The National Cyber Security Agenda The Dutch approach to cybersecurity has the following objective: The Netherlands is capable of capitalizing on the economic and social opportunities of digitalisation in a secure way and of protecting national security in the digital domain. We are therefore committed to the following ambitions: 1. The Netherlands has adequate digital capabilities to detect, mitigate and respond decisively to cyber threats 2. The Netherlands contributes to international peace and security in the digital domain 3. The Netherlands is at the forefront of digitally secure hardware and software 4. The Netherlands has resilient digital processes and a robust infrastructure 5. The Netherlands has successful barriers against cybercrime 6. The Netherlands leads the way in the field of cybersecurity knowledge development 7. The Netherlands has an integrated and strong publicprivate approach to cybersecurity Coalition agreement An ambitious cybersecurity agenda will be formulated with, among other things, standards for internet of Things devices, software liability, strengthening the NCSC, promoting cybersecurity research and improving information campaigns. Ninety-five million euros of structural funding is being reserved for cybersecurity. The resources will be used for, among other things, improving staff capacity and expanding ICT facilities and will be shared by the departments of Justice and Security (NCTV), Defence (MIVD), Interior and Kingdom Relations (AIVD), Foreign Affairs, Infrastructure and the Environment and Economic Affairs. The structural intensification of cybersecurity has been integrated into the measures in this NCSA. The impact of technological and social developments and the digital threat are developing at different speeds and this requires a dynamic, long-term approach to cybersecurity. Many of these measures require a government contribution. Some other measures can only be taken with or by the market parties. This requires close cooperation in the development of the NCSA. The measures are not exhaustive. There is scope for additions. This leads to a dynamic approach that can be adjusted to match the development of the threat. It is also why the annual Cyber Security Assessment Netherlands will consider if this approach needs to be recalibrated and if policy instruments contribute to the realisation of the ambitions. The Agenda will be evaluated in 2021 and revised where necessary. A cyber secure Netherlands National Cyber Security Agenda | 17

Select target paragraph3