Ambition 3. Some popular protocols for data exchange via the internet are decades old and are no longer resistant to contemporary attacks. Improved versions of old internet standards (such as IPv6, or HTTPS) are being adopted very slowly and as a result the drawbacks of the old versions (IPv4 and HTTP) will continue to be an issue for some time. Businesses and public authorities depend on other organisations for their data processing, including cloud providers and their customers, public authorities who make open data available and certificate providers who guarantee the integrity of data exchange. The Dutch government aims to make important (chain) interdependencies between organisations transparent but realises that it is not feasible to have a full grasp of these at all times. The Dutch government is therefore calling for all organisations to be able to respond appropriately when the continuity of their services is at risk. The Digital Trust Center, currently in development, aims to help parties in this regard by raising awareness and offering perspectives for action. The center will do this in consultation with the NCSC and various other parties, including small and medium businesses. Where organisations want to use the services of cybersecurity service providers, it is important that also they deal with computer networks and sensitive information in a professional manner and with integrity. Many Dutch organisation are dependent on a limited number of foreign digital infrastructure service providers, which means that the impact of disruption is severe. Example: Heartbleed Heartbleed was a vulnerability in the OpenSSL programming library, which was discovered in 2014. At the time, the vulnerability had already been present in this commonly used software for two years. Many web servers, VPN servers, mail servers and other applications use OpenSSL to establish secure connections. Other devices can also use OpenSSL. Examples include appliances, routers, WiFi access points and some applications on client systems. By exploiting Heartbleed, attackers could read the internal memory of systems remotely. This example underlines the fact that a vulnerability in open source software can have major consequences for the cybersecurity of the business community, public authorities and citizens. 32 | National Cyber Security Agenda A cyber secure Netherlands OBJECTIVES • All relevant parties will be involved in ensuring the continuity and digital resilience of critical processes which increases the resilience of the entire chain. • The Netherlands aims to improve the quality of open source software and the accelerated adoption of modern internet protocols and internet standards. • The Dutch government promotes an innovative cybersecurity climate in which secure ICT products and services are developed and adopted. MEASURES o In addition to existing obligations for telecommunications providers under the Telecommunications Act, the proposal for the Cybersecurity Act greatly increases the number of providers of critical services subject to duty of care requirements and an obligation for notification. Sectoral supervisory bodies will supervise cybersecurity in sectors in critical infrastructure, which was not done up to now, and they will be given the instruments to do so. o In addition to the above, these supervisory bodies, together with the responsible ministries, will develop a method for identifying dependency relationships of providers of critical services for their own data-driven operating processes. o Research will be conducted into whether additional (European or international) measures are needed to mitigate the impact of disruption of the services of a limited number of foreign providers of digital infrastructure upon which many Dutch organisations depend. o Open source software fulfils a central role in the exchange of data between organisations. The Ministry of Economic Affairs and Climate Policy, in close cooperation with the NCSC, will review how the communities that develop and maintain open source software can be supported to improve the quality of the software. o The government ensures that suppliers incorporate modern internet protocols and internet standards in their products and services, in part through agendasetting in Europe. o The government, as a launching customer, uses cybersecurity requirements when procuring ICT products and services and strongly advices providers of critical services on this matter.

Select target paragraph3