Skip to content

NIS2 and Production Facilities: Liability Risks for Mid-Sized Enterprises

Bottom line: Mid-sized manufacturers must comply with NIS2 standards designed for enterprise infrastructure—violations risk substantial fines and personal liability of company management.

Cyberattacks on production environments are increasing and putting mid-sized enterprises in a tension between regulation and technical feasibility. The NIS2 Directive creates new liability risks that threaten to hit smaller and medium-sized businesses in particular.

Digital attacks on production facilities are no longer the exception but part of the threat spectrum for German and European companies. Ransomware campaigns, data theft, and operational disruptions caused by cyberattacks can significantly impair production operations and cause financial damages in the millions.

The NIS2 Directive (Network and Information Security Directive 2) now obliges mid-sized enterprises to adhere to binding cybersecurity standards. Unlike its predecessor NIS1, NIS2 applies to a significantly broader spectrum of businesses—particularly in the energy, transport, water, healthcare, financial, and telecommunications sectors as well as digital service providers. What is routine for corporations with dedicated security teams poses considerable organizational and financial challenges for mid-sized enterprises. CISOs and company managers must be able to demonstrate concrete measures for risk mitigation—from network segmentation to incident response plans to security audits.

The liability trap lies in the fact that NIS2 not only provides for fines of up to six percent of annual turnover but also enables criminal responsibility of company managers, including personal imprisonment. Enterprises must therefore not only implement technical controls but also document them and be able to review them regularly. For mid-sized businesses without specialized security personnel, this creates considerable pressure to engage external support or specialized service providers—or face non-compliance with regulatory requirements.


Source: news.google.com · Published 12 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: