1. The Netherlands has adequate digital capabilities to detect, mitigate and respond decisively to cyber threats To respond effectively to the growing digital threat, government bodies and private organisations in the Netherlands must cooperate and have appropriate capacities and resources. A number of these organisations are still developing those capacities and they are at various levels of maturity. While some (larger) businesses and organisations are arranging their own security operations center or computer crisis team, other (smaller) businesses or organisations are only just or not sufficiently aware of digital risks. Protection of their own digital systems and information by these public and private parties is not yet a given and basic security regulations have not yet been implemented . Sufficient capabilities also include the capacity of security organisations which must be able to carry out their tasks for national security in the digital as well as the physical domains. This is closely tied-in with the offensive capabilities of Defence, which are covered under Ambition 2. There is an urgent need to build up capabilities, for more and better tailor-made information about digital threats, which is available to government bodies and private organisations more swiftly and for perspective for action for mitigating those threats. The exchange of information between organisations and businesses in the Netherlands has improved greatly in recent years as a result of cooperation on incidents or because parties have come to know each other and started trusting each other. Although this is a step in the right direction, it still does not provide sufficient guarantees that we can address digital threats now and in the future. The next step is to structurally guarantee the exchange of information and existing cooperation while at the same time expand the range, for instance by promoting crosssector analyses. There is a need to improve the detection and response capabilities of government organisations and providers of critical services. By doing so, we will increase the digital capabilities of these parties as a whole. We must adopt a practice in which customers and suppliers encourage each other to arrange their digital security. In this way, we will work towards a cyber ecosystem in which all parties build up capacities and A cyber secure Netherlands National Cyber Security Agenda | 19

Select target paragraph3