In brief: Chief executives bear personal responsibility for cybersecurity under NIS2 and can face fines up to 15 million euros.
Germany’s NIS2 implementation establishes personal liability of chief executives for inadequate cybersecurity. In critical infrastructure and sectors, fines up to 15 million euros can be imposed.
The national implementation of the NIS2 Directive in Germany establishes clear accountability at the management level. Chief executives and comparable senior management are now personally responsible for ensuring adequate cybersecurity measures in their companies — not only as a legal entity, but as individuals.
The framework provides for substantial financial consequences: fines reach up to 15 million euros for violations of cybersecurity obligations. This liability applies in particular to companies classified as operators of critical infrastructure or as providers of digital services and thus fall under NIS2 requirements. Personal liability applies regardless of whether security deficiencies were directly caused by the chief executive or by employees — as long as control obligations were breached.
For chief executive officers, this represents a fundamental reorientation of governance and risk management. Merely delegating cybersecurity to IT departments does not absolve management of its personal responsibility. Documented governance structures, regular risk assessments, and demonstrably implemented security measures are necessary to minimize personal liability risks.
Source: news.google.com · Published 16 July 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.