Cybersecurity is becoming a prerequisite for the functioning of the state, the economy and critical infrastructure. As dependence on cloud services, data and digital tools grows, the issue is no longer only protecting IT systems, but maintaining operations when an attack or failure occurs.
The new rules increase the demands placed on organisations and their suppliers. Merely meeting formal obligations, however, does not guarantee resilience. What matters is the quality of risk management, clear allocation of responsibility and the state's ability to ensure that requirements are understandable and enforceable in practice.
How can we tell whether an organisation is genuinely resilient rather than merely compliant on paper? Where does a supplier's responsibility end and management's responsibility begin? And how should the state set security requirements that protect operations without creating unnecessary administrative burdens?