This guide is intended for directors, business owners and members of supervisory boards across all organisations, regardless of size or whether they are public or private. It is also relevant for directors and owners of businesses that are not subject to the cyber security legislation, such as NIS2 or DORA. Throughout this guide, we use the term ‘directors’ to refer to directors, business owners and members of supervisory boards. As this guide is written from a Dutch perspective, it refers to Dutch legislation. However, the insights provided are broadly applicable.