Last updated: June 2026
For decades, cybersecurity lived in the basement. It was the IT department’s job — a technical line item, something the board heard about only when something broke. The EU’s NIS2 Directive has dragged it up the stairs and set it down in the boardroom. And it didn’t arrive politely. It arrived with personal accountability for company directors, the kind that doesn’t disappear behind the corporate veil.
If you sit on a board, run a company, or advise the people who do, this is the part of NIS2 you can’t delegate away. Here’s what changed, why it matters, and what leadership teams need to do about it.
The end of “that’s IT’s problem.”
NIS2’s governance provisions do something most cybersecurity regulation never has: they name management as the responsible party. Under the directive, the management bodies of in-scope organisations must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for failures.
Read that again, because the verbs matter. Not “be informed about.” Not “support.” Approve and oversee. The directive deliberately puts cyber risk on the same footing as financial risk or legal risk — a matter the board owns, signs off on, and answers for.
On top of that, NIS2 requires members of management to undergo regular cybersecurity training, so they can actually understand and assess the risks they’re now accountable for. The era of a board nodding along to a slide deck it doesn’t understand is officially over.
What “personally on the hook” actually means
This is where many leaders underestimate the shift. NIS2 sets a framework, and each EU member state writes it into national law — which is where the personal consequences get teeth. Across the EU, national implementations have introduced measures that can reach individuals directly, including:
- Personal fines for managers in cases of serious non-compliance, separate from the penalties levied on the company itself.
- Temporary bans from management roles, where regulators in some countries can suspend individuals from holding leadership or director positions in repeat or severe cases.
- Direct accountability for oversight failures, meaning a director can’t simply point at the IT team and walk away. If the board failed to approve adequate measures or oversee them, that’s the board’s failing.
The exact mechanisms vary by country — penalty levels, whether management bans apply, and how aggressively regulators use these powers all differ between national laws. But the direction is unmistakable: the people at the top now carry personal exposure, not just professional embarrassment.
The company-level stakes are just as serious
Personal liability sits on top of organizational penalties that are already severe. For the most critical “essential” entities, fines can reach €10 million or 2% of total worldwide annual turnover, whichever is higher. For “important” entities, the ceiling is €7 million or 1.4% of turnover.
Now combine the two. A serious failure can mean a multi-million-euro corporate fine and personal exposure for the directors who were supposed to be overseeing the risk and the reputational fallout of a public incident disclosure. For a board, that’s a risk profile that demands attention at the same level as a major financial or legal exposure — because legally, that’s now what it is.
Why this is actually a good thing (yes, really)
It’s easy to read all of this as a threat. It’s more useful to read it as a correction.
For years, security teams struggled to get budget, attention, and authority precisely because cyber risk sat below the board’s eyeline. Breaches kept happening not because the technical fixes were unknown, but because the organization never prioritized them. NIS2’s accountability provisions fix that incentive problem at the root. When directors are personally answerable, cyber risk finally gets discussed, resourced, and owned at the level where those decisions actually get made.
In other words, the law didn’t create a new burden so much as assign an existing one to the people who can do something about it. Boards that embrace that find their security posture improves not because they bought more tools but because they started asking better questions.
What boards and leadership teams should do now
Turning accountability into genuine resilience doesn’t require the board to become technical experts. It requires them to govern cyber risk the way they govern every other material risk. A practical starting point:
- Put cyber risk on the board agenda — permanently. Not as a one-off briefing after an incident, but as a standing item with regular reporting, owned by a named director or committee.
- Get trained properly. The directive expects it, and it’s not optional theatre. Leadership needs enough fluency to ask the right questions and judge the answers.
- Demand evidence, not reassurance. “We’re secure” is not an answer a board should accept. Ask for the risk assessment, the gaps, the remediation plan, and the timeline—and review progress against it.
- Formally approve your risk-management measures. Document that the board reviewed and signed off on the cybersecurity approach. That record is both a legal expectation and your evidence of having met it.
- Know your incident-response and reporting plan before you need it. When an incident hits, the directive’s clock starts fast. The board should understand who decides, who notifies the authorities, and how the organisation will meet its reporting deadlines under pressure.
- Treat it as enterprise risk, not an IT project. Fold cyber into your existing governance, audit, and risk frameworks rather than leaving it stranded as a technical silo.
The bottom line
NIS2 closed the gap between where cyber risk is created and where it’s owned. By making directors personally accountable, it ensured that the people with the authority to prioritize security could no longer look the other way.
For boards that were already engaged, this is validation. For those that weren’t, it’s a wake-up call with consequences attached. Either way, the message is the same: cybersecurity is now a leadership responsibility, defined in law, with your name on it. The smart move isn’t to fear that—it’s to govern it as deliberately as you govern everything else that could put the business, and you, at risk.
This article is general information, not legal advice. NIS2 obligations and the personal-liability provisions that flow from it depend on your sector, size, and the national law of each country you operate in—and those national rules are still evolving. Verify your position against the relevant national authority or a qualified advisor before acting.