Operational Technology in factories presents attackers with significantly lower barriers than modern IT infrastructure, while cyber outages in production have existential consequences.
The planned BSIG amendment mandates executive leadership training in NIS2 requirements and establishes cybersecurity governance as a legally binding management responsibility.
From May 2026, NIS2 requirements will be actively enforced by EU authorities, the implementation deadline expires and enforcement measures take effect.
NIS2 affects approximately 30,000 German companies and requires CISOs to implement new governance, risk management systems, and incident reporting obligations.
Starting in 2025, 30,000 companies must implement NIS2 and DORA requirements, forcing CISOs to review their governance, incident management, and third-party dependency management.
NIS2 makes cybersecurity a leadership responsibility at board level, not just an IT matter — CISOs must operate more strategically and work closer to senior management in the future.