
The Cyberbeveiligingswet (Cbw) focuses on managing risks, collaborating across the chain, and ensuring that leaders understand the landscape. For the Employee Insurance Agency (UWV), these topics are familiar. René Steenvoorden (Executive Board member), Astrid Rosendahl (Chief Information Security Officer, CISO), and Kees Halsema (head of the UWV Cyber Defence Centre, CDC) describe how this works in real-world situations.
To address digital risks, the 3 collaborate closely: Halsema’s team identifies threats, Rosendahl translates them into policy, measures, and advice, while Steenvoorden and the Executive Board weigh options and make decisions. According to Steenvoorden, this approach aligns well with the Cbw: “We face a vast number of threats, and with AI, these are becoming faster and more severe. This increases the urgency to act. For me, the essence lies in greater risk-driven decision-making, shared responsibility across the chain, and clearer role division within the organisation.”
For Rosendahl, the Cbw’s added value lies in helping organisations better understand their vulnerabilities and identify which systems, suppliers, and people are needed to structurally link cyber risks to executive decision-making. “As CISO, I wholeheartedly welcome the Cbw, as it places greater emphasis on the importance of risk management and digital resilience. It helps us get a grip on dependencies.” Halsema adds that the law improves internal collaboration: “It’s not just the responsibility of an administrator, policy team, or executive board; this collaborative triangle ensures risks are explicitly addressed.”
Leaders must understand the stakes
As of 15 August 2026, the Cbw is in force, imposing clearer cybersecurity responsibility on leaders. They must understand and weigh risks and fulfil a training obligation. Halsema notes: “Risk management is frequently handled in isolated departments. This law encourages us to consolidate it, making executive risks more transparent. There is no need for leaders to be security specialists, but they must understand the options on the table to make informed decisions.”
Steenvoorden brings extensive cybersecurity knowledge to UWV, including his experience as CIO at Rabobank. “Cybersecurity impacts decision-making. I look forward to engaging more leaders with deeper understanding of the subject. So, bring on the training.” Rosendahl highlights the advantages of informed leadership: “René asks meaningful questions that guide us to make correct decisions and stay focused. This shows that the topic remains important and relevant.”
Shared responsibility
This responsibility extends beyond individual organisations; the Cbw also introduces chain responsibility. Steenvoorden explains: “One of our core beliefs is that cybersecurity requires collaboration.” As an example, he cites the payroll tax chain involving the Tax and Customs Administration, UWV, and Statistics Netherlands (CBS): “All 3 of us are responsible for the security of that chain. It’s reassuring that we now align our cybersecurity efforts equally.”
Rosendahl adds that the Cbw helps improve supplier management: “Ultimately, security doesn’t just lie within UWV but also at the points of connection with our suppliers and subcontractors. This is crucial, especially when considering issues such as sovereignty.”
Steenvoorden expresses concerns regarding the supply chain: “Large organisations such as the Tax and Customs Administration and UWV have the appropriate personnel and resources. However, we often rely on smaller suppliers that may lack the time or capacity to invest in this area. A chain’s strength is only as strong as its weakest link.”
Anticipating threats
A weak link can have significant consequences. This is why the CDC takes a proactive approach towards threats and risks. Halsema explains: “We’ve flipped the script. If we wait until an incident occurs, it’s already too late. Our team monitors field activities, identifies relevant threats to UWV, and evaluates their likelihood. In common terms, we call this ‘shift left’: spotting risks early, rather than responding after the fact. We also focus on our most critical assets: the services that cannot fail. For UWV, this primarily means benefit payments. We translate these insights into risk analyses and present them to the CISO and the Executive Board so they can prioritise accordingly.”
Cybersecurity in practice
Planning for the future also requires preparing for potential failures. Steenvoorden draws on his experience: “We run crisis simulations, even with UWV’s senior management, which is vital. When a crisis occurs, there’s no time to learn the ropes. It’s rather like insurance: when everything is fine, you question the cost. But as a leader at Rabobank and Randstad, I’ve faced several major cyber crises. In those moments, it’s crucial not to have to figure things out on the spot. Who do you contact? And why?”
Beyond legislation, chains, and threats, it ultimately comes down to people. Halsema stresses: “Handling information securely must become part of daily work hygiene. It’s a ‘licence to operate.’” Steenvoorden adds: “With many issues, you might say, ‘Let’s write another report, think it over, or ask a third party for an opinion.’ But cybersecurity isn’t theoretical; it’s highly practical. While we’re writing reports, intruders are already in the house.”



