What is Seveso and cybersecurity?

Seveso and cybersecurity refers to applying OT security at establishments covered by the EU Seveso III Directive 2012/18/EU, which must protect their process control and safety systems against digital attacks that could cause a major accident. The directive itself is technology-neutral and never mentions cybersecurity. Yet a compromised safety instrumented system is just as dangerous as a valve that fails to close, so regulators and operators increasingly treat cyber threats as one more cause of major accidents. In the Netherlands the directive was implemented by the Brzo 2015 decree until the end of 2023 and now sits within the Environment and Planning Act.


🗓️ How has Seveso legislation developed?

The Seveso Directive is named after the disaster in Seveso, Italy, on 10 July 1976, when a cloud containing dioxin escaped from a chemical plant. Since then the EU has adopted three successive directives, each broader and stricter than the last.

Year Milestone
1982 Seveso I (82/501/EEC)
1996 Seveso II (96/82/EC)
4 July 2012 Seveso III (2012/18/EU) adopted; applies from 1 June 2015
8 July 2015 Dutch Brzo 2015 enters into force, replacing Brzo 1999
1 January 2024 Brzo 2015 repealed; rules moved into the Dutch Environment and Planning Act (Omgevingswet) and its decrees, including the Bal and Bkl
15 August 2026 The Dutch Cybersecurity Act implementing NIS2 enters into force, covering many Seveso operators

More than 12,000 establishments across the EU fall under Seveso III. The Netherlands has just over 400; in 2020 there were 407, of which 265 were upper-tier and 142 lower-tier.


🧱 What obligations apply to lower-tier and upper-tier establishments?

Whether a site falls under Seveso depends on the quantity of dangerous substances present relative to the thresholds in Annex I of the directive. Above those thresholds a two-tier regime applies.

Obligation Lower tier Upper tier
Notification to the competent authority Yes Yes
Major accident prevention policy (MAPP), reviewed at least every 5 years Yes Yes
Safety management system (SMS) Yes (explicitly required in the Netherlands) Yes
Safety report, reviewed at least every 5 years No Yes
Internal emergency plan, tested at least every 3 years No Yes
Information to the public Basic Extended, actively provided
Routine inspection At least every 3 years Every year

Annex III of the directive defines seven SMS elements: organisation and personnel, identification and evaluation of major hazards, operational control, management of change, planning for emergencies, monitoring performance, and audit and review. These elements are exactly where cybersecurity can be anchored.


🔐 Why does cybersecurity matter at a Seveso site?

Major accidents are prevented by layers of protection: basic process control in a DCS, alarms and operator response, and finally the SIS with its safety PLCs. Today all of these layers are networked computer systems. An attacker who manipulates the DCS can drive a process outside its safe operating envelope; one who also disables the SIS removes the last instrumented safeguard.

This is not theoretical. In 2017 TRITON malware attempted to reprogram the Triconex safety controllers of a petrochemical plant in Saudi Arabia. A HAZOP or LOPA that assumes the SIS is independent and reliable no longer holds if that SIS can be reached from the office network.

Dutch evidence points the same way. In October 2020 the DCMR environmental agency commissioned Fox-IT to assess the cyber maturity of major-hazard companies in South Holland and Zeeland. Of 70 companies invited, 39 took part. The results, published in September 2021, showed that a sizeable share needed to strengthen their attention to cybersecurity, although no acute major-accident danger was found. A later University of Twente study for Safety Delta Nederland concluded that the chemical industry is insufficiently prepared for cyber incidents affecting process safety. Cyber maturity varied widely, from barely existent to well prepared, and the researchers recommended managing safety and security risks in an integrated way, with particular attention to the link between IT and OT.


🧠 How do Seveso inspectors look at cybersecurity?

In the Netherlands, Seveso sites are inspected jointly under the Seveso+ cooperation programme (formerly BRZO+). Its partners are the Netherlands Labour Authority, the safety regions, six specialised environmental services, the Human Environment and Transport Inspectorate (ILT), Rijkswaterstaat, the water boards, the Public Prosecution Service and State Supervision of Mines. Since 1 January 2022 they have used a national inspection method, the Landelijke Benadering Risicobedrijven (LBR), which assesses each activity, process or installation on three pillars: system (MAPP and SMS), technology (state of the art and condition) and safety culture.

Because the rules are technology-neutral, there is no dedicated cyber clause; in 2021 the Dutch government stressed that operators remain primarily responsible for safe operation. In practice, however, inspectors treat IEC 61511 as the state of the art for instrumented safeguards. Since its 2016 edition, clause 8.2.4 of that standard requires a security risk assessment of the SIS. An operator without one therefore falls short of the very standard used as the inspection benchmark.


🔄 How does Seveso compare with the Dutch Cybersecurity Act?

Many Seveso operators also fall under the Dutch Cybersecurity Act (Cbw), which implements NIS2. The manufacture and distribution of chemicals appears in Annex II of NIS2, while refineries and energy companies fall under the energy sector in Annex I, with its stricter regime. The two regimes complement each other but serve different purposes.

Aspect Seveso III / Environment and Planning Act Cybersecurity Act (Cbw)
Purpose Prevent major accidents and limit their consequences Protect service continuity against cyber incidents
Scope Quantity of dangerous substances above thresholds Sector plus size, see scope
Explicit cyber requirement? No, via SMS and state of the art Yes, duty of care for network and information systems
Key deliverables MAPP, SMS, safety report, emergency plan Risk analysis, measures, registration
Reporting Major accidents Significant incidents within 24 hours, see incident reporting
Supervision Seveso+ (Labour Authority, environmental services, safety regions) ILT for chemicals, RDI for energy
Inspection Upper tier yearly Essential entities proactively, important entities reactively

The sensible route is one integrated approach: a single cybersecurity risk assessment that underpins both the SMS and the duty of care.


🛠️ How do you tackle cybersecurity at a Seveso establishment?

  1. Inventory the safety-critical systems — build an asset inventory of SIS, DCS, engineering workstations, historians and remote access paths, linked to the safety instrumented functions on your P&IDs
  2. Perform the security risk assessment — following IEC 61511 clause 8.2.4, using the zones-and-conduits method of IEC 62443-3-2; for each scenario, check whether an attack could trigger a HAZOP deviation or disable a protection layer
  3. Separate the SIS — segment the SIS from the DCS and the office network, restrict write access and use physical key switches for program mode
  4. Integrate into the SMS — add cybersecurity to hazard identification, operational control and audit, and appoint an owner who understands both process safety and OT
  5. Tie it to management of change — route every software, firmware or network change to safety systems through management of change, just like a physical modification
  6. Engineer for consequences — Cyber-Informed Engineering looks for mechanical or physical safeguards, such as a spring-loaded relief valve, that still work when a control system is compromised
  7. Exercise the emergency plan with a cyber scenario — upper-tier sites should include a loss of control and SIS in the three-yearly emergency plan test, and align it with your incident response plan

❓ Frequently asked questions

Does the Seveso III Directive require cybersecurity?

The Seveso III Directive does not mention cybersecurity explicitly. It does require operators to identify and control all major-accident hazards through the safety management system, and a cyberattack on process control or the SIS is such a hazard. Because inspectors use IEC 61511 as the state of the art, a security risk assessment of the SIS is expected in practice at Seveso establishments.

What is the difference between a lower-tier and an upper-tier Seveso establishment?

A Seveso establishment is lower-tier or upper-tier depending on the quantity of dangerous substances relative to the thresholds in Annex I of Seveso III. A lower-tier establishment needs a major accident prevention policy and, in the Netherlands, a safety management system. An upper-tier establishment additionally needs a safety report and an internal emergency plan and is inspected every year.

Is the Dutch Brzo 2015 still in force?

No, the Dutch Brzo 2015 was repealed on 1 January 2024. The Seveso III requirements now sit in the Environment and Planning Act and its decrees, including the Bal and Bkl. Former Brzo companies are now officially called Seveso establishments, while their substantive obligations remain largely unchanged.

Who supervises Seveso establishments in the Netherlands?

Seveso establishments in the Netherlands are supervised jointly through the Seveso+ programme, formerly BRZO+. The Netherlands Labour Authority, the specialised environmental services and the safety regions usually inspect as a team, supported by bodies such as the ILT, the water boards and State Supervision of Mines. Under the Dutch Cybersecurity Act the ILT supervises the chemicals sector.

Do Seveso operators also fall under NIS2?

Many Seveso operators also fall under NIS2 and its Dutch implementation, the Cybersecurity Act, because chemicals, energy and waste management are NIS2 sectors. Whether a Seveso operator is covered by NIS2 depends on its sector and size, not on its inventory of dangerous substances. A small Seveso establishment may therefore fall outside NIS2 and keep only its Seveso obligations.

What does IEC 61511 clause 8.2.4 require?

IEC 61511 clause 8.2.4 has required a security risk assessment of the safety instrumented system since the 2016 edition. That assessment describes the threats, vulnerabilities, potential consequences and countermeasures for the SIS and its connected systems. For Seveso establishments, clause 8.2.4 is the concrete bridge between process safety and OT security.


📌 In summary

Seveso and cybersecurity belong together: a Seveso operator must control every cause of a major accident, and an attack on the DCS or SIS is one of them. Although Seveso III never mentions cyber, the safety management system, IEC 61511 clause 8.2.4 and NIS2 together make OT security an integral part of process safety.