The Netherlands has been taken to court by the European Commission. The reason: the government has still not converted the directive for the protection of vital sectors such as energy, transport, healthcare and digital infrastructure into national legislation. The Ministry of Justice and Security responds that ‘a good foundation is first needed’. That answer deserves a closer look.
The information security standards framework on which this relies, ISO 27001, has existed in the form of its predecessors since the 1990s. The European directive has been on the table for years. Moreover, legislation starts in Brussels and the Netherlands is a member and can simply participate, not only once the text is final. A foundation could and should have been in place a long time ago. How much more time does the government want?
The cabinet does not have its own crown jewels
During the debate about the takeover of Solvinity, the cabinet appeared unable to indicate what the crown jewels of the central government are. That list was still being drawn up. At the same time, the same government is now calling on vital organizations to arm themselves against threats. A remarkable sequence: first encourage others, then make an inventory of what needs to be protected.
The practice is now disconcerting. The Tax Authorities cannot get their own email in order and have to outsource it. Critical facilities such as DigiD and the Message Box cannot be moved within months. Incidents at the Public Prosecution Service, the Ministry of Finance, Odido, Rituals and the Netherlands Population Survey repeatedly exposed the vulnerability.
“Other countries are also lagging behind”
The spokesperson emphasizes to the Telegraaf that the Netherlands is not alone: Bulgaria, France, Luxembourg, Poland, Spain and Sweden have also been summoned. That is the argument of the motorist who points to other speeders who also received a fine. It does not change the fact that countries such as Greece, Italy, Croatia, Cyprus, Hungary, Malta, Romania, Slovenia and Slovakia have introduced the directive. We are lagging behind countries that The Hague would like to emulate, and behind countries that it would rather not emulate.
Not complex, a matter of will
The government calls the process “extensive and complex”. But the gist is known: stick to standards, start implementation as soon as Brussels determines the direction, and ensure that vital processes can withstand failure. And what is being asked are the basics of information security and they are not new at all. That is not special expertise. That is administrative manual work. Or, in Rotterdam terms: don’t talk, just polish.
The threat, meanwhile, is not abstract. The MIVD, the AIVD, the NCTV and foreign intelligence services continuously warn against cyber attacks, sabotage and espionage from Russia, China and Iran. The director of the MIVD speaks about actions that remain just below the threshold of an open military conflict. The cabinet hears it, nods, and refers to the next foundation.
So what
Two proposals are obvious. Have the government report to the House of Representatives monthly on what has been done, what is in progress and what will happen in the coming month to ensure information security and resilience are in order. Concretely, at organizational level, with deadlines. And: put new policy ambitions on hold until privacy, information security and European obligations are actually in order. Anyone who doesn’t have their house locked doesn’t buy new furniture.
A lawsuit from the European Commission should be a wake-up call. When it comes to resilience, we are the suckers for rosewater. For the time being, it mainly appears to be a new dossier rule that the cabinet is writing around. The bill for this will not be paid in The Hague, but during the first major failure of a vital sector.
This article previously appeared AG Connect.
