NIS2 compliance means healthcare organizations must now prove that cybersecurity risk is managed at every level: internal systems, suppliers and reporting lines. That requirement is pulling security out of the IT department and into the boardroom. The organizations struggling most aren't the ones lacking tools. They're the ones lacking people who can connect law, controls and clinical operations.
For years, healthcare cybersecurity ran on NEN 7510, the Dutch standard for information security in healthcare. That standard hasn't disappeared. But the legal duty of care around it has become sharper, and with it comes a set of roles that most healthcare organizations simply don't have on the payroll yet. This isn't a story about new software. It's a story about who gets hired next.