Summary
- Researchers analysed annual reports from 67 continuously listed Dutch companies across 2020, 2022 and 2024.
- The sample covered the AEX, AMX and AScX indices and tracked cybersecurity and supply chain risk disclosure.
- The study identifies a change during the NIS2 and DORA period but does not prove regulation alone caused it.
Cybersecurity and supply chain risk have become more prominent in the annual reports of Dutch listed companies, according to research examining how corporate disclosure changed between 2020 and 2024.
The study, published by Internet Policy Review, analysed reports from 67 companies on the AEX, AMX and AScX indices and compared material published in 2020, 2022 and 2024.
The researchers began with 75 companies appearing across the three Euronext Amsterdam indices in March 2024. Eight were excluded because they had not remained continuously listed through all three years examined, leaving 23 AEX companies, 23 AMX companies and 21 AScX companies.
The sample covered manufacturing, food and chemicals, digital infrastructure, financial services, healthcare, energy, logistics and transport. Manufacturing and industry formed the largest group.
Annual reports provide a view of which risks companies consider material enough to communicate to investors and other stakeholders. They do not show directly whether the underlying security controls are effective.
More disclosure does not prove stronger security
A company can describe cybersecurity extensively while still carrying serious weaknesses. Another business may operate effective controls without devoting the same amount of space to the subject in public reporting.
The increase nevertheless provides evidence that cybersecurity is occupying a larger place in formal corporate governance. When cyber incidents, technology dependencies and supplier exposure begin appearing more consistently in annual reports, they have moved beyond a subject handled only by specialist technology teams.
The researchers examined the change during the period in which the EU adopted the NIS2 Directive and the Digital Operational Resilience Act. More than half of the companies in the sample were assessed as falling within the scope of NIS2, while 16% were assessed as being covered by both NIS2 and DORA.
The study does not claim that those regulations alone produced the change. Companies could have adjusted their reporting before legal deadlines as they prepared for new requirements, while cyber incidents, investor scrutiny and wider board attention may also have influenced what they disclosed.
That distinction matters because the research measures reporting behaviour rather than technical performance. It can show that cyber risk is becoming more visible within governance, but it cannot establish that the companies studied are less vulnerable to attack.
Supply chain risk has also become more closely connected with cybersecurity regulation. Businesses increasingly depend on software providers, cloud services, managed technology and specialist suppliers whose failure can interrupt operations even if the organisation’s own systems were not the original point of compromise.
NIS2 and DORA both increase attention on those dependencies, although their scope and legal requirements differ. Corporate reporting can therefore reveal whether organisations are beginning to recognise supplier risk alongside threats to systems they operate directly.
The research also notes that businesses had substantial warning before the new regimes took effect. Changes in annual reports may reflect preparation for incoming regulation as well as the formal obligations themselves.
The study was funded through Erasmus University Rotterdam with external funding from Ahold Delhaize. The author states that there was no contractual relationship with Ahold Delhaize and that the university managed the funding.
The evidence therefore supports a measured conclusion. Dutch listed companies are talking more about cybersecurity and supply chain risk than they did earlier in the decade, while the research does not claim that disclosure alone demonstrates stronger security or that regulation was the only cause.





