Resources

NIS2, AI governance and digital resilience: the role of Finance

Written by Gustaf Tanate | Oct 7, 2026, 10:59:19 AM
In brief

New European legislation such as NIS2 and the AI Act is putting digital resilience high on the boardroom agenda. The discussion is shifting away from technology towards a more fundamental question: how much control do organisations want to retain over their own digital future?

What is changing?

Organisations are taking a more critical look at their digital foundations: cybersecurity, data use, transparency and supplier dependency.

Why Finance?

CFOs look beyond the financial business case and also assess the risk, continuity and long-term value of digital investments.

The key takeaway

Make digital resilience, compliance and risk management important criteria in future investment decisions.

As digital resilience moves higher up the boardroom agenda, the requirements organisations place on their digital foundations are changing too. What stands out is that the discussion is shifting away from technology towards a more fundamental question: how much control do organisations actually want to retain over their own digital future?

For years, digitalisation was primarily about improving processes. Organisations looked for ways to work faster, reduce errors and gain greater insight into their data. Technology was assessed on functionality, ease of use and return on investment.

Those factors are still important, but they do not tell the whole story.

New European legislation, such as the Cybersecurity Act (NIS2) and the AI Act, highlights a broader development in which organisations are taking a more critical look at their digital foundations. Questions around cybersecurity, data use, transparency and supplier dependency are increasingly being raised. Rightly so, as more and more business processes depend on technology that is developed, delivered and managed outside the organisation.

Autonomy

Greater focus on digital autonomy

At the same time, European organisations are increasingly considering digital autonomy. The question is no longer simply whether a solution meets functional requirements, but also whether and how it complies with European laws and regulations, governance principles and expectations around the responsible use of AI. This makes the origin, transparency and governability of technology more important than ever.

What I notice in conversations with executives and Finance professionals is that digital dependency is still often viewed as a technical and functional issue. Yet its impact extends much further. A disruption at a supplier, uncertainty about data access or changing legislation can all have direct consequences for risk management and business continuity.

The CFO's role

The CFO looks beyond Finance

This is where I see an interesting shift taking place. CFOs no longer look solely at the financial business case for an investment. Increasingly, they are also asking questions about digital resilience, governance and compliance in order to minimise strategic risks.

That is a healthy development. The conversation is no longer only about what technology can do, but also about questions such as: what dependencies are we creating? Which risks are we willing to accept? And how do we retain control over our processes, data and decision-making?

As organisations continue to digitalise, maintaining this control becomes a core activity. Not only for IT, but for the organisation as a whole.

From a Finance perspective, this creates a valuable new viewpoint. CFOs need to look beyond the initial investment. They assess risk, continuity and long-term value. This requires them to play an active role in decision-making around digital resilience.

Investment

Digital resilience as an investment criterion

My advice to controllers is therefore simple: when making future investment decisions, make digital resilience, compliance and risk management important criteria for success. Price, functionality and expected returns are basic requirements, but digital governance is an insurance policy for the future.

Ask yourself these questions:

✓

Where is the data located?

✓

How transparent is the supplier?

✓

Which compliance obligations apply?

✓

What dependencies are being created in the long term?

Digitalisation is no longer merely an operational issue. It is also a determining factor in the continuity and digital resilience of every organisation. Not because regulation prescribes it, but because maintaining control in these areas represents increasing strategic value.

This article was originally published in Dutch on CMweb.

About the author

Gustaf Tanate

Gustaf Tanate is CEO of ISPnext. Drawing on his experience in technology, cloud solutions and digital transformation, he follows developments at the intersection of Finance, governance and innovation. In his columns, he shares practical insights into the role of technology in strategic decision-making.

Next step

Staying in control of compliance and digital resilience?

Read our whitepaper to learn how financial organisations can achieve compliance with DORA, the EU regulation on digital operational resilience, in four steps.