Deze marathon begint bij het bestuur.

Je hebt jouw startnummer ontvangen. De Cyberbeveiligingswet legt drie nieuwe verantwoordelijkheden bij bestuurders. Die kan niemand anders overnemen. Ontdek wat jij zelf moet weten, doen én kunnen aantonen.

First aid for NIS2

Free one-hour consultation

Always a dedicated consultant (coach)

Drie dingen die niemand kan overnemen

Training obligation

You take training on cyber risks yourself. This can't be delegated to your IT manager or your consultant.
01

Approval and oversight

The board approves the measures and oversees their implementation. Not in detail, but demonstrably.
02

Personal liability

This extends to everyone who actually makes the decisions. Even without a formal title in the Trade Register.
03

The key NIS2 questions

Three questions directors ask

In the video, Wouter answers three questions that matter to you as a director. So you know exactly where you stand.
  1. Moet je als bestuurder zelf maatregelen tegen risico's goedkeuren?
  2. Moet ieder bestuurslid een aparte training volgen?
  3. Al die meldtermijnen. Hoe regel ik dat? 

The steps you can take today

Download the NIS2 board onepager

Everything on one page

A complete overview on a single A4 sheet. Print it and take it to your board meeting.

Executive Training

Meeting the training obligation

How do you meet the training obligation? There are two ways to do so. You'll find more information below.

Veelgestelde vragen

Deze pagina gaat over jouw rol als bestuurder. De rest van het parcours staat op route A voor organisaties die direct onder de wet vallen, en op route B voor leveranciers.

What else does my organisation need to arrange?

Registration, the duty of care and the reporting obligation are very important. You'll find them explained on the page for organisations covered by NIS2.

Does every board member need to take the training, or is one enough?

It applies to everyone who actually has a say in how the organisation is run. In practice, that means the full board or management team, not a single delegate.

We don't fall directly under the law. Does this still apply to us?

The legal obligations don't, but your customers that are covered by NIS2 are responsible for cybersecurity across their entire supply chain. They will ask you for proof. What that means for you is explained on the page for suppliers.

We have an external CISO. Does that change anything?

For the implementation, yes. For your own training obligation, no. You can outsource the work, but not your responsibility or your training.

How do I comply with the NIS2 reporting obligation?

The easiest way is to draw up an incident reporting procedure. We're happy to help you with that, of course: you can download the free procedure here.

Fendix has helped 650+ companies, from startups to enterprises.

Grab a virtual coffee?

One hour.

Two cups of coffee

We go through the five questions the way a regulator would ask them, and you'll hear where you'd stand right now.
Kilian
Houthuijzen
Commercial Manager & Partner