blog hero

Cybersecurity Blog

Stay updated on the latest trends and insights in cybersecurity.

Date: 8/17/2026

Cybersecurity

The rules are in force. But do you know what to do when something goes wrong?

A practical 15-minute resilience test for management, security and operations. Fifteen simple questions about decisions, suppliers, AI, OT and recovery.

The rules are in force. But do you know what to do when something goes wrong?

The Dutch Cybersecurity Act entered into force on 15 August 2026. Today is the first normal working day under the new law.

For organisations in scope, that brings new or clearer duties around cybersecurity, incidents and responsibility.

But I would not start today with a folder full of policies.

I would start with one simple question:

If something goes wrong at 03:00 tonight, do we know what to do?

Rules matter. During an incident, what matters most is what people can actually do.

Imagine it is 03:00

A supplier has remote access to an important system.

That is normal. The supplier uses the connection for maintenance.

But tonight something unusual happens.

The security team sees unexpected activity and wants to block the connection immediately.

Operations says:

“Wait. If you do that, production may stop.”

At the same time, an AI tool recommends:

“Block the connection immediately.”

That sounds sensible.

But who decides?

Security?
The operations manager?
The supplier?
Senior management?

And can anyone actually reach the right decision-maker at 03:00?

This is where cybersecurity becomes practical.

Not on paper.
In the real world.

NIS2, AI and industrial systems meet here

These subjects are often treated separately:

  • NIS2 and the Dutch Cybersecurity Act;
  • AI and the European AI Act;
  • industrial cybersecurity and IEC 62443.

They are not the same rules.

The Dutch Cybersecurity Act implements the European NIS2 Directive in the Netherlands.

The AI Act is separate European legislation for AI. Which requirements apply depends, among other things, on the organisation's role and the type of AI system.

IEC 62443 is not a law. It is an international series of standards for cybersecurity in industrial automation and control systems.

But during a real incident these subjects meet.

Why?

Because the same organisation still has to answer the same practical questions:

What matters? Who decides? Who has access? What do we trust? And how do we recover?

1. Do we know what really matters?

Many organisations have lists of critical systems.

During an incident, another question is more useful:

What absolutely has to keep working?

It may be a machine.
A logistics process.
A customer service.
A power supply.
An IT system.
Or several of these together.

If one part is shut down, what else stops?

You need to know that before the incident.

2. Who is allowed to make a difficult decision?

An incident may require difficult choices.

For example:

  • disconnecting a system;
  • blocking a supplier;
  • shutting something down;
  • reducing production;
  • temporarily accepting a risk.

A job title is not enough.

Someone needs the authority to decide.

And just as important: that person needs to be reachable.

A name in a document is not very useful if nobody has the phone number at 03:00.

3. Can we reach our suppliers?

Suppliers are often essential for maintenance and troubleshooting.

Some suppliers also have remote access.

That makes two simple questions important:

Do we know which suppliers can actually connect today?

and:

Do we have a current phone number if something goes wrong tonight?

Not only a general email address.

For important suppliers, you want a named contact, phone number, backup contact and escalation route.

During an incident, that can save hours.

4. Can we keep a small problem small?

A fire door does not stop every fire from starting.

It helps stop the fire from spreading through the whole building.

Digital systems need a similar idea.

Important parts of an environment should be separable from each other.

This matters especially in factories, energy, transport, water and other industrial environments.

IEC 62443 uses concepts such as zones and controlled connections between them.

The simple question is:

If one system is affected, does the problem have to spread everywhere else?

5. Do we know when to trust AI — and when not to?

AI can be extremely useful.

It can analyse information.
It can find unusual patterns.
It can give advice.

But an important decision should never end with:

“The AI said so.”

If AI recommends shutting down a system, you want to know:

  • what information it used;
  • what may be missing;
  • what the consequences could be;
  • who checks the advice;
  • who makes the final decision.

AI can be a strong assistant.

Responsibility stays with people.

Five questions for tomorrow morning

You do not need a large programme to learn something useful.

Take fifteen minutes with someone from management, IT/security and operations.

Answer these five questions without opening your policy documents first:

  1. Do we know what absolutely has to keep working?
  2. Do we know who is allowed to make difficult decisions during a serious cyber incident?
  3. Can we reach that person outside office hours?
  4. Do we know which suppliers have remote access, and do we have their current emergency contact details?
  5. Have we actually practised this in the last twelve months?

How often does the answer start with:

  • “I think…”
  • “Someone else probably knows…”
  • “We would have to check…”

Those are often the most useful findings.

Free: CyberBusters 15-Minute Resilience Check

The full check contains 15 practical questions about critical services, authority, availability, suppliers, system dependencies, AI, incidents and recovery.
No registration required. No email address required.

Download the free checklist (PDF)

From rules to the ability to act

NIS2 and the Dutch Cybersecurity Act make cyber resilience a clear organisational responsibility.

AI creates powerful new options, but also new questions about control and responsibility.

And in industrial environments, a digital decision can affect machines, production and sometimes safety.

So the key question is not only:

“Do we have the right documents?”

It is also:

“Can we make the right decision when time is short and the information is incomplete?”

Having a plan is good.

Knowing what to do when something goes wrong is better.

About this checklist

The CyberBusters 15-Minute Resilience Check is a practical conversation starter.

It is not a legal compliance assessment, certification, or replacement for a formal risk assessment.

Its purpose is to quickly show where practical cyber resilience appears strong and where more attention may be needed.

Free: CyberBusters 15-Minute Resilience Check

The full check contains 15 practical questions about critical services, authority, availability, suppliers, system dependencies, AI, incidents and recovery.
No registration required. No email address required.

Download the free checklist (PDF)

Sources and further information

CyberBusters Logo

CyberBusters B.V.

Registered at the Chamber of Commerce under number: 89637631

CyberBusters supports boards and executive teams when cyber risk threatens continuity, safety or trust. We are brought in when the situation is complex, pressure is high and decisive leadership is required...

Cyber risk is a boardroom priority. When the stakes are high, call CyberBusters.

© 2026 - All rights reserved.