share information; from the business community to public authorities and from individual citizens to cybersecurity professionals. OBJECTIVES • Public authorities and businesses are capable of responding appropriately to digital threats and attacks. To do this, they implement the necessary (preventative) measures and they have the basics in order. • The Netherlands is prepared for large-scale cyber incidents which pose a threat to national security. • Organisations of vital importance to national security have a better understanding of digital threats and attacks and are capable of detecting attacks that threaten themselves and national security. • A nationwide network of cybersecurity partnerships will be created within which information about cybersecurity can be shared between public and private parties more widely, efficiently and effectively. The aim of this nationwide network is to strengthen the capabilities of public and private parties. • The legal instruments for effective action in the digital domain remain in order and are kept up to date in light of the threat and technological developments. MEASURES o The incident response capabilities of, amongst others, the intelligence and security services, Defence Computer Emergency Response Team (CERT), the National Cyber Security Center (NCSC) and Rijkswaterstaat (Directorate-General for Public Works and Water Management) are being enhanced to be able to deal with ICT breaches that threaten national security. In addition, the creation of more private sector-wide computer crisis teams, such as Z-CERT (for the care sector) and I-CERT (for the insurance sector) is encouraged. o The critical processes in our society demand extra protection and accelerated recovery in the event of failure or damage. It is therefore important that these organisations ensure that they have an appropriate response capacity or that they have agreement in place for this with a trusted third party. To this end, the development of a certification system for cybersecurity service providers, from whom secure o o o o o o services can be acquired, will be explored with private parties.1 The Netherlands must be prepared for large-scale cyber incidents that threaten national security. The National Crisis Plan for ICT (Nationaal Crisisplan ICT) will be being updated. In addition, an integrated ICT emergency exercise policy will be formulated. It will include arrangements between government bodies and private organisations on a joint exercise agenda and the available capabilities of the parties involved for this. The capabilities of the intelligence and security services, DefCERT and the NCSC to gain insight into threats and digital attacks, to detect them, disrupt them and increase resilience will be improved structurally. To ensure this, the government has allocated additional funding in recent years and in the coalition agreement. The National Detection Network [Nationaal Detectie Netwerk, NDN] will be further enhanced to create a future proof network. Situational awareness at the national level will be enhanced by the creation of a cooperation platform2 with the goal to offer more information and a swifter perspective for action with relevant organisations within the legal frameworks. When doing so, attention should also be paid to cybersecurity requirements. Recipients need to have a certain level of maturity to enable information sharing. Under NCTV coordination, round table discussions are organised in which the nationwide network of cybersecurity partnerships can be developed. This will build on the experiences from existing public and private cybersecurity partnerships. The National Cyber Security Center (NCSC) and the Digital Trust Centre3 (DTC) will encourage – and support where necessary – the creation and further development of cybersecurity partnerships for public authorities, the business community and civil society organisations. This will also include the creation of a set of basic security measures for the business community and civil society organisations. Legislation aimed at protecting national security will be reviewed to what extent it provides satisfactory possibilities to promote security in the digital domain, whilst retaining fundamental values and privacy. 1 Please also see the objectives and measures on pages 27-28. 2 The possibilities for developing this cooperation platform, with which parties and the form it should take will be explored further. 3 Letter to Parliament ‘Setting up the Digital Trust Centre’, 23 September 2017. 20 | National Cyber Security Agenda A cyber secure Netherlands

Select target paragraph3