NIS2 for the Boardroom: Why Directors Are Now Personally on the Hook

Last updated: June 2026

For decades, cybersecurity lived in the basement. It was the IT department’s job — a technical line item, something the board heard about only when something broke. The EU’s NIS2 Directive has dragged it up the stairs and set it down in the boardroom. And it didn’t arrive politely. It arrived with personal accountability for company directors, the kind that doesn’t disappear behind the corporate veil.

If you sit on a board, run a company, or advise the people who do, this is the part of NIS2 you can’t delegate away. Here’s what changed, why it matters, and what leadership teams need to do about it.

The end of “that’s IT’s problem.”

NIS2’s governance provisions do something most cybersecurity regulation never has: they name management as the responsible party. Under the directive, the management bodies of in-scope organisations must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for failures.

Read that again, because the verbs matter. Not “be informed about.” Not “support.” Approve and oversee. The directive deliberately puts cyber risk on the same footing as financial risk or legal risk — a matter the board owns, signs off on, and answers for.

On top of that, NIS2 requires members of management to undergo regular cybersecurity training, so they can actually understand and assess the risks they’re now accountable for. The era of a board nodding along to a slide deck it doesn’t understand is officially over.

What “personally on the hook” actually means

This is where many leaders underestimate the shift. NIS2 sets a framework, and each EU member state writes it into national law — which is where the personal consequences get teeth. Across the EU, national implementations have introduced measures that can reach individuals directly, including:

  • Personal fines for managers in cases of serious non-compliance, separate from the penalties levied on the company itself.
  • Temporary bans from management roles, where regulators in some countries can suspend individuals from holding leadership or director positions in repeat or severe cases.
  • Direct accountability for oversight failures, meaning a director can’t simply point at the IT team and walk away. If the board failed to approve adequate measures or oversee them, that’s the board’s failing.

The exact mechanisms vary by country — penalty levels, whether management bans apply, and how aggressively regulators use these powers all differ between national laws. But the direction is unmistakable: the people at the top now carry personal exposure, not just professional embarrassment.

The company-level stakes are just as serious

Personal liability sits on top of organizational penalties that are already severe. For the most critical “essential” entities, fines can reach €10 million or 2% of total worldwide annual turnover, whichever is higher. For “important” entities, the ceiling is €7 million or 1.4% of turnover.

Now combine the two. A serious failure can mean a multi-million-euro corporate fine and personal exposure for the directors who were supposed to be overseeing the risk and the reputational fallout of a public incident disclosure. For a board, that’s a risk profile that demands attention at the same level as a major financial or legal exposure—because legally, that’s now what it is.

Why this is actually a good thing (yes, really)

{%} of your text is likely AI-generated

New version 1:
It’s easy to interpret all of this as a threat, but it’s actually more beneficial to see it as a correction.

For years, security teams have faced challenges in securing budget, attention, and authority, largely because cyber risk was often overlooked by the board. Breaches continued to occur not due to a lack of technical solutions but because organizations simply didn’t prioritize them. The accountability measures in NIS2 tackle this issue right at its core. When directors are held personally accountable, cyber risk finally gets the attention, resources, and ownership it deserves at the decision-making level.

In simpler terms, the law didn’t impose a new burden; it merely shifted an existing one to those who have the power to make a difference. Boards that embrace this shift often see their security posture improve—not because they’ve invested in more tools, but because they’ve started to ask the right questions.

What boards and leadership teams should do now

Turning accountability into genuine resilience doesn’t require the board to become technical experts. It requires them to govern cyber risk the way they govern every other material risk. A practical starting point:

  1. Put cyber risk on the board agenda — permanently. Not as a one-off briefing after an incident, but as a standing item with regular reporting, owned by a named director or committee.
  2. Get trained properly. The directive expects it, and it’s not optional theatre. Leadership needs enough fluency to ask the right questions and judge the answers.
  3. Demand evidence, not reassurance. “We’re secure” is not an answer a board should accept. Ask for the risk assessment, the gaps, the remediation plan, and the timeline—and review progress against it.
  4. Formally approve your risk-management measures. Document that the board reviewed and signed off on the cybersecurity approach. That record is both a legal expectation and your evidence of having met it.
  5. Know your incident-response and reporting plan before you need it. When an incident hits, the directive’s clock starts fast. The board should understand who decides, who notifies the authorities, and how the organisation will meet its reporting deadlines under pressure.
  6. Treat it as enterprise risk, not an IT project. Fold cyber into your existing governance, audit, and risk frameworks rather than leaving it stranded as a technical silo.

The bottom line

NIS2 closed the gap between where cyber risk is created and where it’s owned. By making directors personally accountable, it ensured that the people with the authority to prioritize security could no longer look the other way.

For boards that were already engaged, this is validation. For those that weren’t, it’s a wake-up call with consequences attached. Either way, the message is the same: cybersecurity is now a leadership responsibility, defined in law, with your name on it. The smart move isn’t to fear that—it’s to govern it as deliberately as you govern everything else that could put the business, and you, at risk.


This article is general information, not legal advice. NIS2 obligations and the personal-liability provisions that flow from it depend on your sector, size, and the national law of each country you operate in—and those national rules are still evolving. Verify your position against the relevant national authority or a qualified advisor before acting.

Scroll to Top