


The Dutch Cybersecurity Act came into force on 15 August 2026, placing greater responsibility than ever on boards for managing cyber risks. To support board members in meeting this new responsibility, the University of Twente is launching the two-day Masterclass Cybersecurity Act for Board Members.
Cyber incidents can rapidly cause serious damage to an organisation’s continuity, financial stability and reputation. A ransomware attack, data breach or disruption to digital processes is therefore more than a technical problem. During a cyber crisis, the board must make decisions about service delivery, communication, responsibilities and cooperation with internal and external stakeholders.
The Dutch Cybersecurity Act implements the European NIS2 Directive and applies to more than 8,000 organisations. It covers essential and important entities across eighteen sectors, including energy, drinking water, healthcare, public administration, transport and digital infrastructure. Organisations within its scope are subject to obligations including registration, a duty of care and incident reporting.
The Act also places explicit responsibilities on boards. Board members must approve measures to manage cyber risks and oversee their implementation. Executive board members must also have sufficient knowledge and skills to understand and assess cyber risks and security measures. They are therefore required to undertake training.
The new masterclass helps board members approach cybersecurity from a strategic and governance perspective. No prior technical knowledge is required. Participants learn which cyber threats are relevant to their organisation, how to assess their potential impact and which questions to ask management, the CIO, the CISO and other specialists.
The programme covers current threats such as ransomware, data breaches and disruptions to critical processes. Participants also explore the Dutch Cybersecurity Act, board responsibilities, cyber governance, risk management and oversight. They learn to interpret reports and dashboards more effectively and gain practical guidance on making cyber risks an integral part of board decision-making.
A key element of the masterclass is an interactive cyber crisis simulation. Participants experience how an incident unfolds and face board-level dilemmas involving continuity, communication, competing interests and responsibilities. This reveals what is expected of a board member when pressure increases and information remains incomplete.
The masterclass is designed for members of executive and management boards, executive directors, managing directors and other decision-makers with ultimate organisational responsibility. Supervisory board members and board members of organisations that form part of critical supply chains are also welcome to attend.
Through this programme, the University of Twente aims not only to help board members meet their statutory training requirement, but above all to embed cybersecurity in governance, risk management and decision-making for the long term.