From Compliance to Control: IRM360 on Building Cyber Resilience
Marcel Lavalette, CEO and Product Owner of IRM360, discusses fragmentation as the most underestimated cyber threat, the growing stack of legislation and why governance is the true foundation of cyber resilience.
Marcel Lavalette has watched information security move from the server room to the boardroom. As CEO and Product Owner of IRM360, he built the CyberManager platform around one conviction: compliance is not achieved by ticking boxes, but by governing well.
Ahead of Cybersec Netherlands 2026, where IRM360 returns as an exhibitor, he shares what he is seeing in the market, from supply chain ransomware to the wave of legislation reshaping how organisations are governed.
At a glance
- The most underestimated threat is not a single attack technique, but fragmentation. Without overview, there is no control.
- The Dutch Cybersecurity Act, the national implementation of NIS2, makes directors explicitly accountable and turns the CISO from an administrator into a strategic advisor.
- Technology never replaces people. A GRC platform supports expertise and ownership, just as accounting software does not replace an accountant.
- The problem is rarely the absence of information or security measures. The challenge is bringing everything together into one coherent management system that supports better decisions.
What are the most pressing cybersecurity threats today?
The most underestimated threat is not a single attack technique, but fragmentation. Organisations depend on a growing web of systems, cloud services and third party suppliers, each with its own vulnerabilities. Risk information is scattered across tools, documents and spreadsheets. Without overview, there is no control, and without control, incidents escalate faster than organisations can respond.
Recent ransomware attacks have shown how a single compromised supplier can disrupt an entire chain, while attackers are becoming more professional through AI generated phishing and deepfake fraud.
The real challenge is regaining insight and coherence, so that boards, managers and specialists can act on the same reliable information.
Which trends are shaping the industry?
The biggest shift is that information security is no longer seen as a purely technical subject, but as a boardroom responsibility. With the Dutch Cybersecurity Act, the national implementation of NIS2, directors become explicitly accountable for cyber resilience.
That changes the conversation. The CISO is evolving from an administrator into a strategic advisor.
A second trend is the growing stack of legislation and frameworks. ISO 27001, the Dutch Cybersecurity Act and NIS2, DORA, the AI Act and soon the Cyber Resilience Act each affect different aspects of how an organisation is governed.
Running a separate project or tool for every new requirement is becoming unsustainable. Organisations are therefore moving towards continuous, integrated governance, in which compliance is a logical outcome rather than the goal itself.
“You do not become compliant by ticking boxes. You become compliant because your organisation is well governed.”
How does IRM360 address these challenges?
When risks are up to date, responsibilities are clearly assigned, measures demonstrably work and management can make decisions based on reliable information, compliance follows almost naturally.
CyberManager translates that conviction into practice through modular, best of breed management systems for information security, privacy, quality, AI governance and risk management, all connected within one governance platform. Organisations can start small and scale as they mature.
Technology, however, never replaces people. The real challenge is not designing governance for experts, but making it practical for organisations with limited resources, knowledge and experience.
Together with its implementation partners, IRM360 helps organisations embed knowledge structurally, instead of allowing it to disappear when employees leave.
Why is Cybersec Netherlands an essential industry event?
Cybersecurity is ultimately about people and cooperation, and that is exactly what Cybersec Netherlands enables. Nowhere else do we speak with so many CISOs, compliance officers and directors in such a short period of time about what is really keeping them busy, from NIS2 readiness to supply chain assurance.
These face to face conversations sharpen our thinking and our product. They also help the wider community. Honest exchanges about what works, and what does not, raise the resilience of the entire Dutch cybersecurity ecosystem.
As a returning exhibitor, IRM360 sees Cybersec Netherlands not simply as an exhibition, but as a catalyst: a place where sharing knowledge today can help prevent incidents tomorrow.
IRM360 looks forward to continuing that conversation at Cybersec Netherlands 2026.
Register for free for Cybersec Netherlands 2026
As cyber attacks continue to threaten today’s tech landscape, this event is the premier platform for seasoned cyber security professionals and innovative start-ups to exchange knowledge and tackle cybersecurity challenges together. Organizations across all sectors will discover strategies to boost cyber resilience and safeguard critical assets. Don’t miss this chance to strengthen your cyber defenses, register for free now!