NIS2: Personal Liability for Executives

The consequences of ignoring the EU requirements may be greater than many executives realise.

NIS2 introduces a new level of accountability for executives and board members. This is no longer a technical rulebook. It is a governance requirement with direct, personal consequences.

Management can be held liable for inadequate security governance, missing risk assessments and failure to follow up on security measures.

This means that failures no longer hit only the organisation. They hit you: your title, your responsibilities, your reputation and, in the worst case, your finances.

1. Personal liability

“I didn’t know” is no longer a viable strategy.

NIS2 places explicit responsibility on the board and top management to:

  • ensure that appropriate security is in place
  • approve and oversee risk management, security measures and preparedness
  • complete training and maintain the necessary competence
  • be able to document decisions and priorities
  • handle incidents within regulatory deadlines

In the event of non-compliance, management can be held personally liable for:

  • serious breaches of the duty of governance
  • lack of control and oversight
  • misplaced priorities that lead to incidents
  • omissions that increase risk

The consequences quickly add up:

  • Personal liability: Management is held personally accountable for poor prioritisation
  • Career consequences: NIS2 breaches can lead to disqualification from management roles in the EU/EEA
  • Damages claims for negligence: “I didn’t know” is a risk factor in itself
  • Loss of trust and position: Lack of control over security means loss of trust
  • Suspension of services: A NIS2 breach can trigger an immediate order to suspend services

The EU makes it crystal clear: top executives must not be able to push responsibility down the line.

2. Consequences for the business

NIS2 does not limit the consequences to fines. The directive is designed to safeguard national stability and European digital resilience. The sanction regime is considerably tougher than many are prepared for.

A. Severe financial sanctions

The requirements allow member states to impose substantial fines for non-compliance, on a par with the GDPR regime:

  • Up to EUR 10 million, or
  • 2% of global annual turnover, whichever is higher.

This directly affects the company’s capital, investment capacity and financial position.

B. Supervision, audits and enforcement orders

In the event of incidents or suspected security failings, the supervisory authority can:

  • carry out on-site inspections
  • demand immediate documentation
  • order corrective measures
  • impose operational restrictions
  • order a temporary suspension of services

It is not up to the business to find a solution later. The deadlines are short, and the documentation must already be in place.

C. Impact on supply chains and contracts

NIS2 makes the business responsible for its own supply chain. If you cannot document security, you:

  • lose tenders
  • are rejected in contract negotiations
  • risk being excluded by critical customers
  • may be classified as high risk and lose market position

In several industries, compliance is becoming a de facto competitive requirement.

D. Reputational damage and eroded trust

For the board and the executive team, the reputational damage following a NIS2-relevant incident can be more harmful than the financial consequences. Trust is capital.

When it fails, it affects:

  • customer relationships
  • investor assessments
  • perceived maturity in the market
  • your governance standing
  • recruitment
  • employee relations

Trust, once lost, rarely returns in the same form.

E. Operations, technology and operational stability

NIS2 requires:

  • continuous risk assessment
  • incident handling within tight deadlines
  • documented preparedness
  • technical and organisational controls
  • reporting of significant incidents
  • robust supplier management
  • security governance integrated into the company’s strategy

When this is not in place, the consequences can include:

  • system downtime
  • loss of data
  • loss of services
  • major recovery costs
  • breaches of customer requirements
  • operational disruption

Many businesses only discover the risk once it has already materialised. By then it is too late.

3. What the EU expects you to have in place, as an executive and a board

NIS2 requires management to:

  • establish governance for information security
  • approve the company’s risk management framework
  • ensure that the necessary resources are allocated
  • follow up on implementation
  • document priorities and decisions
  • be able to prove that training is carried out
  • take responsibility for incidents and reporting

All of this must be documented, auditable and available for supervisory review.

4. What NIS2 really means for you as an executive

  • You cannot delegate the responsibility away
  • You are the one who must set the requirements, not wait for IT to do it
  • You must be able to document your decisions
  • You must understand risk, not just have risk “presented” to you
  • And you must be able to prove that the business is in control

5. When uncertainty costs more than security

Waiting increases the risk. Ignoring it increases your liability exposure. Assuming that “we have enough control” is no longer good enough.

NIS2 is about governance. Governance is about leadership. And leadership means accountability.

Berigo helps boards and executives take control before the crisis hits

We assist with:

  • NIS2 gap analysis and impact assessment
  • risk management models that satisfy the directive
  • management structures and governance
  • reporting and documentation
  • implementation of the necessary controls
  • executive and board briefings
  • preparedness and incident response
  • training for top management and the board (mandatory under NIS2)
  • supplier management and contractual requirements
  • ongoing follow-up

Our job is to make sure that you:

  • avoid personal consequences
  • stand firm in an audit
  • meet the requirements of the EU, customers and the market
  • have a management system that works in practice
  • reduce risk before it becomes critical

Read how you can master NIS2

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch