NIS2 and management liability — what the board actually has to do

NIS2 changed something that most cybersecurity regulation leaves alone. It does not only tell the organisation what to do — it tells the management body, by name, that these decisions are theirs, and that they can be held responsible for failing to make them.

First hour’s on us. No commitment.

What you get

  • A board session in plain language — what the law asks of them specifically, framed as decisions rather than terminology
  • The approval documentation, so the decision exists in a form that can be produced later
  • A training record that satisfies the requirement without becoming a compliance theatre exercise
  • A standing reporting format, so oversight is continuous rather than annual
  • Clarity on what “responsible” means in the Swedish implementation

How it works

  1. Intake, 45 minutes. Your governance structure and where cybersecurity currently sits. Free.
  2. The session, run with the board or management team.
  3. The documentation — approval, training record, reporting cadence.

Who you’ll work with

Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.

What the law places on the management body

Three things, and they are separable.

Approval. The management body must approve the cybersecurity risk management measures. Not note them, not delegate them — approve them. That means the measures have to be presented in a form a board can understand well enough to approve honestly.

Oversight. They must oversee implementation. A single approval followed by silence for two years is not oversight, and the gap is visible in the minutes.

Training. Members must undergo training to gain sufficient knowledge to identify risks and assess cybersecurity risk management practices. There is also an expectation that similar training is offered to staff.

And the consequence: members of the management body can be held responsible for infringements. The Swedish implementation and the NIS2 Directive both contemplate that supervisory authorities can require entities to make infringements public, and can suspend or restrict the exercise of managerial functions in defined and serious circumstances for essential entities.

Why this changes the conversation internally

Cybersecurity budgets have historically been argued on operational grounds and lost to other priorities. NIS2 changes who is exposed if the argument is lost.

In our experience this is the single provision that moves a board from receiving an annual update to asking questions. Used well, it is not a threat — it is the reason the CISO finally gets a decision instead of a deferral.

It is worth being precise rather than dramatic about it. The exposure is real but it is not unlimited personal liability for any incident. It attaches to failures of the specific duties: approving the measures, overseeing them, and being equipped to do both.

What “approving the measures” should actually involve

A board cannot meaningfully approve a hundred-page technical standard. What they can approve, and should be asked to:

  • The risk assessment — what could happen, how likely, how bad
  • The measures proposed against each significant risk, and what they cost
  • The risks being accepted rather than mitigated, stated explicitly
  • Who owns delivery, and by when
  • What will be reported back, and how often

That is a decision document. If what reaches the board is a technical annex, the approval is not worth much — to the board or to a supervisor.

Training that is worth the hour

The requirement is knowledge sufficient to identify risks and assess practices. That is not a certification and it is not a general awareness video.

What works for a board: the threat picture specific to their sector, the organisation’s own significant risks in business terms, what the measures do and do not protect against, what happens operationally during an incident and what decisions land on them, and the reporting obligations with their timelines. Two hours, well prepared, with a record of who attended.

Frequently asked questions

Does this apply to individual board members personally?

The duties sit on the management body, and members can be held responsible for infringements. The Directive also provides for supervisory measures including, for essential entities in serious cases, temporary restrictions on exercising managerial functions. The precise consequences depend on the national implementation and the circumstances.

Can we delegate this to the CISO?

Delivery, yes. Approval and oversight, no — those are placed on the management body and cannot be delegated away. A good CISO makes the board’s job possible; they do not do it instead.

What counts as adequate training?

The law sets a standard, not a format. What matters is that it is proportionate to the role, relevant to your sector, and documented. Keep the materials and the attendance record.

How often should the board see this?

Continuous oversight suggests more than annually. A standing item with a short report each quarter, plus an immediate escalation path for significant incidents, is a defensible pattern.

We are an important rather than essential entity. Does this still apply?

The management body duties apply to both. What differs is the supervisory regime and the upper limits for sanctions.

Where to start

With one session for the people who have to sign. It usually takes an hour to establish what is actually being asked of them, and that first conversation costs nothing.

Related