NIS2: What management needs to know personally
NIS2 makes cyber security a board matter, quite literally. What management must approve, oversee and learn, and why delegating alone is not enough.
With the German NIS2 implementation act, one thing has shifted fundamentally: information security is no longer just a job for IT. The law names management explicitly, with duties of its own. The Danish NIS 2 Act follows the same directive and the same logic.
Approve and oversee
Under § 38 of the German BSIG, management of essential and important entities must implement the risk management measures under § 30 BSIG and oversee their implementation. Business continuity is explicitly part of this: backup management, disaster recovery and crisis management.
In practice this means management must know the measures it approves. A signature under a document nobody has read does not meet this duty.
Liability
Anyone who breaches these duties is liable to the entity for the resulting damage under company law. This is the part that is getting attention in many boards right now, and rightly so.
Training duty
Management must take part in training regularly in order to recognise risks and assess risk management practices. A one-off presentation does not cover that.
Why delegating alone is not enough
Of course management does not implement the measures itself. But it has to be able to judge whether what it is shown will hold in a real incident. This is where an exercise helps more than any document: once management has sat in the crisis team itself, it knows which questions to ask.
Three questions for your next board meeting
- Which of our processes must come back first after an outage, and how long can they be missing?
- When was our recovery last actually tested, not just on paper?
- Who decides in the first hour, and how do we reach that person if email and the phone system are down?
If one of these questions has no clear answer, that is not a reproach. It is the starting point.
This article is a practical overview, not legal advice.