Chapter 01
Bol’s own systems were not breached. Bol is still running the playbook.
On 1 August 2026 Bol was informed that CEVA Logistics, the warehousing partner behind its distribution centre in Waalwijk, had suffered a cyberattack. Unauthorised parties gained access to systems used to process orders from that site. Names, addresses, postcodes, email addresses, phone numbers, order numbers and track and trace data may have been accessed. Payment details, passwords and login credentials were not. Bol’s own systems were not breached. Bol and De Bijenkorf, which uses the same partner, notified affected customers on 5 August.
The breach was at the supplier. The notification obligation, the regulator conversation, the media coverage and the board attention all landed on the customer of that supplier.
Bol has been transparent about what happened. Notification to the Autoriteit Persoonsgegevens on 3 August, within forty-eight hours. External investigation. Coordinated customer communication. Board-level oversight. This is not a company scrambling. This is a company running a rehearsed playbook. Worth being precise about which clock was running: notifying the Autoriteit Persoonsgegevens is a GDPR obligation under Article 33. NIS2 carries its own, separate reporting schedule. Bol is in scope under NIS2 as a provider of an online marketplace under Annex II, which means it runs both regimes at once. That is what the rehearsal is for.
The scale behind that notification became clear over the following week. The attack on CEVA began on 29 July and affected eight warehouses across Europe. Ten organisations have filed breach reports with the Autoriteit Persoonsgegevens in connection with it. Alongside Bol and De Bijenkorf they include ING, Ajax, the eyewear brand Ace & Tate, and Valve, the company behind Steam. One compromised logistics provider, and the notification obligation landed on a bank, a football club, two retailers and a games platform in the same week.
For hospitality operators reading the news, the interesting question is not what Bol did. It is what happens to organisations that sit outside the formal NIS2 scope but end up caught in the same operational and regulatory cascade. That is the question this piece exists to answer.
Chapter 02
You are correctly not in scope. That is not the good news your board thinks it is.
NIS2 scope is a two-factor test. The sector, as listed in Annex I (essential entities) or Annex II (important entities). And the size, measured against thresholds drawn from the EU SME definition. As a rule both factors have to apply, subject to Article 2(2), which puts certain entity types in scope irrespective of size.
Sector filter, first
Annex I covers energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration and space. Annex II adds postal and courier services, waste management, chemicals, food processing and wholesale, several categories of manufacturing, research organisations, and digital providers of online marketplaces, search engines and social networks. Accommodation is not on either list. Neither is hotel management, hospitality services or any related sub-sector.
Size filter, second
If your organisation qualifies under one of the sector categories, size decides which bracket. You are a medium-sized enterprise, and so an important entity, from 50 staff, or below 50 staff if turnover or balance sheet total exceeds 10 million euro. You exceed the medium ceilings, and so become an essential entity under Annex I, at 250 staff or more, or if turnover exceeds 50 million euro and the balance sheet total exceeds 43 million euro. Exceeding those ceilings in an Annex II sector still leaves you an important entity. If your organisation does not qualify under a sector, the size filter never comes into play at all. A hotel group with 5,000 employees and 500 million euro in revenue remains outside the formal scope of NIS2. This is a stable fact.
What the sector filter cannot decide
What the sector filter does not decide is whether NIS2-level obligations still show up in the hospitality operating model. The directive is only one way those obligations arrive. There are three others, and for hospitality all three matter more than the directive itself.
Chapter 03
Above you and below you, everyone is in scope.
Hospitality sits between two layers of organisations that the directive does apply to. Above you, in the customer layer, are corporations increasingly bound by essential or important entity status. Below you, in the infrastructure layer, are the cloud and SaaS providers that carry your reservation systems, payment flows, guest communications and back office. Both layers are subject to NIS2. Both layers are contractually obliged to pass the requirement forward. You are the sandwich.
Three cascades already in motion, plus the national implementation question
The corporate customer cascade
Corporate customers who book conferences, off-sites and business travel with your properties are increasingly essential or important entities themselves. Banks, insurers, pharma, tech, government. Article 21 requires them to assess and manage the security risk in their direct supplier relationships, and for the venue that hosts their people and their data, you are one of those direct suppliers. Their procurement questionnaires, security clauses and audit rights are already changing. The next time a large customer signs a corporate rate agreement, they are also assessing whether their exposure at your venue is compatible with their own regulatory position.
The cloud infrastructure cascade
Under the old NIS Directive, cloud providers were digital service providers under Annex III, with light touch, ex post oversight. NIS2 brings cloud computing services into Annex I, digital infrastructure. Because the large providers comfortably exceed the size ceilings, they qualify as essential entities and fall under the comprehensive ex ante and ex post supervisory regime of Article 32. Their contracts are being rewritten with new shared-responsibility clauses and stricter security obligations for their customers. The reservation system, guest WiFi backend, financial ledger and payment gateway that run on that infrastructure inherit the terms of that contract. So do you.
The insurance underwriting cascade
Cyber insurance premiums have risen sharply across the hospitality sector. Underwriters now require evidence of exactly the controls that NIS2 imposes on essential and important entities: multi-factor authentication, endpoint detection, tested backup and recovery, documented incident response, supplier security assessment. The controls are the same. The pricing already reflects them. Only the accompanying regulatory support is missing.
The national implementation contingency
The Dutch Cyberbeveiligingswet entered into force on 15 August 2026, alongside the Wet weerbaarheid kritieke entiteiten. Its annexes mirror the directive, so accommodation stays outside, and the designation powers it grants work at the level of individual organisations within listed sectors rather than whole new sectors. Adding hospitality would take an amendment to the Act, not a ministerial decision. The sector boundary is therefore more stable than it looked. Which removes the comfortable excuse for waiting, because the other three cascades were never waiting on it.
The practical consequence is that NIS2-level obligations enter the hospitality operating model through the side door regardless of what the front door regulation says. Contracts with in-scope customers require them. Contracts with in-scope cloud providers require them. Insurance policies price them. The question is not whether the requirements arrive. The question is how you receive them.
Chapter 04
What “acting as if in scope” actually requires.
The operational answer to the sandwich position is not to argue about formal scope. It is to run the organisation as if the directive applied, because in practical terms it already does. That answer is more concrete than it sounds. Six elements make it work.
Documented risk management
Article 21(2) of NIS2 lists ten categories of technical, operational and organisational measures. Risk analysis and information system security policies. Incident handling. Business continuity. Supply chain security. Security in network and information systems acquisition and development. Policies to assess effectiveness. Cyber hygiene and training. Cryptography. Human resources security, access control and asset management. And, last, multi-factor or continuous authentication together with secured voice, video and text communications where appropriate. None of these are exotic in 2026. All of them require documentation that shows how, when, and by whom they are maintained. The dossier itself is the deliverable.
A tested incident response plan
Early warning within 24 hours and full notification within 72 hours, both counted from the moment you become aware rather than the moment the incident began, with the final report due one month after that 72-hour notification. Article 23 sets the clocks. They only work if the plan exists on paper and has been rehearsed. Tabletop exercises, defined roles, a named incident commander, an escalation tree with the actual phone numbers of the actual people who need to be reached at 2am on a Sunday. Most hospitality groups have some of this. Few have all of it. The gap is where preparedness lives.
A supplier assessment programme
This is where hospitality has to catch up fastest. Hotels typically have twenty to fifty integrations with third parties: PMS, booking channels, loyalty platforms, payment processors, guest messaging, digital keys, POS. Each is a potential CEVA equivalent. Article 21 obliges in-scope organisations to manage the risk in their direct supplier relationships, which is why this pressure reaches hospitality contractually rather than statutorily. NIS2-style supplier assessment means knowing which suppliers hold guest data, what their own security posture looks like, when they last certified, and what the contractual response protocol is when they suffer an incident. Building this programme takes time. Discovering you need it during someone else’s breach costs much more.
Continuous monitoring with defined response
Detection catches attacks that prevention misses. Response contains them before they compound. This is the layer where Managed Detection and Response, whether internal or through a partner, becomes a first-order requirement rather than an optional add-on. For hotel groups without a dedicated security operations centre, this is exactly what a managed service like Secure360 exists to provide. It is worth noting where that partner sits in the directive. Annex I lists ICT service management (business-to-business), naming managed service providers and managed security service providers explicitly. Your hotel group is outside NIS2. The provider running your security is inside it. The controls described in this chapter are the ones that provider is already obliged to run on itself.
Board-level cybersecurity oversight
NIS2 places personal accountability on board members of in-scope organisations. For hospitality boards that are not in scope, the equivalent accountability arrives through corporate customer scrutiny, insurer requirements and public incident coverage. Making cybersecurity a standing board topic, with quarterly reporting, ensures the board is informed before it needs to explain itself.
Audit-ready documentation, always
The difference between an organisation that survives regulatory or contractual scrutiny well and one that does not is rarely the underlying security. It is whether the dossier is current. Policies dated. Reviews recorded. Training logs kept. Incident tickets closed with root cause analysis. Supplier assessments filed. Under NIS2 this is called being audit ready. Outside NIS2 it is called being defendable when a customer, insurer, journalist or regulator asks.
Chapter 05
What “not being in scope” actually costs.
The argument for treating NIS2 scope as decisive is that acting as if the directive applied costs money and effort that a strictly out-of-scope organisation does not have to spend. That argument is technically correct and strategically wrong. What it misses is the asymmetry of the two positions.
If you are right about scope and act as if you were not, you saved effort in the short term. In the medium term you built controls that your insurance underwriter required anyway, that your corporate customers asked for anyway, that your cloud contract quietly obliged you to have anyway, and that would have kept you defendable in the incident you did not have. The upside of being right about scope is invisible and modest.
If you are wrong about scope, or if a large corporate customer runs an audit, or if a supplier is breached and you are named in the coverage, you are personally exposed with a dossier that is not ready and a response plan that is not rehearsed. The downside of being wrong is measured in personal liability for board members, cancelled corporate contracts, insurance premium increases and reputation damage that outlasts the incident cycle. The downside of being wrong is invoiced during a live incident. That is asymmetric.
The notifications Bol and De Bijenkorf sent on 5 August are not a story about retail. They are a preview of how the regulatory and contractual cascade actually behaves. The party that runs the playbook does not have to be the party that was breached. The party held accountable does not have to be the party that failed. In hospitality, where the number of supplier integrations exceeds most other sectors and where the guest data at stake is uniquely sensitive, the sandwich position is not neutral. It is the exposure. Acting as if scope applied is the response.
Being out of scope is a fact about the law. It is not a fact about your exposure.
Sources cited
[1] NOS, Bol en de Bijenkorf waarschuwen klanten voor mogelijk datalek, 5 August 2026. nos.nl
[2] TechCrunch, A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond, 10 August 2026. techcrunch.com
[3] Directive (EU) 2022/2555 (NIS2), Articles 2, 3, 21, 23 and 32, and Annexes I and II. Consolidated European legislation.
[4] Commission Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprises, Annex, Article 2.
[5] Cyberbeveiligingswet, in force 15 August 2026. wetten.overheid.nl