Enterprise · Explainer
NIS2 made directors personally accountable for cyber risk. Most boards still treat it as an IT budget line.
The European network and information security directive shifted responsibility upward. The organisations handling it well changed their governance, not their firewall.

Independent coverage
Published 25 August 2026
7 min read
Evidence: Analysis
NIS2 widened the set of European organisations subject to mandatory cybersecurity obligations, and it did something more consequential than widening scope. It attached management accountability.
Directors are expected to approve risk measures, to understand them, and to be trained. In several member state transpositions, failure carries personal consequence.
The misreading
The common board response has been to increase the security budget and to ask the security team for reassurance. This satisfies neither the letter nor the intent of the directive.
What is required is evidence that management identified the risks, decided what to do about them, and can explain the decision, including the risks it chose to accept.
The four practical obligations
Incident reporting within tight deadlines, which requires a decision process that works at two in the morning rather than a policy document.
Supply chain risk management, the obligation most organisations are furthest from meeting, since it requires knowing which suppliers can affect your service availability.
Business continuity that has been tested rather than written.
And management training that is documented.
What good looks like
The organisations assessed as well prepared in interviews for this piece share an unremarkable pattern. A standing board agenda item, a named executive owner who is not the head of IT, a supplier register with criticality ratings, and at least one incident exercise per year involving the executive team rather than only the security function.
None of that is expensive. All of it is governance work that cannot be delegated to the people it is meant to oversee.
Sources
Related reading