• Jump to main content
  • Jump to main navigation
  • Jump to footer
  • Newsletter
  • About us
  • Contact
  • Nederlands

Digital Government

For Caribbean and international professionals working on government digitalisation

Logo Rijksoverheid, to the homepage

Digital Government

  • Home
  • Topics
  • All News
  • Caribbean News
Home›Featured Stories›From threat to boardroom: how UWV tackles cybersecurity

From threat to boardroom: how UWV tackles cybersecurity

NIS2 Directive (Cyberbeveiligingswet, Cbw) 24 August 2026

From left to right: René Steenvoorden, Astrid Rosendahl, and Kees Halsema.

The Cyberbeveiligingswet (Cbw) focuses on managing risks, collaborating across the chain, and ensuring that leaders understand the landscape. For the Employee Insurance Agency (UWV), these topics are familiar. René Steenvoorden (Executive Board member), Astrid Rosendahl (Chief Information Security Officer, CISO), and Kees Halsema (head of the UWV Cyber Defence Centre, CDC) describe how this works in real-world situations.

To address digital risks, the 3 collaborate closely: Halsema’s team identifies threats, Rosendahl translates them into policy, measures, and advice, while Steenvoorden and the Executive Board weigh options and make decisions. According to Steenvoorden, this approach aligns well with the Cbw: “We face a vast number of threats, and with AI, these are becoming faster and more severe. This increases the urgency to act. For me, the essence lies in greater risk-driven decision-making, shared responsibility across the chain, and clearer role division within the organisation.”

For Rosendahl, the Cbw’s added value lies in helping organisations better understand their vulnerabilities and identify which systems, suppliers, and people are needed to structurally link cyber risks to executive decision-making. “As CISO, I wholeheartedly welcome the Cbw, as it places greater emphasis on the importance of risk management and digital resilience. It helps us get a grip on dependencies.” Halsema adds that the law improves internal collaboration: “It’s not just the responsibility of an administrator, policy team, or executive board; this collaborative triangle ensures risks are explicitly addressed.”

Leaders must understand the stakes

As of 15 August 2026, the Cbw is in force, imposing clearer cybersecurity responsibility on leaders. They must understand and weigh risks and fulfil a training obligation. Halsema notes: “Risk management is frequently handled in isolated departments. This law encourages us to consolidate it, making executive risks more transparent. There is no need for leaders to be security specialists, but they must understand the options on the table to make informed decisions.”

Steenvoorden brings extensive cybersecurity knowledge to UWV, including his experience as CIO at Rabobank. “Cybersecurity impacts decision-making. I look forward to engaging more leaders with deeper understanding of the subject. So, bring on the training.” Rosendahl highlights the advantages of informed leadership: “René asks meaningful questions that guide us to make correct decisions and stay focused. This shows that the topic remains important and relevant.”

Shared responsibility

This responsibility extends beyond individual organisations; the Cbw also introduces chain responsibility. Steenvoorden explains: “One of our core beliefs is that cybersecurity requires collaboration.” As an example, he cites the payroll tax chain involving the Tax and Customs Administration, UWV, and Statistics Netherlands (CBS): “All 3 of us are responsible for the security of that chain. It’s reassuring that we now align our cybersecurity efforts equally.”

Rosendahl adds that the Cbw helps improve supplier management: “Ultimately, security doesn’t just lie within UWV but also at the points of connection with our suppliers and subcontractors. This is crucial, especially when considering issues such as sovereignty.”

Steenvoorden expresses concerns regarding the supply chain: “Large organisations such as the Tax and Customs Administration and UWV have the appropriate personnel and resources. However, we often rely on smaller suppliers that may lack the time or capacity to invest in this area. A chain’s strength is only as strong as its weakest link.”

Anticipating threats

A weak link can have significant consequences. This is why the CDC takes a proactive approach towards threats and risks. Halsema explains: “We’ve flipped the script. If we wait until an incident occurs, it’s already too late. Our team monitors field activities, identifies relevant threats to UWV, and evaluates their likelihood. In common terms, we call this ‘shift left’: spotting risks early, rather than responding after the fact. We also focus on our most critical assets: the services that cannot fail. For UWV, this primarily means benefit payments. We translate these insights into risk analyses and present them to the CISO and the Executive Board so they can prioritise accordingly.”

Cybersecurity in practice

Planning for the future also requires preparing for potential failures. Steenvoorden draws on his experience: “We run crisis simulations, even with UWV’s senior management, which is vital. When a crisis occurs, there’s no time to learn the ropes. It’s rather like insurance: when everything is fine, you question the cost. But as a leader at Rabobank and Randstad, I’ve faced several major cyber crises. In those moments, it’s crucial not to have to figure things out on the spot. Who do you contact? And why?”

Beyond legislation, chains, and threats, it ultimately comes down to people. Halsema stresses: “Handling information securely must become part of daily work hygiene. It’s a ‘licence to operate.’” Steenvoorden adds: “With many issues, you might say, ‘Let’s write another report, think it over, or ask a third party for an opinion.’ But cybersecurity isn’t theoretical; it’s highly practical. While we’re writing reports, intruders are already in the house.”

Preparing for a crisis through exercises

Can you make the right decisions under pressure? How quickly can you restore affected processes after a crisis? The Ministry of the Interior and Kingdom Relations (BZK) is organising the eighth Government-Wide Cyber Exercise on 2 November 2026, enabling Dutch government bodies to strengthen their digital resilience together. For more information or to register for a webinar, visit www.weerbaredigitaleoverheid.nl.
This field is for validation purposes and should be left unchanged.
Was this page helpful?
Your feedback is greatly appreciated.

Share this post
  •  Share via email
  •  Share on X
  •  Share on LinkedIn

Sign up for our newsletter

Got a query, thought, comment, or suggestion?

If you're working on digitalising the government and got something on your mind, please share your thoughts with us.

  • Link DigiD Help Desk digid.nl/en/help
  • Link MijnOverheid / Message Box mijn.overheid.nl/about-mijnoverheid
  • Link eHerkenning Help Desk eherkenning.nl/en/contact
  • Link Message Box for Businesses english.rvo.nl/topics/contact/form

Digital Government

For Caribbean and international professionals working on government digitalisation

Stay Connected

  • Follow us on LinkedIn
  • Follow us on Mastodon
  • Follow us on X (Twitter)
  • Sign up to our Newsletter
  • Activate our RSS Feed

Nederlands

  • Deze site in het Nederlands

About this Website

  • About us
  • Contact
  • Archive
  • Copyright
  • Privacy Statement
  • Accessibility Statement
  • Report a Vulnerability
  • Sitemap