marketing department investigating a chatbot for the website, software development developing its own agents, an IT department using a chatbot as a 24/7 helpdesk, and users utilizing LLMs such as ChatGPT or Copolitot.
Passenger instead of driver.
AI increases the urgency of proper identity management. This is not only because attackers use AI, but also because organizations themselves are increasingly deploying AI tools, agents, service accounts, and API connections. As a result, the number of non-human identities with access to systems and data is growing. Because the risk of disruption and errors is very high when relying entirely on AI to manage critical processes, human control remains important. Also known as ‘Human in the loop,’. This collaboration between human and machine is very powerful and ensures that humans remain the number one priority and that the machine operates as intended, serving instead of controlling humans. An example is when organizations want to take the next step to a higher level of maturity. Modern AI tools can help map out personas and roles to accelerate granting access. Humans remain in control, make the decisions, and ensure quality.
Legislation and state of affairs
Many are already familiar with Cyber the Dutch ‘Cybereveiligingswet’ (CBW), based on the European NIS 2 directive. The key pillars, duty of care, reporting obligation, and management liability, are a top priority for C-level management. Organizations are ambitious when it comes to increasing digital resilience. However, there remains a significant gap between this ambition and the implementation of plans. Knowledge and capacity are major bottlenecks in this regard. The aforementioned pillars are in effect as of August 15, 2026.
CBW and IAM
Identity and Access Management (IAM) is essential for the duty of care and reporting obligation. Organizations must not only secure access but also be able to demonstrate who had access, why that access was needed, when rights were changed, and whether access was revoked in a timely manner.
Since most cyber attacks begin with the theft of usernames and passwords, it is essential to strictly secure particularly, but not exclusively, privileged accounts (administrators and accounts with high privileges). In practice, this can be achieved by implementing privileged access management processes and software. Examples include continuous monitoring of administrator activities and the just-in-time principle for time-based granting and revocation of rights for administrative activities.
Earlier, we discussed the influence and risks of chain organizations. In this context, it is important that businesses are in control at all times so that only valid accounts are active and action can be taken immediately, should a partner or supply chain organization become involved in a cyberattack.
Because organizations have a reporting obligation, it is necessary to have insight at any given moment into who had access, when, and to which data. Watertight logging for authorization changes, login attempts, and data access must be available. Having solid processes and automating the starter, mover and leaver process are key to achieve this.
From obligation to business value
Although this law is mandatory, there are great opportunities for organizations. Good IAM yields more than compliance:
- Faster and error-free onboarding of employees and partners
- Fewer manual service desk tasks
- Lower risk in case of job change or departure
- Cost control and better insight into license usage
- Lower audit pressure
- More control over access within the chain
What do we observe in organizations?
Many Dutch organizations are already well on their way, having conducted a risk assessment and working on streamlining IAM processes. The next step in this requires organizational change. This involves a shift in knowledge and skills, IT ownership, and cross-departmental collaboration and processes.
The investment required for this in people and resources, and the pressure companies experience, often prevent them from taking the next step, or only take it partially. This creates a vicious cycle. Fires are put out when they arise. However, they do not truly gain ‘control’ and fail to achieve the benefits and opportunities regarding cost reduction, efficiency, and productivity.
Time for action!
From the Cybersecurity Act to concrete IAM actions
Every organization has a different starting point. The maturity level of Identity & Access Management varies significantly by sector, organization size, IT landscape, and degree of chain dependency. Therefore, it is important to, in addition to the risk analysis for the Cybersecurity Act, also to clearly understand your organization’s maturity on Identity.
What identities exist? Who has access to which systems and data? What is the risk profile? How are rights granted, modified, and revoked? And to what extent can the organization demonstrate that access management is actually under control?
My Dutch colleagues at Booleans helps organizations quickly and practically translate these questions into direction and decision-making with our Cybersecurity Act (NIS2) Workshop. We map out the current maturity level, key risks, and the desired state aligned to business goals. This leads to a clear vision, a concrete roadmap, and an initial plan with which organizations can take immediate steps.
Control Non-Human Identities
The rise of AI has caused the number of non-human identities in organizations to increase exponentially. The 90-day NHI governance sprint helps organizations map out which AI agents and tools are active in the landscape. We ensure that valid and active agents have a clear owner. From there, a ‘kill switch’ is implemented that ensures a threat from the chain or the organization itself can be immediately eliminated.
Starting point for digital strategy
The Dutch Cybersecurity Act does not call for yet another policy document, but for demonstrable control. IAM is a logical starting point in this regard: visible, measurable, and directly linked to risk, compliance, and operational efficiency.
Do you want to know where your organization stands?
Contact me if you have any questions, or request more information about our Cybersecurity Act (NIS2) Workshop.
Contact Egbert