Skip to content

NIS2: Executives and Board Members Face Personal Liability for Cybersecurity

Bottom line: NIS2 imposes personal liability on executives for cybersecurity with penalties up to 15 million euros or 2.5 percent of annual revenue.

The EU’s NIS2 Directive mandates personal liability for CEOs and board members regarding cybersecurity in critical infrastructures and enterprises. Violations can result in fines up to 15 million euros or a percentage of annual revenue.

With the transposition of the NIS2 Directive into national law, the personal responsibility of management for cybersecurity measures is being concretized. The regulations require executives and board members to demonstrate adequate technical and organizational measures to protect critical infrastructures and essential services.

Liability applies to operators of critical infrastructures in the sectors of energy, water, transport, finance and healthcare, as well as to digital service providers and suppliers of ICT security products. Management must document that appropriate cybersecurity measures have been implemented, regularly reviewed and adapted to current threats.

Standard fines range up to 15 million euros or, for large corporations, up to 2.5 percent of global annual revenue. For CEOs and board members, this represents direct personal liability exposure that goes beyond traditional compliance responsibility.

Companies must therefore establish governance structures that anchor security investments, risk assessments and incident response plans at board level. In doing so, security is no longer a technical detail but a core responsibility of management with direct consequences for liability and insurance.


Source: news.google.com · Published July 16, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: