Data governance: the basis for real information security

Updated on 9 September 2026: the Dutch Cyberbeveiligingswet has since come into force.

Data governance: the basis for real information security

Plenty of organisations still treat data as an IT question. That is too short a view, and it is shortest for CISOs and security teams. Data governance touches risk, compliance, incident response and board accountability directly. In a time of sharp rules and rising attack volumes it has stopped being optional: you have to be able to demonstrate that your data is under control.

The core question is a governance question. How do you make sure data is managed safely, responsibly and lawfully, from beginning to end?

More data means more exposure

Organisations collect more data every year: customer records, log files, HR files, external sources feeding AI. From a security perspective that means more attack surface and more information worth stealing in one place.

Without clear agreements about who owns what, how data is classified and what may be done with it, you get chaos. Data sits spread across systems and clouds, access rights have grown historically, and when an incident hits, the impact is hard to assess quickly. Which is exactly what an attacker needs.

Standards and directives: the difference, and why it gets muddled

In information security and compliance the words standard and directive get used interchangeably. They are two different things.

A standard (ISO 27001, NEN 7510) is a voluntary framework, technical or process-oriented, that helps an organisation implement security. It offers guidance. It is not law, so failing to meet it carries no fine.

A directive (NIS2, DORA) is a legal framework imposed by the EU or by national governments. It sets obligations with sanctions attached, and it is usually built on top of existing standards. NIS2 leans heavily on ISO 27001, and makes it mandatory for certain sectors.

The confusion arises because both work from the same principles. Organisations also tend to start with a standard and discover only later that a directive applies to them as well. So the distinction matters: standards help you secure, directives require you to.

For a CISO that means knowing which standards you use as your base and which directives you are supporting with them. Data governance is the bridge between the two.

ISO 27001: from systems to information

ISO 27001 asks you to treat information as an asset, assess the risks and take measures. In practice the focus lands on systems and tools, while the question “which information is genuinely critical?” often stays unanswered.

Data governance provides that clarity. Which assets are there, who owns them, how are they classified, and what level of protection do they need? That makes your ISMS stronger and better argued.

NEN 7510: governance in healthcare

For healthcare organisations data governance carries extra weight and is mandatory through NEN 7510. The standard covers protection of patient data, confidentiality and control over data exchange across care chains.

That asks for technical measures and for clear responsibilities, classification, logging and control over who may see or change what. Without clear ownership, insight into data flows and a grip on authorisations, compliance is close to impossible. For a CISO in healthcare, data governance serves patient safety and compliance at the same time.

NIS2: governance as an obligation

The NIS2 directive puts the emphasis on risk management, governance and board accountability. You have to identify risks systematically, manage them and account for them. Without insight into which data is critical or sensitive, that stays theory. Data governance makes impact analysis realistic, helps you set priorities, and shows that you are managing deliberately rather than reaching for ad-hoc measures.

NIS2 has applied to EU member states since 16 January 2023, and it does not reach individual organisations directly. A directive first needs translating into national law. In the Netherlands that is the Cyberbeveiligingswet (Cbw), which came into force on 15 August 2026. The Wet weerbaarheid kritieke entiteiten (Wwke), the Dutch implementation of the CER directive, took effect the same day. For organisations in scope, what counts from here is whether they can demonstrate that they have their data risk under control.

DORA: digital resilience in financial services

The Digital Operational Resilience Act (DORA) is the EU law requiring financial institutions to manage digital risk systematically, covering data, systems and third parties. Like NIS2 it emphasises board accountability, risk management and transparency. DORA goes further: it sets concrete requirements for incident reporting, ICT supplier management, and protection of critical data and processes.

Without clear data governance, meaning insight into which datasets are essential for financial stability, who is responsible for them and how they are protected, compliance stays theoretical. Data governance makes it possible to run impact analyses, set priorities, and show a supervisor that you are prepared technically as well as organisationally and legally.

Why this reaches beyond IT

IT manages systems. Data governance is about value, risk and lawfulness. That asks for involvement from the business, legal, compliance and risk. The CISO sets the frameworks, names the threats and translates data risk into security requirements. Ownership of the data itself sits with the business.

Alongside confidentiality and availability, the other two pillars of the CIA triad (Confidentiality, Integrity, Availability), integrity deserves attention of its own. Manipulated or unreliable data leads to wrong decisions, financial damage and compliance problems.

Data governance takes care of quality, provenance, clear definitions and control over data flows. That matters most in AI and automation, where faulty input turns directly into faulty output. Without integrity there is no real security, and no reliable operation either.

Incident response: know what the impact is

During a data breach or a ransomware event, knowing which data was hit makes the difference. Organisations with good data governance can assess impact faster, report to supervisors with more precision, and evidence the measures that were already in place. That reduces legal, financial and reputational damage.

A practical approach: from theory to action

So how do you get this pile of rules and obligations into your organisation in a usable form? The steps below are a first, practical move.

Map your critical data. Not only systems, but the datasets that are essential to your processes, your legal position or your strategy. That gives security direction.

Name data owners at management level. They determine value, approve access and monitor compliance. Security advises; the responsibility sits with the business.

Classify data by sensitivity, impact and compliance. Internal, confidential, strictly confidential. That links risk directly to a level of protection, including encryption, MFA, logging and export restrictions.

Review access and lifecycle. Roles change, projects end, systems disappear, and rights tend to stay behind unnoticed. Regular reviews prevent unnecessary privileges and keep data from being retained longer than it should be.

Make it visible. Put data risk into risk registers, KPIs and management reporting. Governance then becomes part of daily steering, and you can demonstrate that you manage risk actively.

Conclusion

For a CISO, data governance is not another project. It is the organisational layer that gives security direction and priority. Combined with NIS2, ISO 27001, DORA and NEN 7510, it turns security into a risk-led part of running the business rather than a technical function on its own.

Whoever has no grip on their data ends up with no grip on their risk either.

Sources

This article by Fred van den Heuvel was first published on the Digital Trust Community of the Dutch National Cyber Security Centre.

Where this meets the commercial side

Selling security into an organisation that has no grip on its data is a different conversation from selling into one that has. If your team is having that conversation, get in touch.

 

Leave a Reply

Your email address will not be published. Required fields are marked *