Sky NetworksWhat’s OnDuty of care without a deadline: what do you do when no one obliges you (yet)?

Duty of care without a deadline: what do you do when no one obliges you (yet)?

The European NIS2 directive has been in force since early 2023. In the Netherlands, its translation, the Cyber Security Act, is not expected until mid-2026. The bill is now before the Lower House, but formal obligations are still some time away.

Yet we see that many organisations, perhaps yours too, are already actively working on this. Not because they have to, but because it makes sense. The principles of NIS2 are valuable in their own right. And more and more organisations are aware that cybersecurity is not an afterthought, but an integral part of business operations.

A directive with strategic value
NIS2 requires organisations in sectors such as digital infrastructure, healthcare, energy, logistics and industry to take appropriate measures to protect network and information systems. At the same time, the guideline offers direction to other organisations that are not legally obliged but want to work on their digital resilience.

Central to NIS2 is risk-based working. Not every organisation has to do the same thing. As long as it is clear where the risks are and how to respond to them. This approach aligns well with existing standards such as ISO 27001 and offers room to do what suits your own situation.

Duty of care in practice
You probably already do much of what falls under this duty of care. The six components of NIS2 are recognisable and logical.

  • Conducting risk analyses
  • Taking appropriate security measures
  • Addressing supplier chain security
  • Board involvement
  • Setting up incident management
  • Employee training and awareness

What NIS2 adds is structure, consistency and the requirement to have everything demonstrably in order. This gives you grip and overview.

Looking ahead instead of waiting
Cyber threats do not wait until 2026. Incidents and data breaches are the order of the day. At the same time, demands from customers, partners and regulators are increasing. Looking ahead means not waiting for obligation, but working on what will be expected of you later.

Duty of care helps to have the conversation about digital dependencies. What is critical in your organisation? Where are there vulnerabilities? How to respond if things go wrong? And who takes responsibility?

This does not only affect IT. Management, operations and suppliers also play a role. That is why it is good to start working on this now or continuously improve.

A step-by-step approach works best
For organisations that have already taken steps or want to start, structure is important. First map out the risks, systems, dependencies and processes. Use that as the basis for improvement measures and regularly test whether they are still working.

Think not only about technology. Processes, behaviour, awareness and cooperation in the chain also determine your resilience. Cybersecurity does not live in a policy document, but in everyday practice.

And make sure the board is involved. NIS2 stresses that cybersecurity belongs at the strategic level. That requires clear responsibilities and sufficient knowledge. In many organisations, that means investing in awareness and leadership.

What it delivers
Working according to the principles of NIS2 means that you will

  • Gain better insight into digital risks and dependencies
  • Faster and more effective response to incidents
  • Reduce the risk of damage or disruption
  • Builds trust with customers and partners
  • Laying a solid foundation for further digitalisation

Thus, the duty of care does not become a burden, but an opportunity to strengthen the organisation.

To wit
The Cybersecurity Act is coming. But the digital risks are already here. This is the time to build your resilience. In a way that suits your ambitions, your sector and your risks.

The duty of care is not an end point. It is a valuable starting point. And you may already be further along than you think.

Want to spar about your next step. Let me know.

Peter Mesker

Estimated reading time: 4 minutes