Malik Haidar is a veteran cybersecurity strategist who has spent his career at the intersection of technical defense and high-level business intelligence. Having navigated the complex threat landscapes of various multinational corporations, he understands that a truly resilient organization is built on more than just software updates. Malik focuses on the synergy between information technology and operational technology, a perspective that is more critical than ever as the new Cybersecurity Act draws near. In this discussion, we explore the shift toward a unified, risk-driven security model that bridges the gap between boardroom leadership and technical infrastructure.
The Cybersecurity Act taking effect on August 15, 2026, marks a significant shift in how Dutch organizations must handle digital safety. How do you see this new legislation changing the daily operations for companies providing essential services?
The introduction of this Act is a transformative moment for the industry, as it officially replaces the old Network and Information Systems Security Act, commonly known as the Wbni. For organizations that provide essential or important services, the daily grind now involves much more than just basic perimeter defense. They face a formal registration obligation and a strict duty of care to implement security measures that are truly proportionate to the risks they face. We are moving away from a world of optional guidelines into one where reporting significant incidents is a legal mandate that demands immediate action. It requires a fundamental shift in culture, where cybersecurity is seen as a foundational pillar of business continuity rather than a secondary IT expense.
In your experience, cybersecurity was often viewed as a task for the IT department, but the new Act emphasizes an organization-wide challenge. What does this mean for the leadership teams who now find themselves legally responsible for oversight?
Management can no longer afford to sit on the sidelines and treat cybersecurity like a technical problem they do not need to understand. The Act makes it clear that cyber resilience involves management, operations, IT, and OT departments working in unison to protect the entire digital environment. There are now much stricter requirements relating to management and supervision, meaning that directors are personally responsible for the oversight of their security posture. This forces leadership to adopt a risk-based approach, ensuring that they are not just spending money, but investing in technical and organizational measures that protect their specific assets. It turns the C-suite into active participants in the defense strategy, requiring them to understand exactly how a breach could paralyze their entire production line.
You’ve often highlighted the vulnerability of operational technology (OT) in industrial settings. How does the current focus of the Cybersecurity Act address the historical neglect of process automation systems?
For too many years, industrial organizations focused their security efforts almost exclusively on office IT, while the process automation on the factory floor was left to evolve organically. The Cybersecurity Act fixes this dangerous oversight by making no distinction between IT and OT, requiring the security of the entire digital environment to be managed under one umbrella. We frequently encounter OT systems that have operated reliably for decades but were never designed to withstand the sophisticated cyber threats we see today. As these legacy systems become increasingly connected to modern IT networks to drive efficiency, the attack surface grows significantly across both domains. This legislation forces companies to acknowledge that an insecure OT domain is a direct threat to the resilience of the entire organization, demanding that industrial systems receive the same level of protection as a corporate server.
You’ve stated that resilience begins with visibility, yet many organizations lack an up-to-date overview of their infrastructure. Why is this lack of insight such a critical barrier to meeting the requirements of the new legislation?
The simple truth is that you cannot defend an asset if you do not even know it exists on your network. Because many IT and OT environments have grown over many years without a master plan, organizations often lack a comprehensive, up-to-date overview of their own infrastructure. This visibility is the foundation of the duty of care required under the new Act; without it, you cannot possibly identify where your vulnerabilities are or how your systems communicate with one another. We need to be asking deep questions about what assets are present and what specific risks they pose to production continuity and data integrity. Gaining this clear picture is the mandatory first step toward building a resilient framework that can actually withstand a targeted attack. Without that visibility, any security measure you implement is just a shot in the dark that likely misses the most critical risks.
Moving from mere compliance to active resilience is a complex journey. What are the first concrete steps an organization should take to build a roadmap that aligns with these new regulations?
The journey starts with an integrated approach that finally brings IT and OT together under a single, unified risk management strategy. Organizations must first determine if they fall within the scope of the new legislation and then conduct a thorough risk assessment to identify their most urgent priorities. This assessment provides the solid starting point needed to develop a targeted roadmap that isn’t just about passing an audit, but about long-term digital strength. It is about choosing proportionate technical and organizational measures that secure the most vital processes while training employees to be the first line of defense. By focusing on these core actions, a company can transform the burden of regulatory compliance into a strategic advantage that ensures they remain operational no matter the threat.
What is your forecast for cyber resilience?
My forecast is that we are entering an era where the divide between physical operations and digital security will vanish entirely as companies realize that one cannot exist without the other. As we move past the August 15, 2026, implementation date, the organizations that have invested in visibility and integrated management will see a significant decrease in the impact of digital disruptions. We will likely see a more collaborative environment where Dutch organizations share intelligence more freely to meet their reporting obligations under the new law. Ultimately, this shift will lead to a more robust industrial sector where cyber resilience is no longer a luxury for the few, but a standard operating procedure for the many.

