Blog

Cobelens warns of digital disruption: what your vital organisation must record now

Former MIVD director Cobelens calls the Netherlands digitally vulnerable. What CSBN 2025 and the Cybersecurity Act mean for your risk analysis and incident control.

· By

Neatly bundled and labelled fibre-optic cables with an open risk-analysis binder in front, a tangled cable cluster behind, and a technician with a tablet.
Vital organisations must record per work process which risk analysis and controls were carried out before the Cybersecurity Act takes effect.Image: IamVera.ai — original editorial illustration

Treat digital resilience as a governance task, not just something for Defence: map your dependence on internet exchanges, data centres and cloud, carry out a systematic risk analysis and prepare for the Cybersecurity Act (NIS2), expected in the second quarter of 2026 for thousands of organisations still unprepared.

The occasion is a keynote by former MIVD director Pieter Cobelens for Cybersec Netherlands, of which Computable published a preview on 16 July 2026. In it, Cobelens argues that modern conflicts begin not with a shot but with an outage in digital infrastructure, and that the Netherlands, because of its heavily digitalised economy, is particularly vulnerable. In our assessment the core is not the threat itself, but the question of which controls you can demonstrate per work process.

What exactly does Cobelens mean by war that begins with an outage?

According to the preview in Computable, Cobelens contends that the Dutch economy rests on one digital foundation: internet exchanges, hyperscale data centres, logistics chains, financial services and cloud platforms. That cluster makes the country attractive to state actors and cybercriminals. His second point is at least as important: digital resilience, he says, is a shared responsibility of government, business and society, and not solely a task for Defence.

That shift from kinetics to disruption is not a stray opinion. DutchStartup.ai's summary of an advisory report by the Cyber Security Council concludes that the Dutch communications infrastructure is of high quality, but that its resilience is under increasing pressure. The AIVD, MIVD and NCTV see the nature of the threat shifting from pure espionage to active preparation for sabotage of critical infrastructure.

Which structural weaknesses does the Cybersecurity Assessment Netherlands 2025 confirm?

The Cybersecurity Assessment Netherlands 2025 by NCTV, AIVD and MIVD underpins Cobelens' warning with concrete findings. The key conclusions for executives:

  • The digital threat against the Netherlands is becoming more diverse and unpredictable, with an interwoven landscape of state actors, cybercrime and emerging technology.
  • Multiple incidents show that cybersecurity measures at many central-government organisations have been inadequate for some time.
  • Many organisations do not comply with the prescribed guidelines for information security.
  • This leads to a false sense of security: these organisations often cannot detect or mitigate attacks independently.

Dutch IT Leaders' summary of this assessment adds that the NCTV sees the threat becoming more complex due to geopolitics and rapid advances in generative AI, with attacks no longer isolated but increasingly interwoven. Those who want to manage unauthorised AI use within their own walls would do well first to gain visibility of unauthorised AI use in your organisation.

What changes with the Cybersecurity Act and NIS2 and who falls under it?

The Cybersecurity Act is the Dutch implementation of the NIS2 directive and is expected to enter into force in the second quarter of 2026, according to the interpretation of the CSBN summarised by Dutch IT Leaders. The act obliges a far broader group of organisations to carry out a systematic risk analysis and to adopt more stringent security measures.

How large the gap is emerges from a Jaarbeurs press release about Cybersec Netherlands: shortly before the introduction, 4,144 organisations had registered or were listed as affiliated, while an estimated 8,000 to 10,000 organisations fall under the act. In our assessment this means that a considerable proportion of vital organisations are not yet prepared for the mandatory risk analysis and the heavy security requirements. These figures come verbatim from the Jaarbeurs press release.

Which steps should the board, CISO and risk team record now?

The following steps translate the findings of Cobelens, the CSBN and the Cyber Security Council into a concrete governance agenda. This is our editorial ordering, not a statement from a source:

  1. Map your dependence on Dutch and cross-border digital infrastructure: internet exchanges, data centres, cloud platforms and logistics chains.
  2. Align your internal risk framework with the findings from the CSBN and with the obligations under the Cybersecurity Act and NIS2.
  3. Carry out a systematic risk analysis and record which measures follow from it and who owns them.
  4. Integrate AI-aware threat monitoring and rehearse incident handling, so that detection and response do not exist only on paper.
  5. Ensure that vital providers and government organisations can actually detect and respond to sophisticated disruptions.

For government organisations bringing generative AI into work processes, we have worked out this approach in an article on deploying GenAI safely in government per work process. The broader context can be found in our topic hub on AI security and digital resilience.

How do you demonstrate that controls were active per work process?

The CSBN identifies a false sense of security as a core problem: organisations believe they are protected but cannot detect attacks. In our assessment the answer to this is no longer technology alone, but evidence. You want to be able to show, per workflow, which systems, AI components and controls were active, which logs exist of executed risk analyses and incident handling, and how that aligns with the expectations from the CSBN and the Cybersecurity Act. How to build up and retain that evidence we describe under recording evidence and logging of executed controls.

A verification layer such as IamVera.ai can support this by making the digital-security posture visible per workflow: which steps, models and controls have been carried out and what evidence of that exists. Vera is not a chatbot and not its own language model, and does not replace security; it makes control possible and leaves the final judgement with the user. You still set up the mandatory measures, the risk analysis and the detection capability yourself. Where personal data enters the chain, the requirements of the GDPR continue to apply in full.

Sources and references

  1. Oorlog begint niet met een schot, maar met een storingComputable · 2026-07-16
  2. Duizenden organisaties nog niet klaar voor nieuwe cyberwet; vakbeurs Cybersec Netherlands in teken van digitale weerbaarheidJaarbeurs · 2026-09-01
  3. Cybersecuritybeeld Nederland 2025NCTV/AIVD/MIVD · 2025-11-26
  4. NCTV: cyberdreiging complexer door AI en geopolitiekDutch IT Leaders · 2025-11-26
  5. Rapport: Nederlandse communicatie-infrastructuur is goed maar onder drukDutchStartup.ai · 2026-07-09

Sources: The article draws on the Computable preview of Cobelens' keynote, the Cybersecurity Assessment Netherlands 2025 by NCTV/AIVD/MIVD, a Jaarbeurs press release on Cybersec Netherlands and an advisory report from the Cyber Security Council summarised by DutchStartup.ai.

← All articles in this topic ← All articles