The gist: NIS2 makes executives personally liable for cybersecurity, yet the German Mittelstand currently meets only 56 percent of BSI baseline requirements.
The NIS2 Directive creates new liability responsibility for around 29,500 medium and large companies: chief executive officers and boards of directors can now be held personally liable for cyber breaches. A current risk barometer reveals a critical gap between self-assessment and actual security status.
A study by the SMK Group shows a widespread security deficit in the German Mittelstand: many affected companies rate their cybersecurity significantly better than it actually is. While businesses feel subjectively well protected, according to the German Federal Office for Information Security (BSI), they meet on average only 56 percent of the required baseline measures.
With the implementation of the NIS2 Directive, this situation deteriorates significantly. The Directive obligates around 29,500 companies from sectors such as energy, transportation, water, health and digital infrastructure to comprehensive security standards. New is the personal liability: chief executive officers and boards of directors will henceforth bear personal responsibility for meeting these requirements — delegation is no longer possible.
The combination of existing security gaps and new personal liability forces management to treat cybersecurity as a strategic top-management issue. Previous models in which IT management and security officers alone answer for cyber risks no longer meet the new legal requirements. A risk assessment and a documented implementation plan are among the necessary measures.
Source: www.security-insider.de · Published July 15, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.