Direct naar inhoud

What is standing when I am done

I do not sell hours, and I do not sell a report. Below are four states that exist once the work is done. Each one names the part of my own infrastructure that proves I work this way myself.

Who has access to what is fixed, and traceable

One place where access is granted and revoked: single sign-on, multi-factor authentication, an access matrix that matches reality, and logging that lets you see afterwards who did what.

Also part of this outcome: encryption of data at rest and in transit, patch management against known vulnerabilities, and monitoring that flags anomalies.

Evidence: The sovereign stack, in production →

Your recovery is tested, not assumed

Backup with offsite replication. On larger implementation engagements, that includes a restore that has actually been carried out — with the date, the elapsed time and the outcome on record. A backup that has never been restored is an assumption.

Also part of this outcome: backup with offsite replication. On larger implementation engagements, that includes a periodically tested restore procedure.

Evidence: My own rack, my own hardware →

You can show that it works, not just that it is written down

A record that describes the working situation rather than the intended one: which measure runs where, who signs off on it, which supplier it depends on, and what you have required of that supplier.

Also part of this outcome: the supply-chain security requirements you impose on your own suppliers, and supplier and contract management.

Evidence: sovereign-nix →

Your board knows what is expected of it

The Dutch Cyber Security Act places responsibility explicitly with the board and obliges directors to keep themselves trained. I brief them in their own language, with the decisions they have to make as the subject.

Also part of this outcome: a dedicated board session that fulfils the training obligation in the Cyber Security Act.

Evidence: SAIG Academy →

Not just my claim — the regulator's

The Dutch Cyber Security Act (Cyberbeveiligingswet) entered into force on 15 August 2026 (Staatsblad 2026, 187). The Rijksinspectie Digitale Infrastructuur (RDI) — the Dutch regulator responsible for enforcement — has been explicit about what that means in practice. Below are the RDI's own statements in the original Dutch, alongside an English translation.

“Nee, het voldoen aan een eigen normenkader betekent niet dat een organisatie aan de zorgplicht voldoet.”

Translation: “No, meeting a self-defined normative framework does not mean an organisation meets its duty of care.”

Rijksinspectie Digitale Infrastructuur (RDI), translated from Dutch

The same page adds this qualification right alongside it — and it belongs here, because a quote without its own nuance is a half-truth:

“Een normenkader kan wel houvast geven bij het beheersen van de risico's van de beveiliging van de netwerk- en informatiesystemen.”

Translation: “A normative framework can, however, provide a degree of guidance in managing the risks to the security of network and information systems.”

Rijksinspectie Digitale Infrastructuur (RDI), same page, translated from Dutch

“Ook mogen we ter plekke uw systemen inkijken.”

Translation: “We are also permitted to inspect your systems on site.”

Rijksinspectie Digitale Infrastructuur (RDI), translated from Dutch

Who this is for

These four outcomes are relevant for organisations that:

  • Fall under the Cyber Security Act and do not yet know whether their measures are sufficient
  • Have a normative framework or certificate, but wonder whether that is enough during an inspection
  • Have suppliers where it is unclear whether they meet the supply-chain security requirements
  • Have a board responsible for approval and oversight, but no technical team to carry that out
  • Have between 50 and 250 employees and no in-house CISO or IT manager

Not sure which outcome you need first?

No problem. In a no-obligation 30-minute call I'll map out your situation and we'll work out together where to start.