4.Resilient digital
processes and a
robust infrastructure
ICT is becoming increasingly interwoven with Dutch
society. One of the consequence of this is that the
operations of businesses and public authorities are
becoming increasingly data-driven through intelligent
applications. Organisations are often no longer capable
of carrying out all of the tasks themselves. They operate
in chains. They depend on other organisations for,
among other things, supplying the data or for carrying
out or supporting their data processing. This is not
without risk. Business processes can be disrupted if data
is not exchanged with other organisations in a secure
and reliable manner. When this occurs in the chains of
providers of critical processes, it can lead to major
system failure, damage to physical security and societal
disruption. Problems could arise with the physical
infrastructure or with the protocols and the software for
data exchange. Finally, the parties that provide data
processing services may cease to exist or fall short.
supervisory bodies. This will further increase the security
level of providers and create the possibility to take firm
action against vulnerable (not appropriately protected)
information systems. The CSW replaces and adds to the
Dutch Data Processing and Cybersecurity Notification
Obligation Act [Wet gegevensverwerking en meldplicht
cybersecurity, WGMC] already in effect, which among
other things stipulates that the NCSC is tasked with
providing advice on cybersecurity to central government
and providers of critical services. This Act also provides
the opportunity to inform a relevant Minister in those
cases where a government body or provider of critical
services does not deal with the recommendations from
the NCSC adequately. The Dutch government expects all
organisations to be able to respond appropriately when
the continuity of their services is at risk. It is also
important that outdated software and hardware is
replaced in good time (legacy issues).
Due to the importance of the availability (or continuity) of
data communications networks, specific requirements
are set for the providers of such networks, amongst
others through the Telecommunications Act
[Telecommunicatiewet] and the proposed legislation for
the Cybersecurity Act [Cybersecuritywet, CSW].8 Their
objective is that such providers make their systems
resilient to various threats and incidents, including those
that could lead to failure of the physical infrastructure.
The CSA also creates the obligation to implement suitable
technical and organisational measures for all providers of
an essential service and digital service providers.
Implementation of this will be overseen by the sectoral
To ensure effective and unhindered data exchange, the
software and protocols for worldwide exchange of data
also require attention and maintenance. This often
involves what is known as open source software which is
usually developed by communities of volunteers. As a
result, they often lack the capabilities or resources for
maintenance and/or professional review of the quality of
the software. Other software developers also use open
source software as building blocks for their work, further
increasing the dependence on this software.
The quality of paid software and the security of hardware
components is equally important to the effective and
unhindered exchange of data. This is addressed in
8
The Cybersecurity Act stems from the EU Directive on Security of Network and Information Systems (NIS Directive) and was submitted to the House of Representatives in
February 2018.
A cyber secure Netherlands National Cyber Security Agenda | 31