Skip to main content

Security scan

The security scan is a structured assessment of an organisation's information security against the requirements of the Baseline Informatiebeveiliging Overheid (BIO, the Dutch government's information security baseline) and, where relevant, the NIS2 directive.

Two colleagues talking across a meeting room table
Colleagues talking in a glass-walled meeting booth

Why the security scan?

The security scan is a structured assessment of an organisation's information security against the requirements of the Baseline Informatiebeveiliging Overheid (BIO) and, where relevant, the NIS2 directive. BIO applies to municipalities, provinces, water authorities and other government organisations. NIS2 places comparable requirements on organisations in vital and important sectors, with stricter requirements for risk management, incident response and board-level accountability.

The scan assesses both technical measures, such as access security and logging, and organisational aspects, such as policy, responsibilities and incident response procedures.

Our approach

  1. 1

    Determine scope and framework

    We determine together which framework applies, BIO, NIS2 or a combination, and align the scope of the scan with the relevant systems and processes.

  2. 2

    Assessment against the framework

    We systematically assess technical and organisational measures against the requirements of the framework, based on documentation, interviews and, where relevant, technical verification.

  3. 3

    Determine maturity per domain

    We map out the maturity per domain, such as access security, logging, incident response and risk management, so it's clear where the biggest gaps are.

  4. 4

    Set priorities and an improvement plan

    We translate the findings into a concrete, prioritised improvement plan, distinguishing between quick wins and structural improvements that require more time and investment.

  5. 5

    Reporting for the board and regulators

    The scan results in a report suitable for sharing with the board, regulators or auditors, with a clear management summary alongside the detailed findings.

What does the compliancy scan deliver?

Maturity picture

A substantiated picture of the maturity of your information security per domain, assessed against BIO and/or NIS2.

Improvement plan

A prioritised improvement plan with a clear distinction between quick wins and structural improvements.

Usable reporting

A report that's immediately usable for the board, regulators and auditors.

Substantiated next steps

Insight into the risks of any gaps and a realistic starting point for next steps, without unnecessarily heavy measures.

  • Stadlander logo
  • Mourik logo
  • Evides Waterbedrijf logo
  • Gemeente Alphen aan den Rijn logo

Challenges within government organisations

Curious how we handle the challenges around guidelines and legislation within government organisations?

Challenges within government organisations

Ready to find out where you stand against BIO and NIS2?

Digital Survival Company carries out BIO/NIS2 compliancy scans for government organisations and organisations in vital and important sectors, with consultants experienced in the BIO, NIS2 and NEN7510 frameworks. Get in touch and let's discuss what the security scan delivers for your organisation.

FAQ

  • Does BIO apply to our organisation, or is that only for municipalities?

    BIO applies to municipalities, provinces, water authorities and central government. Other organisations, such as housing corporations or healthcare institutions, don't formally fall under BIO but sometimes use the framework as a reference. We determine together in advance which framework, BIO, NIS2 or another framework such as NEN7510, best fits your situation.

  • What's the difference between BIO and NIS2?

    BIO is specifically aimed at Dutch government organisations. NIS2 is a European directive that applies to organisations in vital and important sectors, with stricter requirements for risk management, incident response and board-level liability. Some organisations, such as certain government agencies, have to deal with both frameworks.

  • Is the scan enough to be demonstrably compliant?

    The scan gives a substantiated picture of your maturity and a concrete improvement plan, but formal compliance certification is usually a separate process, often with an external auditor. The scan is, however, a strong foundation to prepare for that and to demonstrate that you're structurally working on improvement.