The all-hazards risk assessment — the first obligation every critical entity faces
The all-hazards risk assessment is the foundation the Wwke builds on — physical threats, natural hazards, hybrid campaigns and insider risk in one structured assessment.
An all-hazards risk assessment is a structured assessment of every threat category that could disrupt an organisation's essential services — physical attack, sabotage, insider action, natural hazards, supply-chain failure and hybrid campaigns — in one integrated analysis. Under the EU CER framework and the Dutch Wwke, a designated critical entity must complete this assessment within nine months of being notified of its designation, and every subsequent resilience measure is calibrated against it.
Why the risk assessment comes first
The Wwke regime is deliberately sequenced: assessment before measures. The law does not prescribe a fixed set of controls — it requires measures proportionate to the assessed risk. That makes the risk assessment the document that determines everything downstream: which sites need hardening, which processes need redundancy, what the incident thresholds are, and where the budget goes. An assessment built to a weak standard produces either over-spend on the wrong controls or an exposed essential service with a paper shield.
What "all-hazards" actually has to cover
- Deliberate physical threats — attack, sabotage, unauthorised access, theft of critical assets, and the drone observations over Dutch and Belgian infrastructure through the past winter
- Espionage and information loss — technical surveillance of decision-making spaces, exploitation of installed devices such as internet-connected cameras (the subject of a July 2026 AIVD warning), and insider access
- Personnel risk — reliability, screening posture, and the human route into every technical control
- Natural and accidental hazards — flood, fire, extreme weather, utility failure
- Dependency risk — suppliers, single points of failure, and cross-sector dependencies through which someone else's incident becomes yours
The shape of a defensible assessment
A defensible all-hazards assessment is threat-led, not checklist-led. It starts from who could target the entity and with what capability, maps essential services to the assets and people they depend on, scores scenarios for likelihood and impact, and closes with a prioritised measure set the board can fund. It is also a living document: the CER framework expects it to be maintained, and the Dutch threat picture — national threat level 4 of 5, active espionage reporting, contested airspace over infrastructure — is not static.
Mission Support builds all-hazards assessments for critical entities with operators drawn from governmental and defence backgrounds — covering physical security, technical surveillance counter-measures, counter-drone exposure and validation through scenario-based exercises where the entity's risk profile warrants them.
Last reviewed: 11 August 2026. Orientation summary, not legal advice.
Frequently Asked
Request a Resilience Consultation
Operational engagements start with a vetted conversation. Mission Support responds inside one working day for governmental and Tier-1 enquiries.
Continue to service briefDe all-hazards risicobeoordeling — de eerste verplichting voor elke kritieke entiteit
De all-hazards risicobeoordeling is het fundament waarop de Wwke bouwt — fysieke dreigingen, natuurlijke risico's, hybride campagnes en insider-risico in één gestructureerde beoordeling.
Read next