This does not mean your organisation must be fully compliant on 15 August. What regulators do expect from day one is that you know your risks, have set priorities, and can demonstrate structured progress. For many organisations, that is where the biggest challenge begins. Policies may be in place, but reality often tells a different story: dormant accounts, former employees with lingering access, overprivileged administrators, and service accounts running on years-old credentials. These identity risks are among the most common entry points for cyberattacks and the most visible findings during audits.
This workshop is designed to bridge the gap between policy and practice. It provides clear insight into your Identity & Access Management landscape, identifies the most important identity and access risks, and delivers practical recommendations to help strengthen your cyber resilience. Because in the end, the question is not whether you’re compliant. It’s whether you’re in control.
Why identity and access?
Preparing for the Dutch Cybersecurity Act (NIS2) requires organisations to assess risks across the ten security measures defined in Article 21.2, covering everything from incident response and supply chain security to cyber hygiene and access control. For many organisations, that can feel overwhelming.
At Booleans, we believe in doing one thing exceptionally well. We are specialists in Identity & Access Management (IAM), and that is exactly what this workshop focuses on.
Identity and access typically represent around 25% of a NIS2 risk assessment, but it is also the area where requirements are the most tangible, risks are the easiest to identify, and improvements deliver immediate value.
Why start with Identity & Access Management?
- NIS2 explicitly addresses identity. While the directive is largely technology-neutral, it specifically refers to multi-factor authentication (MFA), continuous authentication, access control policies and asset management(Article 21.2). These are among the most concrete and measurable requirements.
Identity is the foundation of cyber resilience. Most cyberattacks no longer begin by exploiting systems, but by compromising an identity. User accounts, privileged accounts, third-party access and non-human identities have become the primary attack surface.
- IAM supports multiple NIS2 domains. Joiner, mover and leaver processes, least privilege, privileged access, supplier access, account lifecycle management and governance all contribute directly to meeting broader NIS2 requirements.
- IAM delivers fast, measurable improvements. Dormant accounts, excessive privileges, shared administrator accounts and missing access reviews are among the most common audit findings. They are also some of the quickest and most impactful risks to address.
This workshop helps you identify those risks, understand their business impact, and define practical next steps. Because before you can demonstrate compliance, you first need to demonstrate control.