On 15 August 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) entered into force. As a result, thousands of organisations in the Netherlands are now subject to new cybersecurity obligations. For companies operating in industry, high-tech and critical infrastructure, this means more than simply complying with new legislation. The greatest challenge lies in demonstrably managing cyber risks across both IT and OT environments.

At ICT Group, we see that many organisations are already taking steps towards regulatory compliance, but still lack sufficient insight into their current level of cyber resilience. This insight is precisely what provides the foundation for an effective cybersecurity strategy. The new legislation makes one thing clear: cyber resilience is no longer the responsibility of a single department, but an organisation-wide challenge involving management, operations, IT and OT.

New obligations require an integrated approach

The Cybersecurity Act is the Dutch implementation of the European NIS2 Directive and replaces the existing Network and Information Systems Security Act (Wet beveiliging netwerk- en informatiesystemen, Wbni). Organisations providing essential or important services will be subject to a number of requirements, including a registration obligation, a duty of care to implement appropriate security measures, an obligation to report significant incidents, and stricter requirements relating to management and supervision.

More information about the entry into force of the Cybersecurity Act can be found on the website of the Dutch National Cyber Security Centre (NCSC).

While these obligations are clearly defined, the greatest challenge lies in putting them into practice. Organisations must implement appropriate technical and organisational measures. This requires a risk-based approach to determine measures that are proportionate to the risks involved.

IT and OT deserve equal attention

For many industrial organisations, cybersecurity efforts still focus primarily on office IT. Process automation often receives considerably less attention, even though cybersecurity maturity in the OT domain is generally much lower than in IT.

The Cybersecurity Act makes no such distinction: it focuses on the security of the entire digital environment. This means that operational technology must also be an integral part of a resilient organisation.

In recent years, process automation systems within the OT domain have become increasingly connected to IT systems. While this brings many benefits, it also increases the attack surface across both IT and OT. In addition, many OT environments rely on systems that have operated reliably for decades but were never designed with today's cyber threats in mind.

As IT and OT environments have evolved organically and systems often remain in use for many years, many organisations lack an up-to-date and comprehensive overview of their infrastructure.

This is precisely why cyber resilience starts with visibility. What assets are present? How do systems communicate with one another? Where are the vulnerabilities, and what risks do they pose to production continuity? Without an up-to-date picture of the IT and OT environment, it is difficult to meet the duty of care required under the Cybersecurity Act.

From insight to action

The introduction of the Cybersecurity Act means that organisations need to reassess their cybersecurity approach. The first step is to determine whether the organisation falls within the scope of the new legislation. From there, a broader perspective on risks, processes and technology is required.

ICT Group supports organisations through an integrated approach that brings IT and OT together. Gaining visibility of assets, combined with a risk assessment, provides a solid starting point for strengthening cyber resilience. This foundation enables organisations to identify appropriate measures and priorities and develop a targeted roadmap that not only supports regulatory compliance, but also strengthens digital resilience in the long term.

Our approach

Our cybersecurity specialists combine many years of knowledge and experience in IT and OT environments with extensive cybersecurity expertise. We support organisations in areas including gaining visibility, providing advice, implementing security measures, maintaining cyber resilience and training employees.

Would you like to understand what the Cybersecurity Act means for your organisation, or how you can meet the new requirements? Contact one of ICT Group's cybersecurity specialists for a no-obligation discussion.



Would you like to know what the Cybersecurity Act means for your organisation or how you can meet the new requirements? Contact one of ICT Group’s cybersecurity specialists for a no-obligation discussion.

You may also be interested in?

Quick scan

Product OT Cybersecurity Maturity Quick-scan

Do you know how mature the cybersecurity of your OT environment really is? With our OT Cybersecurity Maturity Quick Scan, you can quickly gain insight into your strengths, risks and specific opportunities for improvement. This gives you a clear understanding of where you stand and which steps should take priority.
Read more

More information?

Please contact one of our experts
Kelvin Rorive

Kelvin Rorive

Chief Information Security Officer
+31 6 1270 0784
Sebastiaan Koning

Sebastiaan Koning

Business Consultant Cybersecurity
+31 (0)6 81349584
Merijn

Merijn Carmiggelt

Principal Security Consultant
+31 6 3110 9091