In July, the Dutch Senate approved the Dutch Cybersecurity Act, introducing new cybersecurity obligations for organizations providing essential services, including drinking water operators. The legislation implements the European NIS2 Directive and strengthens the country’s approach to critical infrastructure security.
Under the new framework, water utilities must adopt stronger cyber risk management practices, improve governance structures, and establish clearer incident reporting procedures. Management teams will also be expected to take greater responsibility for cybersecurity decisions and risk oversight.
The law reflects a broader European trend toward treating cyber resilience as a strategic business issue rather than a purely technical matter. Regulators are increasingly expecting operators of essential services to demonstrate robust protection of both IT and operational technology environments.
For water utilities, the new requirements create an opportunity to strengthen resilience against ransomware, supply-chain attacks, and threats targeting industrial control systems. The legislation is expected to significantly raise cybersecurity standards across the Dutch water sector.