Editorial update August 12, 2026. The legal responsibility of the management body requires careful explanation per organisation and situation. This article provides board-level explanations and no legal judgment on personal liability.

For specific training of directors and supervisors, Kynexis Information Security refers to NIS2BoardroomTraining. Research, implementation and demonstrable assurance remain part of the Kynexis Information Security service.

See the specific NIS2 training for governance and oversight →View NIS2 implementation at Kynexis Information Security →

Cyber threats affect continuity, reputation and financial results. The NIS2 raises the bar by requiring the management of risk management and information security. The thought is simple: Digital security is often a critical business and belongs in the boardroom as well as finance, ESG and occupational safety. For IT board members, this means more backup and clearer rules of play; for directors and supervisory directors, it means an active role, with a view to risk mitigation, measures and accountability.

NIS2 does not call for technological tricks, but for demonstrable control, choices and control. That's exactly what board member liability within NIS2 is about.

What does NIS2 prescribe about board member liability?

NIS2 introduces explicit obligations for the management body. That body (directory/management) shall:

  • define policies for information security and risk management;
  • making sufficient resources, people and priority available;
  • monitor implementation and periodically review;
  • train themselves and management in cyber-risks and their role;
  • demonstrate that the organisation reports and handles incidents in a timely and correct manner.

If this is seriously inadequate, it can lead to measures against the organisation and, in certain cases, to personal consequences. NIS2 board-level liability therefore requires demonstrable governance, not just technical measures.

Is your organisation NIS2?

NIS2 applies to essential and important entities across sectors including energy, transport, digital infrastructure, healthcare, waste, food, manufacturing, postal and courier services, digital services and certain IT service providers. Suppliers may also be affected when they are part of critical supply chains. Board members should determine early whether their organisation falls within the scope of NIS2, whether it is a supplier and which obligations apply.

Board-level issues

  • Scope: Define which entities, brands, establishments and chain partners are in scope.
  • Chain Dependencies: inventory critical suppliers and digital links.
  • Tangible risks: Which processes/data are .kronor jewelry . and what is the impact on failure or data breach?

From IT issue to board-level duty

Previously, the emphasis was on technical measures in the IT line; under NIS2, final responsibility is broader and more explicit. The Board cannot be satisfied with the IT department which regulates the performance of the service. The CoC can expect: are risks appointed, are there targets set, is there a plan, are results measured and adjusted?

From "Finches' to "Finches'

  • No more loose projects, but a system of continuous improvement.
  • From ad hoc measures to policies, frameworks and reporting which have been determined by the board.
  • From the techniques used to the techniques used, to Business risks first: continuity, legislation and regulation, reputation.

Risk mitigation, impact and opportunities for board members

The risks are probably known: production stop, sales loss, claims, fines, reputational damage. What NIS2 adds is board-level transmission: whether the board was in control. This is a risk, but also an opportunity to strengthen governance.

Possible consequences in the event of insufficient steering

  • Enforcement and fines in the event of serious negligence;
  • Binding instructions and enhanced oversight;
  • Contract risk: larger customers require proof NIS2 execution;
  • Reputation risk in the event of incidents without clear direction and communication.

Opportunities for governance and CoC

  • Enhanced continuity: faster recovery, less failure;
  • Lower total costs: extinguishing fewer fires, more predictable investments;
  • Stronger confidence: demonstrable control towards customers, partners and supervisors.

The role of supervisors (CoC/RvT)

oversight means asking the right questions, oversight frameworks and oversight. The CoC does not need to be a technical expert, but it does understand how digital risks affect the strategy and what choices the board makes.

Five questions we advise each Commissioner to ask

  1. What are our most important digital risks and crown jewellery, and how are they protected?
  2. Which KPIs and thresholds are used to determine whether we are in control?
  3. How are you? incident response plan organized and when was the last time we practiced?
  4. Which suppliers are critical and what requirements/agreements have we set out about this?
  5. What steps do we take to: NIS2 implementation And what's the plan?

Governance: structure and responsibilities

Board-level responsibility requires a clear set-up. Without clear roles, it remains with good intentions. A workable governance model can look like this:

Role ResponsibilitiesManagement/DirectoryDefines policies and targets, allocates budget and priority, approves the improvement plan, requires periodic reports.Supervisory BoardKey frameworks, monitors progress, asks for choices and incidents, monitors expertise management.CISO/ISMS ownerDevelops policies/procedures, ensures risk management and audits, reports independently.IT ManagerImplements measures, organises detection and response, provides management information.Process ownersTranslate measures into work processes, approve restart/acceptance upon recovery.

Building blocks of NIS2 version

No list of IT jargon, but clear building blocks that you can see as a board. This is the core of NIS2 implementation and of a digital adult organisation.

1. Risk management and crown jewellery

  • Make a Risk profile with an impact on continuity, finance and reputation.
  • Identify Crown jewels (critical processes, data and systems) and determine their level of protection.
  • Connect measures and KPIs to those crown jewels.

2. ISMS and policy

  • Aim for a Information Security Management System in (e.g. according to ISO 27001).
  • Establish policies, responsibilities and procedures; Keep them up to date.
  • Plan audits and improvement cycles (PDCA) and report to the board.

3. Incident Response and Crisis Organisation

  • Make a incident response plan with roles, decision-making rules and roadmaps.
  • Practice annually (tabletop), including communication and reporting obligations.
  • Borg backups, recovery targets and decision criteria for restart.

4. Suppliers and digital links

  • Lay security requirements, reporting periods, audit rights and exit agreements fixed in contracts/SLA debt instruments.
  • Limit access and rights; Perform periodic reviews.
  • Test critical scenario performance indicators together with suppliers.

5. Human and culture

  • Follow the NIS2 board member training in their role; include . . security by design . .
  • Increase awareness among employees; make reporting at low threshold via a central hotline.
  • Measure participation and effect (phishing simulations, reporting behaviour, lessons learned).

6. Reporting and KPIs

  • Define a short set of KPIs (e.g. time to detection and recovery, patch time, back-up recovery tests, number of critical suppliers with current keys).
  • Report periodically on the board and discuss deviations and decisions.

Examples of the taking of directors' responsibility

Case 1 . . Payment fraud by email

A finance employee transfers a payment based on an e-mail from the CEO. The organisation had no four-way principle and no clear notification procedure. After the incident, the Board established frameworks: verification outside email, limits and a clear hotline. Consequences: reduced risk and faster response in new attempts.

Case 2 – Ransomware and Recovery

Backups were unusable because they were on the same network. After the incident, recovery capacity was established by board-level means: separate, immutable backups and periodic recovery tests reported to the CoC. This is classic NIS2 implementation in practice: policy, resources, demonstration and continuous improvement.

Case 3 – Supplier coupling

An external supplier had broader rights than necessary. By imposing contractual requirements, limiting access and checking logs, vulnerability became significantly reduced. The CoC got a look at the top-10 critical suppliers and the state of play.

Board members' liability and insurance

A board member's liability insurance can help, but is no excuse to do nothing. Under the NIS2, supervisors have far-reaching possibilities to hold directors personally liable. Insurance companies are increasingly looking at governance, risk management and incident response. Without demonstrable control, premiums can rise or claims can be rejected. 

Board members' roadmap: in 90 days to grip

  1. Weeks 1–2: determine applicability NIS2 and appoint an board-level owner; Set targets and scope.
  2. Weeks 3–6: carry out a baseline assessment of risks, policies, incident response and suppliers; identify top risks and quick wins.
  3. Weeks 7–10: formalise governance (roles, reports), prepare an ISMS and improve plan; Start awareness program.
  4. Weeks 11–12: practice a scenario (tabletop), evaluate and record decisions and investments. Schedule quarterly reports and audits.

Make demonstrable, documented steps. Board members' liability is about choices, priority and evidence that you are in control.

Frequently asked questions about NIS2 board member liability

Does every board member have to be cyberexpert?

No. The board does not need to master technical details, but must steer on policy, priority, KPIs and reports. If desired, you will complete your knowledge with external experts and training.

When will it be enough?

That depends on your risk profile and your sector. Work with thresholds (KPIs) set and assessed by the Executive Board. Document choices and deviations.

What if a supplier is responsible for an incident?

Then it still counts if you were in control: were requirements laid down, access restricted, reporting obligations regulated and is there oversight? NIS2 looks at the chain, but also at your governance.

Is NIS2 only for large companies?

No. The scope is wider than before and also affects medium-sized organisations and suppliers. Finding out if you're falling into scope is step one.

Checklist for directors and supervisors

  • Applicability NIS2, scope and crown jewels appointed.
  • Policy established and resource/budget allocated.
  • ISMS is designed or built up; roles and responsibilities clear.
  • Incident response plan present, recently practiced and evaluated.
  • Supplier policy and contracts with security and reporting arrangements in order.
  • Quarterly reports with KPIs to board and supervisory authority; decisions and derogations laid down.
  • Training board/management and awareness program employees active.
  • Continuous improvement: audit planning, improvement list and priorities known.

Responsibility as a guarantee of continuity

NIS2 board member liability is not a threat of "again a new law" but an invitation to mature digital security. Through clear governance, risk management, a trained incident response plan and tight reporting, you will take steps towards NIS2 implementation and build sustainable continuity. This is where directors, IT board members and supervisors find each other: less surprises, more predictability and more trust in customers, partners and society.

Spill on your NIS2 approach?

Plan a NIS2 Boardroom Training or a baseline assessment.