NIS2 and director liability: why this is a boardroom topic
Under NIS2, directors are personally responsible for cybersecurity. What that means concretely and how the board can demonstrably take up its role.
By Limburg Cyber Group
There is one aspect of NIS2 that definitively lifts cybersecurity out of the “IT will sort that” corner: the law places responsibility firmly with the board. Directors must approve the measures, oversee their implementation, and can be held personally liable. That makes it a boardroom topic.
What the law expects of directors
At its core, three things:
- Approve. Management must know the risk measures and formally sign off, not delegate and look away.
- Oversee. Actively track whether the measures are implemented and working.
- Have knowledge. Directors are expected to understand enough of the risks to decide on them; that is why the law also mentions training for the board.
Why “IT handles it” no longer suffices
Under NIS2, cybersecurity is not a technical side issue but a business risk, on a par with financial or legal risks. Just as a director cannot say “I don’t understand the accounts”, they will not be able to hide behind “I don’t understand the technology”. The responsibility is managerial, even if the execution is technical.
How to take up your role demonstrably
Liability is about demonstrability: can you show that you took your role seriously? In practice that means:
- Put cybersecurity on the agenda periodically in board or management meetings and record decisions.
- Get informed with understandable reporting, no technical jargon, but risks, status, and choices.
- Formally approve policy and measures, and document that.
- Invest in basic knowledge within the board, so you can ask the right questions.
The common thread: documentation
As with the rest of NIS2: what is not recorded will not count. A simple but consistently maintained record of decisions, reports, and measures is your best protection, and at the same time the basis under your IT policy and your incident process.
Help with the translation?
We help boards make cybersecurity understandable and governable: clear reporting, the right decisions, and the documentation that goes with them. See our NIS2 approach or book a conversation.
Read more
GDPR and NIS2: where they overlap and where they differ
GDPR and NIS2 look alike, but protect different things. Here is how to understand the overlap, the differences, and why you may face both at once.
ISO 27001 vs NIS2: what is the difference and do you need both?
ISO 27001 and NIS2 are often mentioned in one breath, but they are not the same. The difference explained clearly, and how they actually reinforce each other.
The NIS2 reporting duty explained: what, when, and to whom you report
NIS2 requires organisations to report serious incidents quickly. How that reporting duty works, which deadlines apply, and how to prepare for it.