4.Resilient digital processes and a robust infrastructure ICT is becoming increasingly interwoven with Dutch society. One of the consequence of this is that the operations of businesses and public authorities are becoming increasingly data-driven through intelligent applications. Organisations are often no longer capable of carrying out all of the tasks themselves. They operate in chains. They depend on other organisations for, among other things, supplying the data or for carrying out or supporting their data processing. This is not without risk. Business processes can be disrupted if data is not exchanged with other organisations in a secure and reliable manner. When this occurs in the chains of providers of critical processes, it can lead to major system failure, damage to physical security and societal disruption. Problems could arise with the physical infrastructure or with the protocols and the software for data exchange. Finally, the parties that provide data processing services may cease to exist or fall short. supervisory bodies. This will further increase the security level of providers and create the possibility to take firm action against vulnerable (not appropriately protected) information systems. The CSW replaces and adds to the Dutch Data Processing and Cybersecurity Notification Obligation Act [Wet gegevensverwerking en meldplicht cybersecurity, WGMC] already in effect, which among other things stipulates that the NCSC is tasked with providing advice on cybersecurity to central government and providers of critical services. This Act also provides the opportunity to inform a relevant Minister in those cases where a government body or provider of critical services does not deal with the recommendations from the NCSC adequately. The Dutch government expects all organisations to be able to respond appropriately when the continuity of their services is at risk. It is also important that outdated software and hardware is replaced in good time (legacy issues). Due to the importance of the availability (or continuity) of data communications networks, specific requirements are set for the providers of such networks, amongst others through the Telecommunications Act [Telecommunicatiewet] and the proposed legislation for the Cybersecurity Act [Cybersecuritywet, CSW].8 Their objective is that such providers make their systems resilient to various threats and incidents, including those that could lead to failure of the physical infrastructure. The CSA also creates the obligation to implement suitable technical and organisational measures for all providers of an essential service and digital service providers. Implementation of this will be overseen by the sectoral To ensure effective and unhindered data exchange, the software and protocols for worldwide exchange of data also require attention and maintenance. This often involves what is known as open source software which is usually developed by communities of volunteers. As a result, they often lack the capabilities or resources for maintenance and/or professional review of the quality of the software. Other software developers also use open source software as building blocks for their work, further increasing the dependence on this software. The quality of paid software and the security of hardware components is equally important to the effective and unhindered exchange of data. This is addressed in 8 The Cybersecurity Act stems from the EU Directive on Security of Network and Information Systems (NIS Directive) and was submitted to the House of Representatives in February 2018. A cyber secure Netherlands National Cyber Security Agenda | 31

Select target paragraph3