The NIS2 Implementation Act came into force in December 2025; since January 6, affected companies have been required to register with the Federal Office for Information Security to report incidents – and for the first time, responsibility for cybersecurity lies with senior management, who are personally liable if risks are not adequately managed, reporting obligations are violated, or governance requirements are disregarded.
The NIS2 Directive stipulates that, in addition to traditional critical infrastructures, medium-sized companies in numerous industries with 50 or more employees or ten million euros in turnover must now also systematically manage their cyber risks. For many medium-sized companies, this represents a cultural and organizational change – from simply identifying cyber risks to actively managing them and implementing verifiable controls.
Approval and monitoring of measures becomes a top priority
What is particularly important in NIS2 is the personal liability of company management for the cybersecurity strategy. Although measures can be delegated at the operational level, ultimate responsibility remains with the management and board of directors. A look at Articles 20 and 21 of the NIS2 Directive shows what management needs to focus on:
It must "approve" cybersecurity risk management measures and "monitor" their implementation. This means that the strategy must be truly understood. Simply signing off on a prepared document is not enough. A risk-based approach is required: risks must be systematically identified, assessed, and addressed with appropriate measures. This includes technical, organizational, and personnel risks as well as the supply and service chain. Only if management can demonstrate that appropriate steps have been taken to establish the required processes are the requirements met.
Documentation as a protective tool
One key aspect is comprehensive documentation. Minutes of board meetings, decisions on security strategies, budget approvals, external expert reviews, and monitoring reports form the basis of defensive governance. In the event of an emergency, they prove that management has fulfilled its obligations. Without verifiable evidence, fines of up to ten million euros or two percent of global annual revenue, depending on the category of company, as well as reputational damage and personal liability risks for senior management, may be incurred.
Boss hits the books with employees
The NIS2 requirements regarding the responsibilities of company management are also a clear call for in-depth cybersecurity training. On the one hand, management itself must regularly participate in training courses and keep up to date with the latest developments in order to understand cyber risks and make informed decisions. On the other hand, it must ensure that awareness of cybersecurity is established in the company's day-to-day business – which in turn requires appropriate training for employees.


