THIRTEEN DELTA BOUTIQUE CYBERSECURITY START THE CONVERSATION
THE BOARD & EXECUTIVE WORKSHOP

The First Responder Workshop, condensed for your board and leadership team.

A two-hour, high-level workshop with your board or leadership team, in English or Dutch. Your board learns to weigh cyber risk and approve the right measures. We also explain what the Cyberbeveiligingswet (NIS2) asks of executive board members.

On-site at your location, shaped around your organisation at intake. Every participant receives a digital certificate of attendance.

ENQUIRE ABOUT THE WORKSHOP

What you leave with

A shared vocabulary

The language to challenge a risk paper or an incident update. We walk you through the threat landscape and one real incident, without acronyms, seen from the boardroom rather than the server room.

Four decisions, rehearsed in calm

Two exercises on your own organisation: what would take you down, and for how long; then the hard calls under fire, such as pay or rebuild, disclose or wait, with half the facts.

A 90-day list you sign off

You weigh competing measures, agree what gets done this quarter, and name who owns each item before you leave.

THE LAW

What the Cyberbeveiligingswet asks of your board.

AT A GLANCE
  • In force in the Netherlands since 15 August 2026, through the Cyberbeveiligingswet
  • Applies to executive board members of essential and important entities
  • Knowledge and skills in place by 15 August 2028; new members within two years of appointment
  • Content and certificate set in the Cyberbeveiligingsbesluit, articles 20 to 22
  • The certificate must be in Dutch or English
  • Elsewhere in the EU, the national NIS2 law and its dates apply

NIS2 is an EU directive, in force since January 2023, and every member state writes it into its own law on its own timetable. In the Netherlands that law is the Cyberbeveiligingswet (Cbw), in force since 15 August 2026. It makes the executive board of an essential or important entity responsible for approving its cyber risk management measures. Board members must follow cybersecurity training and have the required knowledge and skills by 15 August 2028, new members within two years of their appointment, and keep that knowledge current.

The Cyberbeveiligingsbesluit sets what that must cover. It must enable a board member to identify the risks to network and information systems and to judge what they mean for the services the entity delivers (article 20). It covers at least the types of risk, the risk management process and the risk assessment method, plus the security measures the Cbw requires, from risk analysis and incident handling to business continuity, supply chain security and access control (article 21). The law prescribes no course, exam or accredited provider.

Each executive board member must hold a certificate stating their name, the date or dates, the topics covered and the provider, in Dutch or English (Cbw article 24(5); Cyberbeveiligingsbesluit article 22). Supervisory and non-executive board members are not covered by the specific duty.

HOW IT RUNS

One workshop, agreed on an intake call.

It starts with an intake call, where we agree the content and the outcome you want, and we confirm it in writing before we begin. All materials and travel within the Netherlands are included. Where you can, we still recommend the full-day First Responder Workshop, with your executives and board members in the room: that's where they see what handling a breach really takes.

The workshop helps your board prepare. It is not an audit, and we issue no compliance statement. The legal summary on this page covers the Dutch law; NIS2 is EU-wide, so if you operate in other member states, their national rules and dates apply there as well.

ENQUIRE ABOUT THE WORKSHOP
FAQ

Frequently asked questions.

How does the workshop relate to the Cbw duty?

You hear what the law asks of executive board members, and you practise the decisions a board faces in a serious incident. Whether your board's knowledge and skills meet the duty is for your organisation, and in the end the regulator, to judge.

Can you run it outside the Netherlands?

Yes. We operate worldwide; for workshops outside the Netherlands we agree travel with you.

How does it relate to the First Responder Workshop?

It's the condensed, high-level version. The First Responder Workshop takes a full day and rehearses the first hours of a breach in a live four-round tabletop exercise on your own plans. The board workshop draws on the same material at board level, with the focus on the decisions that land on the board.

CONTACT

Start the conversation.

A keynote, the First Responder Workshop or its board version, the Board & Executive Workshop, or just a hard question you'd like a straight answer to. Tell us what you're facing and we'll find the right format together, in the Netherlands, abroad or remote. You speak with the expert directly, and in confidence.

info@thirteen-delta.com

Active incident? HOW WE CAN HELP