All articles

9 min read

Cyberbeveiligingswet: what changes for Dutch entities on 15 August 2026

The Cbw and the Wwke were adopted on 7 July 2026 and take effect on 15 August. Registration with the NCSC, sectoral supervisors and CSIRTs, and what to finish before the date.

Read article
11 min read

NIS2 for managed service providers: in scope twice over

Why MSPs and MSSPs are named in Annex I, how customers reach them again through the supply chain measure, and the evidence pack that answers both.

Read article
11 min read

NIS2 business continuity and backup: what Article 21(2)(c) requires

Recovery objectives per service, a backup architecture that survives ransomware, restore evidence, and the crisis layer that collides with the reporting clock.

Read article
12 min read

How to prepare for a NIS2 audit: the evidence supervisors ask for

The supervisory powers behind an audit, the four-layer evidence pack, a four-week preparation plan, and the findings that keep repeating.

Read article
11 min read

NIS2 registration: which authority, what data, which deadline

The two registration duties, the data set each one needs, the jurisdiction rules for cross-border entities, and the two-week change notification rule.

Read article
11 min read

NIS2 director liability: what board members personally risk

NIS2 bestuurdersaansprakelijkheid uitgelegd: Article 20, Article 32(5), de Cyberbeveiligingswet, plus een 6-stappen due diligence checklist voor bestuurders.

Read article
10 min read

Inventory of critical assets: the NIS2 step most organisations skip

How to scope a service-aligned inventory, what fields it needs, and the starter template that beats an empty CMDB.

Read article
11 min read

Cybersecurity insurance post-NIS2: what underwriters now require

How 2026 cyber policies have changed, which exclusions appear in the fine print, and how to keep cover payable after an incident.

Read article
11 min read

MFA under Article 21: where NIS2 makes it mandatory and where it stays best-practice

Where MFA is mandatory under Article 21(2)(j), where it is still best-practice, and the rollout pitfalls that produce findings.

Read article
10 min read

Board training under Article 20: what NIS2 requires of directors

What the training must cover, how often it needs refreshing, and the evidence pack supervisors ask for first.

Read article
11 min read

Ransomware trends 2026: double extortion, RaaS, and the NIS2 reporting clock

What changed in ransomware through 2025-2026, the European-specific picture, and what NIS2 requires when you are hit.

Read article
12 min read

AI-powered cyberattacks in 2026: deepfakes, prompt injection, and autonomous malware

The 2026 attacker playbook runs on AI. How the three most important threat categories work, and how to defend under NIS2.

Read article
14 min read

NIS2 Article 21 explained: the 10 cybersecurity measures in plain English

Each measure in plain English, with evidence checklists and common pitfalls regulators look for.

Read article
11 min read

NIS2 enforcement update 2026: transposition, infringements, and what supervisors ask first

Four member states referred to the Court of Justice, no published fines, and what a supervisor asks for first.

Read article
12 min read

NIS2 compliance checklist 2026: a complete guide

Step-by-step guidance to achieve NIS2 compliance, from scoping to implementation.

Read article
10 min read

NIS2 vs ISO 27001: key differences and how they work together

Understand the relationship between these frameworks and use what you already have.

Read article
8 min read

NIS2 penalties explained: fines, management liability, and how to avoid them

Understand the financial and personal consequences of non-compliance.

Read article
10 min read

NIS2 supply chain security: how to audit your vendors

Practical framework for third-party risk assessment, supplier tiering, and contract clauses.

Read article
9 min read

NIS2 incident response: your 24/72-hour reporting playbook

Who to notify, when, and how to manage the three-stage reporting process.

Read article
10 min read

NIS2 vs DORA: what financial firms need to know

Understand the overlap and differences between EU's two major cybersecurity regulations.

Read article
8 min read

NIS2 for SMEs: which rules apply and how to start

Size thresholds, scope exceptions, and a practical 6-step starter path for smaller organizations.

Read article

Need help with NIS2?

Get expert guidance from a PECB Certified NIS2 Lead Implementer. Schedule your free compliance assessment today.

Get Your Free Assessment