Fines and the role of the board under the Cyberbeveiligingswet

Published · Updated

The Cyberbeveiligingswet (Cbw) places obligations on organisations and on their boards. An organisation that does not comply risks an administrative fine and other measures from the supervisor. Directors also have duties of their own, and failing to meet them can affect them personally.

This article sets out which sanctions the Act has, what article 24 asks of the board and what a board must be able to show in practice. Every provision links to the text of the Act on wetten.overheid.nl.

What the Act asks of the board

Article 24 is short and concrete. The board approves the duty-of-care measures. In addition, every board member must personally have the knowledge and skills to:

  • identify risks to the security of network and information systems;
  • assess cybersecurity risk-management measures;
  • assess the impact of those risks and measures on the services the organisation provides.

Every board member must meet this within two years, so by 15 August 2028. Members appointed later have two years from their appointment. The knowledge must be kept demonstrably current, and every board member holds a certificate of a training covering these subjects. Where a legal entity sits on the board, these requirements apply to the natural persons who represent it.

Sanctions for the organisation

The supervisor can impose an administrative fine on an organisation that breaches the Act, together with or after a warning or another measure. The maximums differ by category.

  • Essential entity: at most EUR 10 million or 2% of the worldwide annual turnover of the undertaking it belongs to, whichever is higher (article 80).
  • Important entity: at most EUR 7 million or 1.4% of that turnover (article 87).

A fine is not the only tool. For an essential entity the supervisor can, among other things, require an independent audit (article 72), give a binding instruction (article 74) and set a deadline by which a breach must end (article 76). For an important entity the Act also provides for an audit (article 83) and a binding instruction (article 85).

Who supervises

Which supervisor is competent depends on your sector. Under the Cyberbeveiligingswet, sector inspectorates supervise, such as the RDI, the ILT, the IGJ and the NVWA, and DNB and the AFM for the financial sectors. The NCSC runs the reporting portal.

The style of supervision differs too. Essential entities are checked proactively, important entities mainly after the fact, for example after an incident or a signal. The obligations themselves are the same for both categories; the difference lies in how often and when the supervisor looks, and in the maximum fine.

What can affect directors personally

The Cyberbeveiligingswet creates no personal liability: the Dutch word for liability does not appear in the Act and company law is unchanged. Even so, the Act affects directors personally, in two ways.

  • A personal fine. If a board member does not meet the knowledge, currency and certificate duties of article 24, or does not cooperate with the supervisor, the supervisor can impose an administrative fine of at most EUR 25,000 on that board member (article 93). An order subject to a penalty payment is also possible (article 92). This sanction concerns the board member's own duties, not every breach by the organisation.
  • Suspension, for essential entities only. If an essential entity has not ended a breach by the deadline the supervisor set, the supervisor can ask the civil court to suspend one or more board members for as long as the entity does not comply (article 78). The suspension is entered in the Trade Register and removed once the entity complies.

Both routes are easy to avoid. A board member avoids the article 93 fine by keeping their own duties in order. Suspension is the last step of a process in which the organisation first gets a deadline to remedy a breach.

What a supervisor will want to see

The Act does not prescribe how the board records its approval. In practice, these are the documents a supervisor or auditor will want to see.

  • A dated board resolution approving the duty-of-care measures, recorded in the minutes.
  • For every board member, the training certificate, and for new members the appointment date from which the two-year period runs.
  • An overview of how knowledge is kept current, such as periodic training or a standing agenda item on cyber risk in board meetings.
  • Documents showing that the board follows implementation: reports on risks, incidents and the progress of measures.

The exact requirements for the training and the certificate can be set out further by order in council (article 24, sixth paragraph). We will update this article once those rules exist.

Keeping the risk small

The personal risk for directors is manageable: record the approval, complete the training in time and keep the knowledge current. The risk for the organisation asks more: a duty of care that demonstrably works, a reporting process that meets the deadlines and a registration that is correct. For each of these, a supervisor asks the same question: can you show it?

Read alsoDoes the Cyberbeveiligingswet apply to your organisation?

Board duties belong to the duty of care

We prepare the board's approval and training, and keep the evidence for the whole duty of care current.

See how we set up the duty of care