Summary
The core message of the session was that the International Digital Reporting Standard (IDRS) is intended to give boards, supervisory boards, regulators, and other stakeholders a standardized way to report on IT governance and cyber resilience, including in the context of DORA, NIS2, and the Dutch Cyberbeveiligingswet. Marc Welters introduced IDRS as a voluntary annual reporting standard for organizations that want to report about IT in a structured way. He explained that NOREA drafted the standard and handed it over to the Dutch Ministry of Economic Affairs on May 25 of the previous year, after which a maintenance organization involving fourteen organizations was established. Those organizations include universities, ministries, CIO Platform, the CSIR community, and others, supporting the claim that the standard has broad acceptance.
Key Topics
5 key topics from Marc Welters, Sandeep Gangaram Panday and Jacco Jacobs at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Assign explicit board-level ownership for IT governance responsibilities.
- Use IDRS to standardize quarterly IT reporting and annual disclosure.
- Document who accepts residual cybersecurity risks and for how long.
- Map DORA and NIS2 obligations into existing IT reporting structures.
- Define report scope clearly, especially when excluding OT or other domains.
“cybersecurity is never finished, so there will always be some residual risk left over.”
Up Next


Next in agenda
VShell: Tracking a State-Actor C2 Framework in the Wild

Also on nis2
Aligning NIS2 in Practice Across the EU
Dániel Váczi
Also on cybersecurity
Power, Trust, Responsibility in Fragmented Digital World
Miguel De Bruycker