Netherlands Seeks Broader Intelligence Powers to Fight Foreign Cyberattacks

Netherlands Seeks Broader Intelligence Powers to Fight Foreign Cyberattacks

2026-08-29 data

The Hague, Saturday, 29 August 2026.
To counter rising cyber threats from China and Russia, a new Dutch proposal grants spy agencies expanded powers to hack and tap without requiring prior permission.

Unveiling the Legislative Push

On August 28, 2026, the Dutch government introduced a significant legislative proposal designed to bolster the operational capabilities of its primary intelligence services, the General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD) [1][2]. This proposal seeks to grant these agencies broader intelligence-gathering powers to counter increasingly sophisticated cyber threats and espionage operations, particularly those originating from state-sponsored actors in China and Russia [1]. By expanding these operational boundaries, the government aims to enable a much more agile and rapid response to digital incursions that threaten national security [1][2].

Streamlining Cyber Defense Operations

The new proposal serves as a replacement for the country’s controversial previous intelligence law, colloquially known as the ‘sleepwet’ (dragnet law) [2]. Under the newly proposed framework, the AIVD and MIVD will gain expanded hacking and wiretapping capabilities [2]. Crucially, the law reduces the frequency with which these agencies must secure prior permission before taking action against active cyber threats [2]. This structural shift is intended to remove bureaucratic delays, allowing intelligence officers to neutralize digital attacks and security breaches in real-time [2].

A Broader Shift in Dutch Digital Security

This intelligence-focused legislative push arrives on the heels of another major regulatory milestone in the Netherlands [GPT]. Just weeks earlier, on August 15, 2026, the Dutch Cybersecurity Act (Cyberbeveiligingswet, or Cbw) officially entered into force, replacing the older Network and Information Systems Security Act (Wbni) [4]. While the new spy agency proposal enhances offensive and defensive state intelligence capabilities [1][2], the Cbw focuses on fortifying the defensive posture of the private and public sectors [3][4].

The Regulatory Burden on Essential Sectors

The Cyberbeveiligingswet, which implements the European Union’s NIS2 cybersecurity directive, places strict risk-management and reporting obligations on more than 8,000 organizations across the Netherlands [4]. Entities operating within critical sectors, such as energy and digital infrastructure, are now legally required to implement robust measures to prevent and mitigate cyber incidents [3]. Furthermore, these organizations are mandated to report any significant security incidents and register themselves through the official ‘MijnNCSC’ platform managed by the National Cyber Security Center [4].

Strengthening Critical Infrastructure Resilience

Simultaneously, on August 15, 2026, the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, or Wwke) also came into effect, translating the EU’s CER directive into Dutch national law [4]. Under these combined frameworks, Dutch companies must independently assess whether they fall within the scope of the new regulations and complete their registration as soon as possible [3]. Together, these legislative updates represent a comprehensive, double-sided approach by the Dutch state: demanding higher defensive standards from private operators while equipping national intelligence agencies with the aggressive tools necessary to confront foreign cyber adversaries [1][3][4].

Bronnen


cybersecurity national security