Administrators, managers, and staff must be aware of digital threats. In addition, they must recognise their own roles, the risks and consequences of their actions, and the associated business risks. This knowledge enables (government) organisations to counter digital attacks and act securely.
Government-wide Cyber Programme
Since 2019, the annual Government-wide Cyber Exercise has been held. Participants in this exercise experience the complexity of a cyber crisis and learn how to respond. Throughout the year, the programme also shares knowledge on cybercrime through podcasts, webinars, and masterclasses. These activities are part of the Government-wide Cyber Programme, initiated by the Ministry of the Interior and Kingdom Relations (BZK) in collaboration with various government and knowledge partners.
Red teaming toolbox
The Dutch national government is an attractive target for malicious actors, as highlighted in the Cybersecurity Assessment of the Netherlands and the AIVD Annual Report. Strengthening its digital resilience is therefore a key policy priority. Red teaming, advanced security testing, enables organisations to enhance their digital resilience. Red teaming tests an organisation’s (or a chain of organisations’) security measures and supports learning from the process. There is no pass or fail; the focus is on improvement. The Red Teaming Toolkit (Dutch) provides 4 documents to guide organisations through every stage of testing, from selecting a test to procurement and execution.
Simulating crisis situations
By simulating crisis situations, the entire government becomes more aware of digital threats, individual roles and responsibilities, and the risks and consequences of its actions.
Organisations and key actors in these efforts include:
- Alert Online: An initiative that encourages and supports government, businesses, education, science, and consumers in the Netherlands to stimulate collaboration on cybersecurity and to act more safely. Alert Online peaks in October during the European Cybersecurity Month.
-
Veiliginternetten.nl: A joint initiative of the Ministry of Economic Affairs and Climate Policy (EZK), the Ministry of Justice and Security (JenV) /National Cyber Security Centre (NCSC), Platform for the Information Society (ECP), and the business community.
CIP support programme
To help organisations implement BIO2, the CIP has developed supporting documents, including a BIO self-assessment, frequently asked questions (FAQs), and a ‘was-wordt’ (before-and-after) list outlining the differences between BIO2 and previous versions. Additionally, the CIP has published a CISO Toolbox (Dutch).
At the request of the Ministry of the Interior and Kingdom Relations (BZK), the CIP is also organising an implementation support campaign, featuring events and guidance to help organisations elevate their information security standards.
Read more at bio-overheid.nl (Dutch)
Cyberbeveiligingswet (Cbw) tools and resources
Under the Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, the government is classified as a separate sector. Do you work within a government organisation and need to comply with the Cbw? Or do you work for a non-governmental organisation and want to determine whether it falls under the Cbw? Explore the available tools.




