The planned BSIG amendment mandates executive leadership training in NIS2 requirements and establishes cybersecurity governance as a legally binding management responsibility.
From May 2026, NIS2 requirements will be actively enforced by EU authorities, the implementation deadline expires and enforcement measures take effect.
AI agents function reliably only with comprehensive observability that reveals causal relationships in complex systems—not through language models alone.
NIS2 makes cybersecurity a leadership responsibility at board level, not just an IT matter — CISOs must operate more strategically and work closer to senior management in the future.
NIS2 makes board members personally liable for cybersecurity and requires annual management documentation – CISOs must establish formal compliance evidence.
Ransomware attack costs Marks & Spencer £131.3 million directly and reduces profit by £210 million, prompting the remuneration committee to strip the CEO’s annual bonus.