In practice
“Cyberattack? Don’t worry, our IT person will take care of it.”
For many entrepreneurs, that is still the first thought when it comes to cybersecurity. Understandably so, because firewalls, back-ups and passwords quickly feel like technical topics. But with the new cyber legislation, that is no longer the whole story.
Imagine this: you arrive at the office on Monday morning, open your computer and discover that nothing is working. No emails, no systems, no customer data. You call the IT department.
“Yes… we’ve been hacked.”
At that point, the question is no longer only how quickly IT can resolve the problem. The question is also whether the board knew what risks existed, whether sufficient measures had been taken, and whether it had been clearly recorded in advance who does what in the event of a cyber incident.
The legal point
That is precisely why 15 August 2026 is a date entrepreneurs cannot simply ignore. On that date, the Cybersecurity Act (Cbw), the Critical Entities Resilience Act (Wwke) and the Cybersecurity Decree (Cbb) entered into force. The names may sound technical, but the core message is simple: cyber resilience is also becoming a board-level responsibility.
Although cybersecurity may sound like something for the IT department, the message of this new legislation is clear: it also belongs on the boardroom agenda.
The urgency is real. International reports by the European Commission and supervisory authorities have long signalled that cyberattacks are increasing in both number and severity. Dutch businesses are affected as well: in 2020, 22% of large Dutch companies were victims of a cyberattack, and in 2021 the number of data breach notifications caused by cyberattacks increased by 88%.
What does this mean for entrepreneurs?
Cybersecurity is no longer solely an IT issue
The focus therefore shifts from technology to governance. Cybersecurity is not only about firewalls, passwords and back-ups, but also about continuity, decision-making and supervision. That is why the topic belongs not only with the IT specialist, but also with the entrepreneur and the board.
Perhaps more importantly, the board now has a more active role. A board member does not need to become a hacker or personally configure the firewall. However, the board must understand which cyber risks the business faces, which measures are being taken to address them and whether those measures actually work.
In other words: you do not need to know exactly how the server is technically secured, but you must be able to explain why the chosen security measures are sufficient. That suddenly makes cybersecurity a business governance issue.
“But we have antivirus software, don’t we?” Perhaps. But the question has become broader. What happens if a critical system fails? How great is the risk to business continuity? Who makes decisions during an incident? Are employees sufficiently trained? How are risks relating to suppliers and other third parties managed?
The Cybersecurity Decree further elaborates the duty of care.
This includes, among other things, risk management, incident handling, business continuity and crisis management, supply chain security, access management, cyber hygiene, training and cryptography.
That may sound like a long IT checklist. For an entrepreneur, it really comes down to another question: can we keep our business running if the digital part of it partially fails tomorrow?
And then there is the board member
The Cybersecurity Act expressly makes cybersecurity part of the board’s responsibility.
The relevant board members are also subject to a training obligation. They must have sufficient knowledge and skills to assess cyber risks and security measures. New board members have two years from their appointment to comply with this training obligation; existing board members have a comparable period from the date the legislation entered into force.
But attending a training course and then putting the certificate in a drawer is not the whole story. Board members are expected to be genuinely involved. They must approve measures, understand their substance and supervise their implementation and effectiveness. Cybersecurity therefore also becomes part of good governance.
Does this mean that you are now personally liable as a board member?
No, not automatically. The Cybersecurity Act does not introduce an entirely new regime for directors’ liability. Existing administrative-law and civil-law frameworks remain the point of departure. But that does not mean a board member can ignore the subject.
As cybersecurity is increasingly regarded as part of good governance, ignoring cyber risks may, under certain circumstances, have legal consequences.
The question is then no longer simply: “Do we have an IT department?”, but above all: “Has the board done enough to manage the cyber risks facing the business?”
So what needs to be done?
For entrepreneurs who fall within the scope of the new legislation, 15 August 2026 is not just another date. It is a starting point and a good moment to enter the boardroom and ask a few simple questions.
Which cyber risks do we face? What measures have we taken? Who supervises them? Are the board and employees sufficiently trained? And do we know what to do if something actually goes wrong?
Perhaps that is the most important change introduced by the new cyber legislation.
Cybersecurity is no longer only about whether someone can hack your systems. It is also about whether you, as an entrepreneur, can demonstrate that you have done everything that could reasonably be expected of you.
That is why now is the time not only to ask your IT specialist whether the systems are secure, but also to record within the board who is responsible, which measures have been taken, how incidents are reported and how it is checked whether the business is actually resilient.
Legally sharp – practical tip for entrepreneurs
Record who within your organisation is responsible for cyber resilience, which measures have been taken and how you will act in the event of an incident. This prevents cybersecurity from reaching the boardroom only after things have already gone wrong.