7. Public-private approach to cybersecurity In recent years, the public, private and public-private sectors have taken various initiatives to improve cybersecurity in the Netherlands. The course and speed of the approach needs to be coordinated to safeguard that direction. Coordination can and must be stronger and that, of course, is up to the government. As the coordinator, the NCTV takes the lead in promoting and ensuring the improvement of cybersecurity in a cohesive manner, in conjunction with all the parties involved (public authorities, business community, science, civil society). However, the government cannot do this on its own. All parties may and must be expected to accept their responsibilities and contribute to make and keep the Netherlands digitally secure as part of a concerted effort. The approach can only be successful if it is designed, further developed and evaluated in close public-private cooperation. The increasing complexity and breadth of the cyber domain require continuous clarification of the roles and responsibilities of the various parties involved. This should also help to identify successful market initiatives and link them to this Agenda. For instance, cybersecurity is included in the Corporate Governance Code and as such is a topic during audits and reviews. And on the private side, there is also a need for more cohesive efforts in the integrated Dutch approach to cybersecurity. The importance of information security and cybersecurity to public authorities is growing, because citizens and businesses are increasingly using their services from public authorities digitally. Failure, sabotage to or disruption of digital services will therefore directly lead to damage to critical service provision processes. To optimise the digital services provided to citizens and businesses by the government and to be able to guarantee high-quality services, it is essential for public authorities to keep investing in information security and cybersecurity and to prioritise the availability and continuity of services. In addition to services, digitalisation also has an impact on public values and human rights and ensuring them in the information society. In addition to the secure provision of services to citizens and businesses, the government also needs to have and keep its own information security in order and be resilient to digital attacks. The Broad Agenda for Digital Government (Ministry of the Interior and Kingdom Relations, BZK) discusses these topics in greater detail, as well as the measures the government will take, at an inter-governmental level, to step up its efforts on information security and cybersecurity. OBJECTIVES • The coordinating role of the government in the integrated approach to cybersecurity will be strengthened. • Dutch businesses, citizens and government organisations implement their responsibilities, rights and obligations with regard to cybersecurity. • For the information security of the digital government, there is a coherent package of measures to enhance the information security for the digital basic infrastructure, to further standardise and harmonise frameworks of norms on information security, including the creation and implementation of a Government Information Security Baseline [Baseline Informatiebeveiliging Overheid]. In this regard, attention will be paid to reducing administrative burdens on municipalities for information security and to bundling audits and assessments in a single A cyber secure Netherlands National Cyber Security Agenda | 43

Select target paragraph3