Showing Posts From
Operational excellence

- 13 Aug, 2026
From Waiting Too Long to Moving Ahead: Why Cbw and AI Governance Need One Clear Plan
In the Netherlands, waiting until the very last moment to deal with new rules is very common. For a long time, the standard approach to IT security was simple: "They won't check us yet," or "Let's wait and see what others do." With the European NIS2 directive and the new Dutch cybersecurity law — the Cyberbeveiligingswet (Cbw) — that time is over. The laws are active, supervision is starting, and the final responsibility now sits directly with company directors and executive management. Viewing the Cbw as just a burden or a boring checklist is a mistake. At the same time, the EU AI Act and frameworks like ISO 42001 are coming at us fast. Treating these as completely separate projects will waste budget and burn out your team. The smartest move is to stop waiting and combine IT security and AI governance into one clear strategy. The Cyberbeveiligingswet (Cbw): Why Waiting Is No Longer an Option The goal of NIS2 and the Cbw is simple: raise the basic level of digital security across Europe. The old rules mostly applied to traditional vital sectors like energy and water. The new Cbw applies to many more organizations. Medium and large companies in logistics, food, chemistry, digital services, and IT providers (MSPs and MSSPs) now fall under the law. Because of this, supply chain security becomes a shared legal responsibility. Two core parts of the Cbw change how companies must operate:Duty of Care & Fast Reporting: Companies must prove they take the right technical and organizational security steps. If a major incident happens, strict rules apply: a first warning must be sent to regulators within 24 hours. Personal Board Responsibility & Mandatory Training: Directors can now be held personally responsible if they ignore basic security rules. On top of that, executives are legally required to take regular training to understand cyber risks. Leaving IT security completely to the IT department without director oversight is no longer allowed by law.BIO2 Becomes Law: Your Foundation Is Already There For Dutch government bodies and their IT suppliers, an important change is happening. The Baseline Informatiebeveiliging Overheid (BIO2) is moving from a voluntary framework to a binding law under the Cyberbeveiligingsbesluit. While many organizations worry about this, the truth is that BIO2 gives you a solid foundation you might already own. It builds on well-known global standards:ISO/IEC 27001: The process foundation for security management (ISMS). It sets up risk checks, policies, and continuous improvement. CIS Controls: The practical, technical checklist. Where ISO tells you what goals to reach, CIS Controls give you a concrete list of actions (device management, multi-factor authentication, logging, and endpoint protection).If your organization already works with ISO 27001 or BIO2, you already cover most of the technical requirements of the Cbw. The AI Side: Don't Build Another Separate Project At the same time, company boards are hearing about the EU AI Act and ISO 42001 (the standard for Artificial Intelligence management). The usual reaction is to push AI away: "Let's finish the Cbw project first. We will worry about AI in a few years." This is a missed opportunity. If you compare BIO2 and ISO 27001 with ISO 42001, you see something interesting: a company running a good ISO 27001 or BIO2 setup already covers 70% to 80% of what ISO 42001 requires. That is because AI management uses the exact same basics as normal IT security: risk checks, data rules, access management, supplier controls, and incident handling. You do not need to build a whole new management system. The Specific "AI Gap" The remaining 20% to 30% gap is very specific:AI Ethics & Fairness: Making sure algorithms work fairly without discrimination. Explanation & Human Control: Understanding how an AI tool reaches a decision and keeping a human in control (human-in-the-loop). Impact on People: Checking how the AI tool affects employees, customers, and privacy. AI Lifecycle Management: Checking data quality and monitoring if the AI model changes over time (data drift). AI Incident Handling: Preparing for new threats like prompt injection or accidental data leaks through AI tools.These extra steps are not a new system; they are just a direct addition to your current IT security setup. One Integrated Plan: Build It Once The AI Act timeline moves forward regardless of your Cbw deadlines. Companies that treat these things as three separate projects — one for Cbw, one for ISO 27001, and one for AI — will pay three times as much for the same result. The practical order to follow is: BIO2 / ISO 27001 Foundation ➡️ CIS Controls (Technical Setup) ➡️ ISO 42001 (AI Extension) Practical Steps to TakeCombine Risk Checks: Add AI tools and algorithms directly to your existing risk lists in your security management system. Use Clear Technical Rules: Use CIS Controls to secure your cloud environments (like Microsoft Azure) to meet the requirements for both Cbw and ISO standards. Extend Your Security Policies: Add the specific ISO 42001 points for AI ethics and control directly into your daily processes. Train the Board: Combine the required Cbw training for directors with a practical update on AI risks and opportunities.Closing Thoughts Putting off rules and regulations until the last minute no longer works. The Cyberbeveiligingswet, mandatory BIO2 rules, and the EU AI Act mean that IT security and AI are now direct topics for company leadership. Instead of running separate compliance projects, combining these standards into one clear plan turns a legal obligation into a practical advantage. You protect directors from liability, remain a trustworthy partner in your supply chain, and build a safe foundation to use AI effectively in your business.

Rolf Schutten- 12 Aug, 2026
Why AI pilots stall on operational reality (and how to build real value)
Almost every organization is investing heavily in Artificial Intelligence. Budgets are expanding, executive teams are eager, and press releases about new AI pilots appear daily. Yet behind boardroom doors, the reality is far more frustrating. According to a global CEO survey by Bain & Company, 80% of chief executives are unhappy with the progress of their AI programs. Even more telling, 85% report that their organizations have failed to turn AI experiments into lasting, structural change. Research from Gartner shows a similar picture: only 28% of AI projects in infrastructure and operations fully succeed and meet their expected return on investment (ROI). Why are so many organizations getting stuck? Why do promising AI experiments fail the moment they touch day-to-day operations? In my work advising and leading IT service organizations—the companies I work with—I see this pattern repeatedly. The problem is rarely the underlying AI technology or the models themselves. The problem is that companies are trying to plug modern AI into outdated, fragmented, and disorganized operational foundations. The "humanoid theater" and the layoff illusion To understand why AI transformations stall, we must first look at where companies spend their energy. Many organizations get distracted by what can be called "humanoid theater"—flashy demonstrations of chatbots, novel tools, or complex dashboards that look impressive in demos but fail to improve the bottom line. At the same time, we see a troubling trend across the technology sector. Over 160,000 jobs have been cut across tech companies in recent months. Wall Street often rewards leaders who label these mass layoffs as an "AI efficiency strategy." But cutting headcount without redesigning your operational workflows is not an AI strategy; it is simply reducing capacity while keeping the same inefficient processes. Real value is not created by buying a shiny new software tool or cutting workforce numbers. It is created by doing the hard, complex work: integrating AI deeply into legacy IT systems, unifying fragmented data sources, and reshaping daily workflows. This explains why established IT integrators and software providers are seeing strong growth. They solve the difficult integration challenges that prevent most companies from scaling. Fix the process before adding the technology A major misconception among business leaders is that deploying new technology automatically drives adoption and business results. If your underlying business processes are confusing, inconsistent, or broken, adding AI will only automate that confusion at higher speed. As an executive, you often need to act as the organization's traffic light. Turning lights green for good ideas is easy, but your most critical decisions are the red lights: stopping teams from wasting time, money, and energy on the wrong initiatives. Before layering AI into your business, you must build a strong operational foundation:Standardize core workflows: Simplify business processes and remove unnecessary manual handoffs between teams. Clean and organize data: AI outputs depend directly on data quality; un-silo your systems and establish clear data ownership. Remove daily friction: Focus first on administrative tasks and repetitive work that slow down your employees.In a recent operational transformation, standardizing and consolidating service management processes reduced support ticket volumes by 30% on its own. Only after that clean operational foundation was established did adding automation and AI capabilities bring total ticket reductions close to 70%. The primary gain came from operational discipline; technology simply accelerated the result. [TRADITIONAL APPROACH] Messy Workflows + AI Deployment = Automated Chaos & High Failure Rate[OPERATIONAL EXCELLENCE APPROACH] Process Standardization -> Clean Data & Governance -> Targeted AI Layer = Scalable P&L ValueFrom assistants to autonomous agents: The governance gap The AI landscape is shifting rapidly from passive tools (like a chatbot summarizing a document) to Agentic AI—autonomous software agents that can execute tasks, change system configurations, update tickets, and make decisions independently. This evolution fundamentally changes an organization's risk profile. An employee typing an awkward prompt into a chat interface is a minor issue. An autonomous AI agent carrying full employee access rights and executing dozens of automated system actions is a major operational risk. Boardrooms and executive teams must address new governance questions:Identity: Who or what is authenticated when an AI agent acts on behalf of an employee? Authorization: What specific system boundaries and guardrails limit the agent's actions? Accountability: Who is responsible when an autonomous agent makes an incorrect decision?Without clear governance, companies risk creating a dangerous new form of shadow IT. Furthermore, as software takes over operational execution, traditional service models built purely on billable hours will face severe pressure. Successful companies will build AI-by-design operating models where software handles repetitive execution, allowing human teams to focus on strategy, quality, and high-value customer relationships. Measure business impact, not activity AI programs lose momentum when leadership measures activity instead of real outcomes. The P&L statement does not care how many Copilot licenses you have assigned or how many pilots you have launched. To build sustainable value, executives must track hard operational indicators:Reductions in service turnaround times and cycle times. Improvements in gross margin and unit economics. Reductions in error rates and operational incidents. Scalability—handling higher business volumes without increasing headcount proportionally.Scaling technology requires active change management and leadership. Avoid broad, blanket rollouts that confuse employees. Instead, deploy capabilities in phases, focus on specific team cohorts, and clearly demonstrate how the tools improve daily work. Building scalable value Artificial Intelligence is a powerful lever, but a lever only works if it rests on a solid fulcrum. Companies do not fail with AI because they lack advanced algorithms. They fail because they lack execution discipline, clear governance, and standardized processes. The market leaders of tomorrow will not be the companies running the most AI pilots, but those that build an operational foundation capable of turning technology into predictable, scalable performance. Closing thought Technology will not fix a broken operational model, but leaders who build disciplined, adaptable organizations will use AI to widen their competitive advantage rapidly. The goal of AI transformation is not to turn managers into programmers or replace human judgment with automated software. It is about creating the operational clarity, governance, and culture needed for people and technology to perform at their best together. Stop looking for quick AI wins. Start building the operational foundation that turns technology into real value.