If we have selected the wrong experience for you, please change it above.
NIS2 is all about the security of our data and the resilience of our essential and important sectors. In the Netherlands, the European NIS2 Directive has been implemented through the Cyberbeveiligingswet (Cbw) and is supplemented with the Cyberbeveiligingsbesluit (Cbb), which have been in force since 15 August 2026. Sebastiaan ter Wee on cybersecurity compliance, the role of the Chief Information Security Officer and the need to build bridges. And, of course, about the importance of information security — for any party.
Sebastiaan ter Wee became an attorney-at-law in Brussels in 2009 and later in The Hague. In 2015, he became a corporate lawyer at Aegon, and in 2023, he left the company as Group Chief Privacy Officer and Head of Legal Digital. Since then, he has been a Partner in Digital Regulations at Deloitte. Sebastiaan lives with his wife and two daughters in Rotterdam.
Opens in new window
"To answer that question, we first need to look at an important difference between the European and American approach. I'm talking specifically about privacy versus security. In Europe, with the introduction of the General Data Protection Regulation (GDPR) in 2016, we have contributed to shaping the fundamental human right to the protection of privacy. In those first years following the introduction of the GDPR, lawyers were mainly responsible for its implementation, with data protection officers often taking on a compliance rather than a technical function.
As a result, the initial focus was on paper-based controls such as documentation of policies and processes, while less attention was paid to technical safeguards. Consequently, around 2021, we roughly found that this approach had led to two types of gaps. First, in practice, organizations lacked sufficient control over data and data management to be able to properly implement the GDPR and related legislation. Second, there was a disconnect between cybersecurity and the legal department - they spoke too little with each other. In practice, this meant that information security, data and its quality often received insufficient attention - even though the GDPR is, at its core, legislation that deals with the use of data and more specifically personal data."
"Correct. There, they focused less on privacy and instead much more on data protection. Attention was paid to unauthorized access and misuse of information. Companies were required to implement safeguards for data security and to invest heavily in technology. This created an entire sector dedicated to this, and the position of CISO automatically became a very difficult one. Over time, this also resulted in executives within the information security domain who came from a technical background: they matured quickly and with great responsibilities. But not necessarily executives who could also effectively communicate with the Board, Supervisory Board and Authorities."
"Despite their different starting points, both approaches ultimately struggled with a disconnect between the two functions. Privacy and legal teams and information security teams often saw themselves as having little in common, when in fact they needed to work closely together. There is no privacy without information security and no proper information security without good management and clear data. As this insight grew, information security for the purpose of GDPR compliance gained increasing importance."
"No privacy
without information security."
" In addition to the gap created by the lack of cooperation between legal and information security teams under the GDPR, it was already apparent that NIS1 was too soft, too limited in scope. With NIS2, the scope has been broadened; third-party risk management and individual liability for directors are now also ingrained in the law. In the Netherlands, these requirements have now been implemented through the Cyberbeveiligingswet (Cbw) and supplemented by the Cyberbeveiligingsbesluit (Cbb), which has been in force since 15 August 2026. And the latter in particular raises questions, if only out of self-interest of the directors: Do I have the right people and the right organisation in place to deal with the Cbw and Cbb? Is my own understanding and that of my board(s) to assess and challenge the risks as well as roadmap put forward by the CISO, is our CISO strong enough and capable of leading the change?
As previously mentioned, many CISOs have ended up in heavy managerial positions coming from a technology background. That is fine, but the position also requires serious managerial competencies: you have to be able to manage teams, conduct internal politics, and engage with regulators such as in the Netherlands, the State Inspectorate of Digital Infrastructure (RDI) or, in the case of financial institutions, the Dutch Central Bank (DNB) and the Dutch Authority for the Financial Markets (AFM). This therefore requires a broad profile, covering politics, technology, change, and governance. So directors' and officers' liability has contributed to directors taking a much more critical look at not only the qualities of the CISO, but also the cyber risk to the company and its risk management."
"As I already mentioned, a significant change that the NIS2 brings is the increased emphasis on directors' liability. Directors already had a responsibility for their task and bore general managerial responsibility, but in practice, the threshold for being held accountable was quite high. However, things are now changing; under the Cbw, directors have explicit responsibilities for cybersecurity risk management and must also receive
training in information security. Understanding the threat landscape and identifying the organization's major cybersecurity risks already requires a significant level of knowledge. But, directors must go further: they need to be able to assess whether the CISO is taking the right steps and whether the organization is making sufficient progress. Since directors are responsible for approving the information security policy, they must understand what they are approving, including the information security reporting needed to assess whether the policy is being effectively implemented.
Another important aspect of the Cbw is its overarching goal: protecting our critical infrastructure. The Netherlands is a highly open and interconnected society, with all the vulnerabilities that come with it. Over the past decades, we have not always been sufficiently aware of these risks. The scale of the Cbw reflects the urgency of the challenge: in the Netherlands, it is expected to apply to more than 8,000 organisations, the majority of which are SMEs of all shapes and sizes, each with its own risk profile. This means that a large and diverse group of organisations will need to make a serious effort to strengthen their information security. Europe still has significant ground to make up in this area. With the Cbw now in force, organisations need to translate these requirements into concrete measures, responsibilities and actions."
"My professional preference: a CISO with an understanding of technology. In many organisations, the CISO is part of the IT organisation. However, a Chief Technology Officer or IT Director often also has an innovation agenda. Innovation requires funding, but so does information security. Where these two diverge, they can come into conflict with each other. And then the question arises: is there still enough budget for the CISO and his information security agenda? Interestingly, over the years, security departments have come to realise that the legal department can help them to emphasise the importance of information security. After all, from a legal or risk perspective, there is a desire to protect data properly, regardless of whether that desire stems from the GDPR, the Cbw, the Critical Entities Resilience Directive (CER), the Cyber Resilience Act (CRA) or from a supervisory authority or shareholders. So, lawyers and IT professionals had to build bridges between them; the ‘alphas’ and the ‘betas’ had to learn to speak the same language. In other words: the lawyer must move to technology, and the technician must move towards better understanding and helping to implement the legal obligations. It is, by the way, exactly the reason why I joined Deloitte a year ago, to bridge that gap. I absolutely see these two functions as interdependent."
"Then you run the risk of non-compliance to begin with. But there is more to it. If no bridge is built between the law and daily practice, things will fall out of sync, and departments will begin pointing fingers at each other. This creates operational risks, but under the Cbw and Cbb, also liability risks for the boards. Of course, several disciplines are represented on most boards, the CEOs, CFOs, CIOs, General Counsel, etc. will often bear joint responsibility. And that's a good thing.
It is important to keep in mind that compliance is not only about the relevant cyber legislations but also strongly intersects with the for example the AI Act, Data Act and of course the GDPR. Companies and institutions are therefore working hard to build professional teams focused on data, information security and compliance with the related laws and regulations. Many of these organisations still have a long way to go. This is particularly challenging because the Cbw and Cbb covers organisations of all shapes and sizes, both regulation and “non-regulated”, and what may be manageable for a large organisation can be a significant undertaking for a smaller one. There is still a lack of familiarity with this increasingly complex domain, and setting up the necessary framework can come at significant cost."
"Lawyer and technician:
they are interdependent."
"I would like to say, particularly to lawyers: make sure you can think proactively and strategically. And don't just think solely from a legal perspective: this topic requires risk-based thinking, thinking at different levels of risk. And that is only possible if you are able to think along with your CISO on both a technical and operational level. In the end, you are allies and there needs to be a bridge between them."
In this episode, we will discuss what NIS2 means in the field of directors' liability. What can you do as a director and what do you have to do now? Lokke Moerel and Sebastiaan ter Wee will discuss this with each other under the guidance of Shay Danon.
Opens in new window