Knowledge base
Practical articles on the NIS2 supply chain obligation, your digital attack surface and evidence-first vulnerability monitoring.
NIS2 & Cybersecurity Act
The Dutch Cybersecurity Act takes effect on 15 August 2026, without a transition period. What NIS2 and the supply-chain duty of care really require of you, and why you have to demonstrate it, not just declare it.
Published on August 16, 2026
Is a vulnerability scan mandatory under NIS2?
NIS2 does not mandate any tool by name, including vulnerability scans. What the law does require: appropriate measures you can demonstrate.
Read article →Published on July 11, 2026
Do I fall under NIS2? How to determine whether your organisation is an essential or important entity
Sector plus size determine whether your organisation falls under NIS2 and the Dutch Cybersecurity Act. Walk through the self-check: which sectors, which thresholds, the exceptions, and what to arrange before 15 August 2026.
Read article →Published on July 7, 2026
Dutch Cybersecurity Act final: NIS2 applies in the Netherlands from 15 August 2026
The Dutch Senate has adopted the Cybersecurity Act and the Critical Entities Resilience Act. Both enter into force on 15 August 2026. What does this mean for your organisation and your suppliers?
Read article →Published on June 16, 2026
What is actually required under the NIS2 supply-chain duty of care (and what is not)?
NIS2 does not mandate any specific tool. Learn what the supply-chain duty of care really asks of you, when the Dutch Cybersecurity Act takes effect, and how to substantiate it with evidence.
Read article →Published on June 12, 2026
How do you answer a NIS2 supplier questionnaire? A practical guide for SMEs
A NIS2 supplier questionnaire from your large customer on your desk? How to answer the four themes that follow directly from the NIS2 requirements (patch management, MFA, incident response and your own suppliers), with evidence the assessor takes seriously.
Read article →Published on June 12, 2026
The NIS2 roadmap for public-sector boards: from duty of care to demonstrable compliance
A practical NIS2 roadmap for public-sector boards: from duty of care to demonstrable compliance in five steps. With concrete actions for scope, training, monitoring, incident response and the audit trail.
Read article →Published on June 5, 2026
NIS2 and joint and several liability: what public-sector directors should and should not fear
NIS2 makes cybersecurity a board-level responsibility. Read what this means for public-sector directors, liability, duty of care, training obligations and demonstrable risk management.
Read article →Published on May 26, 2026
Scanning is not NIS2 compliance. But it is a necessary building block
An honest take: scanning for vulnerabilities does not make you NIS2 compliant. But it does provide defensible evidence for vulnerability management and the supply-chain duty of care.
Read article →Published on May 12, 2026
What does your large customer ask under the NIS2 supply-chain duty of care?
Through the supply-chain duty of care, NIS2 and the Dutch Cybersecurity Act also affect SME suppliers. What your large customer expects of you and how to demonstrate basic cyber hygiene.
Read article →
Attack surface & vulnerabilities
What your organisation exposes to the outside world, and how to find and prioritise vulnerabilities before an attacker does.
Published on July 11, 2026
Not every vulnerability is equally urgent: EPSS and KEV explained for decision-makers
A scan report with dozens of findings: what comes first? EPSS predicts the likelihood of exploitation, the KEV catalogue shows confirmed exploitation. This is how you prioritise by actual risk instead of severity scores alone.
Read article →Published on July 11, 2026
Penetration test or vulnerability scan: the difference, and what your organisation needs under NIS2
A penetration test and a vulnerability scan are not synonyms. What is the difference, what do they cost, what does NIS2 expect and in what order should you deploy them? A guide for boards and decision-makers.
Read article →Published on July 11, 2026
What is vulnerability monitoring, and why a one-off scan is not enough
Vulnerability monitoring is the continuous surveillance of your systems for vulnerabilities. Why does a one-off scan or pentest age so quickly, what does NIS2 expect, and what should you demand from good monitoring?
Read article →Published on July 3, 2026
internet.nl is free. So when do you need Exposentry?
internet.nl is an excellent free starting point for modern internet standards. But a snapshot and an evidence file are two different things. When a free check is enough, and when it is not.
Read article →Published on June 16, 2026
EASM for SMEs and the supply chain: know and manage your external attack surface
Your external attack surface changes constantly. What External Attack Surface Management (EASM) is, why SMEs and the supplier chain need it, and how to manage it with evidence.
Read article →Published on June 16, 2026
What is OpenKAT, and what it is not
OpenKAT is a free, open-source vulnerability analysis tool, originally built by the Dutch Ministry of Health and now maintained by the community. Not a mandatory SaaS, not a certification.
Read article →Published on June 12, 2026
Shadow IT and NIS2: how do you manage and secure unknown digital assets?
Shadow IT is the biggest blind spot under NIS2. Learn how to manage your external attack surface: prevent subdomain takeover, find exposed admin panels and track down expired certificates with continuous monitoring.
Read article →Published on May 19, 2026
What does an attacker see of your domain?
Your attack surface in plain English: DNS, open ports, TLS, subdomains, exposed panels and CVEs. What an attacker sees and why monitoring matters.
Read article →
Evidence & reporting
From a list of vulnerabilities to traceable, independent evidence that auditors, insurers and boards can trust.
Published on July 3, 2026
Independent reporting: why your IT provider should not judge its own work
A security report that reaches you through your IT provider is judging that provider's own work. Why that weakens your evidence and what independent reporting means.
Read article →Published on June 16, 2026
Forensically substantiated evidence: what auditors and insurers really want to see
A list of vulnerabilities is not evidence. Auditors, cyber insurers and large customers want traceable, dated evidence. What that is and how to build it.
Read article →Published on June 12, 2026
From CVE list to board report: how do you filter cyber noise for the board?
You don't build a cybersecurity board report by summarising a CVE list. How to filter noise using exploitability and exposure, and build a NIS2 dashboard the board can actually steer on.
Read article →Published on June 5, 2026
For CISOs: from vulnerability list to board-level evidence
CISOs need more than a list of vulnerabilities. Discover how evidence-first vulnerability monitoring helps make attack surface, risks and remediation demonstrably governable.
Read article →
Guides & settings
Practical steps: verify your domain, set up mail records (SPF, DKIM, DMARC) and check a security report.
Published on July 17, 2026
SPF, DKIM and DMARC explained: why domains that never send email need these records too
SPF, DKIM and DMARC explained with example records. Plus the blind spot: domains that never send mail, null MX, and what MTA-STS, DANE, BIMI and CAA add.
Read article →Published on June 26, 2026
Verifying an Exposentry report: digital seal and timestamp
By default we digitally seal and timestamp every Exposentry report. Here is how to confirm a report is genuinely ours and has not been altered, using our public certificate and its fingerprint.
Read article →Published on May 29, 2026
Verifying your domain: step-by-step guide
Prove ownership of your domain in three ways: a DNS TXT record, a file on your web server, or an HTML meta tag. One method is enough for most plans; the NIS2 plans require two. Includes provider examples and fixes for common problems.
Read article →
Published on August 23, 2026
Extern aanvalsoppervlak monitoring: bewijs voor uw auditor
Extern aanvalsoppervlak monitoring uitgelegd: wat een scan van buiten vindt, hoe u het inricht en hoe rapporten bewijs leveren dat bij een audit standhoudt.
Read article →Published on August 22, 2026
NIS2 compliance checklist: aantoonbaar voldoen in 2026
NIS2 compliance checklist voor de Cyberbeveiligingswet: scope bepalen, de tien maatregelgebieden, meldplicht, boetes en het bewijsdossier waarmee u naleving aantoont.
Read article →Published on August 18, 2026
Technical vulnerability management under NEN 7510: what control 8.8 asks of healthcare organisations
Since the 2024 revision, NEN 7510 follows the structure and numbering of ISO 27001:2022. Management of technical vulnerabilities sits in it as control 8.8. What does the standard expect of a healthcare organisation, and how do you demonstrate it at an audit?
Read article →Published on July 28, 2026
Vulnerability management: the process, the standard, and how to prove it works
Vulnerability management is the continuous cycle of discovering, prioritising, remediating and verifying vulnerabilities. What does that process look like, what do ISO 27001, NEN 7510 and the Dutch Cybersecurity Act expect, and how do you demonstrate it works?
Read article →