Hartwich Risk & Resilience
Reality CheckQuestionsOutputInsightsMethodContact
NL|EN
Discuss your question
Reality CheckQuestionsOutputInsightsMethodContact
NL|EN
Discuss your question
← Back to insights
Insight · IT · Cyber

Outside supervision, not outside the risk

The debate about digital dependency is about vital sectors and central government. In mid-sized companies the dependency is just as absolute, without anyone asking about it.

In this insight
  1. Why this matters now
  2. Why this is a board-level matter
  3. What I typically see
  4. The questions this raises
  5. You are not on your own
  6. What a Reality Check delivers here
  7. In short

At some point a renewal lands on your desk. The contract with the party that runs your systems, holds your data or supports your operations. Everything works, there are no complaints, there is no reason to look again. You sign.

That is a decision. It simply does not feel like one, because nothing has changed. And that is precisely what makes it one: by signing, you confirm a dependency that nobody has reassessed since it came into being.

In July 2026 two advisory reports appeared on this subject. The Dutch Cyber Security Council warned the government about the continuity of telecom and internet networks. Five supervisory authorities called on government and business to move faster towards digital autonomy.

Both are worth reading. Both are about someone else.

They are about national infrastructure, about central government, about vital sectors and financial institutions. About purchasing power and European alternatives. The company with fifty employees does not appear in them, while the dependency there is no smaller. Often it is more absolute, because there is less to fall back on.

The difference is not the degree of dependency. The difference is that nobody comes to ask you about it.

Why this matters now

On 15 August 2026 the Dutch Cybersecurity Act enters into force. More than eight thousand organisations in the Netherlands acquire new obligations. Two of those are matters of governance rather than technology: the board carries ultimate responsibility for managing cyber risk, and directors must have sufficient knowledge to assess risks and measures themselves.

For part of the mid-market that applies from that date. For another part it does not. And a considerable group has not yet established which of the two applies to them. The government places that question emphatically with the organisation itself: you are responsible for determining whether you fall within scope.

Determining that is therefore already an act of governance. Those covered by it know a standard applies and that their board is accountable for it. Those outside it know they must set their own. Those who do not know have neither.

And that is the heart of it. Falling outside the law does not reduce the risk. It only means nobody puts it on your agenda, and that there is no date by which it has to be done.

Why this is a board-level matter

The question is not whether you are satisfied with your supplier. The question is whether you can demonstrate that switching is possible if it becomes necessary. And whether that has ever been tested, or exists only on paper.

That distinction is a governance matter, not a technical one. A contract with a supplier is an operational decision. Accepting the risk underneath it, without an alternative and without a tested way out, is a board decision. Even if nobody has called it that.

There is one distinction most organisations fail to make: not every process requires the same. A system you can do without for a week deserves a different assessment than the system your invoicing depends on. Anyone who does not make that difference explicit is tacitly treating everything as non-critical.

That requires no procurement department and no compliance function. It requires a conversation in which the question is asked.

What I typically see

  • the choice for this supplier was made years ago, by someone who no longer works here, and has never been reconsidered since
  • a plan to switch was once drawn up because a client asked for it, and has never been tested since
  • nobody on the board knows precisely what the contract says about termination and the return of data
  • the question "what if they fail" has never been asked, precisely because the supplier has delivered well for years
  • there is an insurance policy, and nobody has worked out what it covers when the failure sits with the supplier rather than with you
  • one party carries several indispensable functions at once, without anyone ever having named that as concentration
  • at the last change of leadership this dependency was not handed over, because it was not written down anywhere
  • nobody can say whether the organisation falls under the new legislation
  • it is assumed that questions like these only arise at larger organisations
  • the question only reaches the table when a client, an insurer or a potential acquirer asks about it, and then under time pressure.

The pattern is not that organisations choose dependency. It is that the question is never asked. And whoever does not ask it has already answered it.

The questions this raises

  • Which processes must not come to a standstill, and for how long exactly is a standstill acceptable?
  • Which suppliers do those processes depend on?
  • Does one party carry several of those indispensable functions at once?
  • Is there a plan to switch away from each critical supplier?
  • Has that plan ever been tested, and what concretely shows it?
  • What does the contract say about termination, and who has read it?
  • Who inside your organisation is accountable for this dependency?
  • Does the organisation fall under the new legislation, and who established that?
  • Which dependencies have been accepted simply by changing nothing?

These questions return digital dependency to where it belongs. Not to a technical discussion, but to a board-level conversation about what you are prepared to risk.

You are not on your own

One point from the supervisors' advice deserves attention, particularly for smaller organisations. This is not a problem you solve alone. Facing a large supplier, you have no negotiating position. Together with other customers in your sector, you do, and according to the supervisors there is more room for that than companies tend to think.

The same goes for your contract. You have more right to your own data, and to taking it with you, than most organisations make use of. But a right you neither know about nor invoke makes no difference at all.

What a Reality Check delivers here

A Reality Check does not examine your entire supplier base. It starts from one concrete board-level question and makes visible what is demonstrable and what is an assumption.

On this subject, that typically produces:

  • a sharp picture of the process or supplier the question concerns
  • an overview of how many indispensable functions actually sit with the same party
  • the distinction between a plan on paper and a plan with a tested outcome
  • insight into what the contract genuinely arranges on termination
  • an established answer to whether the new legislation applies
  • the distinction between what justifies additional safeguards and what does not
  • decision points for the board, sharp enough to make the trade-off yourself
  • clear ownership: who monitors this, and when do we look at it again.

What a Reality Check does not deliver is a cost estimate or an improvement programme. What something costs depends on choices still to be made. That trade-off is yours, and it stays yours.

The value does not lie in a verdict on your supplier. The value lies in making visible a choice that was never made explicitly.

In short

The debate about digital autonomy is about vital infrastructure and systemic risk. Rightly so. It is simply not the whole story.

At the company that falls outside all those frameworks, nobody comes to ask whether the plan works. That does not make the question less urgent. It only means you have to ask it yourself.

A plan to switch that has never been tested is not a plan. It is an assumption with a supplier inside it.

Sources
  1. Dutch Cyber Security Council, Verbinding onder druk (Connection under pressure), advisory report to the Dutch government, 9 July 2026.
  2. ACM, AFM, AP, DNB and RDI, De route naar digitale autonomie (The route to digital autonomy), position paper, 10 July 2026.
  3. Government of the Netherlands, Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht (Dutch Cybersecurity Act and Critical Entities Resilience Act in force from 15 August 2026), news release, 7 July 2026.

Test this for your organisation?

Would you like to assess this topic for your own organisation? Discuss your question in a short conversation.

Discuss your question
Hartwich Risk & Resilience

Make digital dependency governable.

Website

Reality CheckQuestionsOutputInsightsMethodContact

Legal

Privacy StatementCookie StatementDisclaimerGeneral Terms

Follow Hartwich Risk & Resilience

LinkedInInstagram
CoC 76948773 · VAT NL003133490B55 · Sittard · hartwichrisk.com

We use analytics cookies (Google Analytics) to improve this website. Cookie statement