Managing Director Liability: Why NIS2 Makes IT Security an Executive Priority

Martin Bastius
01.04.2026
999
min.

Introduction

In the past, IT security was often viewed in the executive suite as a "necessary evil" — a technical discipline confined to the depths of the IT department. As long as the systems kept running, management rarely saw a reason to get personally involved in firewall configurations or patch management cycles. But the digital threat landscape has changed dramatically. Ransomware attacks today aren't a matter of "if," but "when."

The European Union is responding to this volatile situation with the NIS2 Directive. Its core goal: a consistently high level of security across all member states. But the real twist isn't just the tightened technical requirements — it's the clearly assigned accountability. Under NIS2, cybersecurity becomes a non-delegable leadership responsibility. Managing directors who turn a blind eye to cyber risks are now putting not just company assets on the line, but their personal livelihood.

What Does NIS2 Mean for Company Management?

The NIS2 Directive (Network and Information Security Directive 2.0) is the response to the growing professionalization of cybercrime. While its predecessor, NIS1, primarily targeted large critical infrastructure operators (such as energy suppliers or hospitals), NIS2 massively expands the scope of application.

Under the current state of its transposition into German law (the NIS2UmsuCG), significantly more businesses now need to prepare for strict controls. Affected sectors include chemicals, food, waste management, digital services, and manufacturing. Once a company reaches the thresholds of 50 employees or €10 million in annual revenue, it comes into the regulators' focus.

For company management, this represents a paradigm shift:

  • Personal approval: You can no longer simply rubber-stamp security concepts. You need to understand and formally approve them.
  • Duty of oversight: It's not enough to approve a budget. You need to demonstrate that measures were actually implemented and are effective.
  • Direct responsibility: The complexity of IT doesn't exempt you from responsibility. The law assumes that a prudent managing director knows the risks of their digital infrastructure.

Why IT Security Can No Longer Be Delegated

A widespread misconception among German businesses is the belief that liability can be fully delegated by appointing a competent IT manager or an external service provider. Legally speaking, this is a dangerous misjudgment.

While operational execution (the "doing") can be delegated, the organizational and oversight responsibility mandatorily remains with the management body. NIS2 sharpens this point: management must not only fund risk management measures, but actively oversee their implementation.

The finance comparison: A managing director can delegate bookkeeping but remains liable for the accuracy of the balance sheet and for avoiding delayed insolvency filings. IT security now holds exactly that same status under NIS2. Cyber risks are strategic risks today. A total IT outage caused by a hacking attack is equivalent to a fire destroying an entire production facility. Anyone who fails to manage such risks at the board level is in breach of duty.

What Specific Duties of Care Arise

To avoid liability under NIS2, managing directors must fulfill a set of duties of care. These can be broken down into five core areas:

  1. The duty to stay informed: You need to establish a system that regularly informs you about the threat landscape. Waiting for the annual report isn't enough. Critical vulnerabilities or attempted attacks must be escalated promptly.
  2. The duty to approve: Strategic documents such as the information security concept or the incident response plan must be signed off by management. This documents that you consciously determined your company's level of protection.
  3. The duty of oversight: You need to establish control mechanisms. Who verifies that backups actually work? Who ensures that departed employees no longer have network access? Management must have the effectiveness of these controls confirmed to them regularly.
  4. The duty to train: This is one of the most underestimated points. NIS2 explicitly requires leadership to participate in training. The goal is to equip you to competently assess cyber risks and their impact on business operations.
  5. The duty to allocate resources: Security costs money. If the IT department has been complaining about outdated systems for years and management rejects necessary investments without a valid reason, that constitutes a clear breach of duty.

The Liability Trap: Fines and Personal Consequences

Penalties under NIS2 are strict and modeled on the logic of the GDPR, but often go even further in terms of personal consequences.

Corporate fines:

For "essential entities," fines of up to €10 million or 2% of global annual revenue are on the table. For "important entities" (many mid-sized companies), it's still up to €7 million or 1.4% of revenue. These amounts can directly threaten a company's financial stability.

Personal internal liability:

Far more threatening for managing directors, however, is internal liability under Section 43 of the German Limited Liability Companies Act (GmbHG) or Section 93 of the Stock Corporation Act (AktG). If a company has to pay a multi-million-euro fine because management neglected its NIS2 obligations, the shareholders' meeting can hold the managing director personally liable for damages.

The Role of D&O Insurance:

Many managers feel a false sense of security because they've taken out D&O (Directors and Officers) insurance. But beware: insurers only pay out in cases of simple negligence. If a clear legal requirement — such as the NIS2 training obligation — was ignored, insurers often argue "knowing breach of duty" or "grossly negligent organizational failure" and refuse to pay.

Risk Management: The Strategic Tool

NIS2 doesn't demand absolute security, but rather appropriateness based on the current state of the art. Through a structured risk analysis (identifying critical assets and threat scenarios), management can make well-founded decisions about investments or residual risks. This documentation is the most important tool for demonstrating diligent conduct during audits.

Documentation and the Reversal of the Burden of Proof

In the event of a claim, the burden of proof is reversed: you have to prove that you fulfilled your duties of care. Without a complete "NIS2 file" — including management minutes, proof of budget allocation, and training certificates — this proof is nearly impossible to provide. Digital compliance platforms serve here as a legally sound "life insurance policy."

Supply Chain Security and Governance

Responsibility doesn't end at the company's front door. You need to ensure that direct suppliers also maintain appropriate security standards. This requires active governance and a "tone from the top": IT security must be established as part of company culture, including clear role allocation and an open culture around handling incidents.

Conclusion: Responsibility as an Opportunity

The NIS2 Directive forces a long-overdue professionalization. For managing directors, this means greater personal liability — but also the opportunity to make their business crisis-proof. Companies that operate in compliance with NIS2 don't just minimize risk; they also secure a competitive advantage with customers and insurers.

Published
01.04.2026
Martin Bastius
Co-Founder & CLO

More articles

View all articles
Data Protection & GDPR
4/3/24

Secure Handling of Ex-Employee Emails Under GDPR

Secure Handling of Ex-Employee Emails Under GDPR
AI & Data Governance
7/11/25

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant
AI & Data Governance
6/12/26

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection
Discover all stories