Cyber incident response – bureau Brandeis publishes a step-by-step plan for dealing with a significant incident under the Cybersecurity Act
On 15 August 2026, the Cybersecurity Act (Cyberbeveiligingswet; “Cbw”) came into force. Under the Cbw, essential and important entities are required to report ‘significant incidents’ to their Computer Security Incident Response Team (“CSIRT”) and the competent regulator.
The statutory threshold for determining when an incident is significant is set out in Article 25(2) of the Cbw: an incident is significant if it:
(a) causes or is likely to cause a serious operational disruption or financial loss to the entity, or;
(b) causes or is likely to cause significant material or immaterial damage to other entities.
These criteria are open-ended. Ministerial regulations further specify the reporting obligation for each sector, setting out more precise thresholds. For example, read our blog on the ministerial regulation for the digital infrastructure sector.
Is your company (potentially) dealing with a significant incident? If so, please refer to the step-by-step guide below, or download the guide here.
If you would like to receive a hard copy (in poster form) of this step-by-step guide, please contact a member of bureau Brandeis’ Cybersecurity Team (Machteld Robichon, Lucas de Vet or Bente van Kan).

