7. Public-private
approach to
cybersecurity
In recent years, the public, private and public-private
sectors have taken various initiatives to improve
cybersecurity in the Netherlands. The course and speed
of the approach needs to be coordinated to safeguard
that direction. Coordination can and must be stronger
and that, of course, is up to the government. As the
coordinator, the NCTV takes the lead in promoting and
ensuring the improvement of cybersecurity in a cohesive
manner, in conjunction with all the parties involved
(public authorities, business community, science, civil
society). However, the government cannot do this on its
own. All parties may and must be expected to accept
their responsibilities and contribute to make and keep
the Netherlands digitally secure as part of a concerted
effort. The approach can only be successful if it is
designed, further developed and evaluated in close
public-private cooperation. The increasing complexity
and breadth of the cyber domain require continuous
clarification of the roles and responsibilities of the
various parties involved. This should also help to
identify successful market initiatives and link them to
this Agenda. For instance, cybersecurity is included in
the Corporate Governance Code and as such is a topic
during audits and reviews. And on the private side, there
is also a need for more cohesive efforts in the integrated
Dutch approach to cybersecurity.
The importance of information security and
cybersecurity to public authorities is growing, because
citizens and businesses are increasingly using their
services from public authorities digitally. Failure,
sabotage to or disruption of digital services will
therefore directly lead to damage to critical service
provision processes. To optimise the digital services
provided to citizens and businesses by the government
and to be able to guarantee high-quality services, it is
essential for public authorities to keep investing in
information security and cybersecurity and to prioritise
the availability and continuity of services. In addition to
services, digitalisation also has an impact on public
values and human rights and ensuring them in the
information society. In addition to the secure provision
of services to citizens and businesses, the government
also needs to have and keep its own information
security in order and be resilient to digital attacks. The
Broad Agenda for Digital Government (Ministry of the
Interior and Kingdom Relations, BZK) discusses these
topics in greater detail, as well as the measures the
government will take, at an inter-governmental level, to
step up its efforts on information security and
cybersecurity.
OBJECTIVES
• The coordinating role of the government in the
integrated approach to cybersecurity will be
strengthened.
• Dutch businesses, citizens and government
organisations implement their responsibilities, rights
and obligations with regard to cybersecurity.
• For the information security of the digital
government, there is a coherent package of measures
to enhance the information security for the digital
basic infrastructure, to further standardise and
harmonise frameworks of norms on information
security, including the creation and implementation
of a Government Information Security Baseline
[Baseline Informatiebeveiliging Overheid]. In this regard,
attention will be paid to reducing administrative
burdens on municipalities for information security
and to bundling audits and assessments in a single
A cyber secure Netherlands National Cyber Security Agenda | 43