Bottom line: NIS2 creates personal liability for approximately 29,500 German CEOs for IT security and compliance within their organizations.
The NIS2 Directive creates new personal liability risks for executives in the area of IT security. Approximately 29,500 CEOs in Germany are directly affected and must meet compliance requirements or face personal consequences.
The NIS2 Directive (Network and Information Security Directive 2) of the EU mandates binding IT security standards for critical infrastructures and corporate organizations. For Germany, this means that CEOs as responsible parties can be held personally accountable if organizations fail to meet these requirements or if security breaches occur.
The figure of 29,500 affected CEOs refers to companies that fall under the expanded scope of NIS2 – including critical infrastructures such as energy, water, transport and health sectors, as well as digital service providers and companies above certain size thresholds. Personal liability extends beyond traditional compliance requirements: CEOs can be held civilly, criminally and administratively accountable.
For CEOs, this represents a core responsibility: the implementation of effective IT security measures, regular risk analyses, incident response plans and employee training are no longer optional. Organizations must report security incidents to the competent authorities in a timely manner – delays or lack of transparency can result in fines and personal consequences. For CEOs, it is essential to actively delegate this responsibility, work with clear governance structures and regularly verify that NIS2 standards are being met.
Source: news.google.com · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.