Cobelens warns of digital disruption: what your vital organisation must record now
Former MIVD director Cobelens calls the Netherlands digitally vulnerable. What CSBN 2025 and the Cybersecurity Act mean for your risk analysis and incident control.
You must now map your organisation's dependence on digital infrastructure, complete a systematic risk analysis aligned with the Cybersecurity Act, and document the controls you have deployed per workflow. The Act enters force in the second quarter of 2026, and thousands of vital organisations remain unprepared.
The prompt is an analysis of 14 September 2026 of digital resilience governance in the Netherlands, which argues that modern conflicts begin not with kinetic action but with outages in critical infrastructure, and that the Dutch economy, because of its heavy digitalisation, is particularly vulnerable to state actors and cybercriminals. A former MIVD director has warned that digital resilience is a shared responsibility of government, business and society, not solely a defence matter. In our assessment, the core obligation is not the threat itself, but your ability to demonstrate which controls you have put in place and what evidence of their execution exists per work process.
The Dutch communications infrastructure is of high quality, but its resilience is under increasing pressure. Internet exchanges, hyperscale data centres, logistics chains, financial services platforms and cloud services form a single digital foundation on which the Dutch economy rests. The AIVD, MIVD and NCTV have observed the nature of the threat shifting from pure espionage to active preparation for sabotage of critical infrastructure. Attacks are no longer isolated incidents but increasingly interwoven, and the threat is becoming more complex due to geopolitics and rapid advances in generative AI.
What does the Cybersecurity Act require you to do?
The Cybersecurity Act is the Dutch implementation of the NIS2 directive and is expected to enter into force in the second quarter of 2026. It obliges a far broader group of organisations than previous rules to carry out a systematic risk analysis and to adopt more stringent security measures. An estimated 8,000 to 10,000 organisations fall under the Act, yet shortly before its introduction only around 4,144 organisations had registered or were listed as affiliated. This gap suggests that a considerable proportion of vital organisations are not yet prepared for the mandatory risk analysis and the heavy security requirements.
Which failure modes should your risk analysis address?
The Cybersecurity Assessment Netherlands 2025, produced by NCTV, AIVD and MIVD, identifies the following categories of risk:
- Sabotage of critical infrastructure — deliberate disruption of internet exchanges, data centres and logistics chains that underpin the economy.
- Espionage and preparation for attack — reconnaissance and staging activities by state actors and cybercriminals targeting digital systems.
- Unauthorised AI use — deployment of generative AI within your organisation without visibility, control or risk analysis.
- False sense of security — belief that your organisation is protected when you cannot detect attacks or demonstrate control execution.
- Geopolitical escalation — increasing likelihood that attacks will be interwoven and coordinated rather than isolated.
What must you be able to demonstrate per workflow?
You must establish and retain evidence that the following controls have been carried out:
- Map your digital dependencies — identify which internet exchanges, data centres, cloud platforms and logistics chains your organisation relies on and document the risk each poses to your operations.
- Complete a systematic risk analysis — conduct a formal assessment of threats to your critical systems and document the methodology, findings and remediation steps you have taken.
- Record the systems and AI components in use — document which models, tools and controls are active in each workflow, the lawful basis for any data they process, and the risk analysis that justified their deployment.
- Establish logging of control execution — maintain records of which security measures were carried out, when, by whom, and what evidence exists that they were performed correctly.
- Prepare for incident detection and response — ensure you have the capability to detect unauthorised access or disruption and can demonstrate that your incident handling procedures have been tested and documented.
How should you approach evidence and visibility?
A false sense of security is a core problem identified by the Cybersecurity Assessment: organisations believe they are protected but cannot detect attacks or prove that controls have been executed. The answer is no longer technology alone, but evidence. You want to be able to show, per workflow, which systems, AI components and controls were active, which logs exist of executed risk analyses and incident handling, and how that aligns with the expectations from the CSBN and the Cybersecurity Act.
Where personal data enters the chain, the requirements of the GDPR continue to apply in full. Tooling can make your digital security posture visible per workflow and help you record which steps and controls have been carried out, but it cannot replace your own professional judgement. You still set up the mandatory measures, conduct the risk analysis and establish the detection capability yourself. The final decision on which controls to deploy and how to respond to incidents remains yours.
What is the timeline for compliance?
The Cybersecurity Act is expected to enter into force in the second quarter of 2026. If your organisation falls under the scope—which includes most vital organisations in energy, water, transport, health, digital infrastructure and other critical sectors—you must have completed your systematic risk analysis and implemented the required security measures by that date. The gap between the number of organisations that have registered and the estimated total that fall under the Act suggests that compliance planning should begin immediately if it has not already.
Sources: This article draws on reporting and guidance from Computable, Jaarbeurs, NCTV, AIVD, MIVD, Dutch IT Leaders and Dutchstartup.
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.