Skip to content
NIS2 & Cbw · · 2 min read

NIS2 and director liability: why this is a boardroom topic

Under NIS2, directors are personally responsible for cybersecurity. What that means concretely and how the board can demonstrably take up its role.

By Limburg Cyber Group

There is one aspect of NIS2 that definitively lifts cybersecurity out of the “IT will sort that” corner: the law places responsibility firmly with the board. Directors must approve the measures, oversee their implementation, and can be held personally liable. That makes it a boardroom topic.

What the law expects of directors

At its core, three things:

  1. Approve. Management must know the risk measures and formally sign off, not delegate and look away.
  2. Oversee. Actively track whether the measures are implemented and working.
  3. Have knowledge. Directors are expected to understand enough of the risks to decide on them; that is why the law also mentions training for the board.

Why “IT handles it” no longer suffices

Under NIS2, cybersecurity is not a technical side issue but a business risk, on a par with financial or legal risks. Just as a director cannot say “I don’t understand the accounts”, they will not be able to hide behind “I don’t understand the technology”. The responsibility is managerial, even if the execution is technical.

How to take up your role demonstrably

Liability is about demonstrability: can you show that you took your role seriously? In practice that means:

  • Put cybersecurity on the agenda periodically in board or management meetings and record decisions.
  • Get informed with understandable reporting, no technical jargon, but risks, status, and choices.
  • Formally approve policy and measures, and document that.
  • Invest in basic knowledge within the board, so you can ask the right questions.

The common thread: documentation

As with the rest of NIS2: what is not recorded will not count. A simple but consistently maintained record of decisions, reports, and measures is your best protection, and at the same time the basis under your IT policy and your incident process.

Help with the translation?

We help boards make cybersecurity understandable and governable: clear reporting, the right decisions, and the documentation that goes with them. See our NIS2 approach or book a conversation.

Read more

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.