Who Owns Cyber Resilience?

Auteur zonder afbeelding icoon
Sander Hulsman
20 August 2026
4 min

Who Owns Cyber Resilience?

Mietta Groeneveld and Jeroen Gaiser at Cybersec Netherlands 2026

On Thursday 10 September, Colonel Mietta Groeneveld of the NATO Command & Control Centre of Excellence and Jeroen Gaiser, Deputy CISO at the Dutch Ministry of Infrastructure and Water Management, will host a joint session at Cybersec Netherlands 2026 titled “Between Threat and Reality: Who Owns Cyber Resilience Today?”

It is a question that is more relevant than ever. As geopolitical tensions increasingly spill over into the digital domain, a fundamental question arises: who is actually responsible for our digital resilience?

Cybersecurity has long since ceased to be an issue confined to the IT department. In recent years, it has become clear that digital attacks are part of a broader geopolitical reality. States use cyber operations to exert economic pressure, create social disruption or interfere with critical processes.

And military targets are not the only ones at risk. Civilian infrastructure in particular has become an increasingly attractive target.

Everything is digitally connected

That is hardly surprising. Almost everything that keeps our society running is now digitally connected. Energy supplies, drinking water, transport, ports, telecommunications, healthcare and government services together form the foundation of our economy and society.

A disruption in one part of this system rarely remains limited to a single organisation. Because of these interdependencies, the consequences can spread rapidly throughout the entire chain.

“Cyber resilience is shifting from a technical concept to a strategic governance challenge.”

This is also changing the meaning of cybersecurity. For years, organisations primarily invested in preventing attacks. Today, there is growing recognition that complete protection is simply no longer realistic.

The question is no longer whether an organisation will be affected, but how quickly it can detect an attack, limit its impact and restore its services. Cyber resilience is therefore shifting from a technical concept to a strategic governance challenge.

An operational domain

This creates an interesting tension. Defence has long viewed cyber as an operational domain in which threats are continuously present. Not every attack is visible, not every adversary identifies itself and not every disruption can immediately be attributed to a specific actor.

In this environment, the focus is not solely on protection, but also on resilience, cooperation and the ability to remain operational under all circumstances.

For organisations that are part of critical infrastructure, this reality is becoming increasingly familiar. They operate in an environment where IT and operational technology (OT) are becoming more closely intertwined, dependencies within international supply chains are increasing and legislation is placing greater demands on directors.

At the same time, staff shortages, legacy systems and the constant flow of new threats remain daily challenges.

Cyber risks

This makes cyber resilience a clear governance issue. Digital risks have direct consequences for business continuity, public services and societal stability.

Boards can therefore no longer assign responsibility for digital resilience exclusively to the CISO or IT department. Just as financial risks and physical safety are part of good governance, cyber risks must now be treated in the same way.

“Digital resilience can never be organised solely on an individual basis.”

There is, however, a second question that is at least as important. Even when organisations have their own security in order, they remain dependent on suppliers, partners, governments and other parties within the chain.

Critical infrastructure consists of a network of interconnected organisations. Digital resilience can therefore never be organised solely on an individual basis.

Societal continuity

Cooperation is therefore becoming a strategic necessity. Sharing threat intelligence, conducting joint exercises, developing uniform standards and strengthening public-private cooperation are no longer optional initiatives. They are essential conditions for safeguarding societal continuity.

This requires trust, transparency and a willingness to look beyond organisational boundaries. In practice, however, this is often difficult because of differing interests, responsibilities and levels of maturity.

The central question therefore shifts from “How do we secure our organisation?” to “How do we ensure that society as a whole remains digitally resilient?”

This requires a fundamentally different way of thinking about ownership. Cyber resilience is no longer the exclusive responsibility of the CISO, CIO or Defence. It is a shared responsibility of directors, government, businesses and the organisations that together form our critical infrastructure.

Who owns cyber resilience?

This is exactly the tension that Mietta Groeneveld and Jeroen Gaiser will explore during their joint session at Cybersec Netherlands 2026 on 10 September at 13:05.

Drawing on their different responsibilities, they will show how the strategic reality of geopolitical threats and the daily practice of Dutch critical infrastructure are increasingly converging.

Not to provide simple answers, but to start the conversation around a question that every board should now be considering:

Who owns cyber resilience when everything is connected?

Register for free for Cybersec Netherlands 2026

As cyber attacks continue to threaten today’s tech landscape, this event is the premier platform for seasoned cyber security professionals and innovative start-ups to exchange knowledge and tackle cybersecurity challenges together. Organizations across all sectors will discover strategies to boost cyber resilience and safeguard critical assets. Don’t miss this chance to strengthen your cyber defenses, register for free now!