FC Health Index1,428.60+0.42%Novo NordiskDKK 812.4+1.10%Intuitive SurgicalUSD 546.9−0.30%EU AI Act — Art. 6in forceM+7FDA 510(k) AI clearances (YTD)312+18 w/wNHS AI Diagnostic Fund£123mcommittedKarolinska trials open48+2Reimbursement CPT codes (AI)17+1 QFC Health Index1,428.60+0.42%Novo NordiskDKK 812.4+1.10%Intuitive SurgicalUSD 546.9−0.30%EU AI Act — Art. 6in forceM+7FDA 510(k) AI clearances (YTD)312+18 w/wNHS AI Diagnostic Fund£123mcommittedKarolinska trials open48+2Reimbursement CPT codes (AI)17+1 Q
Wednesday, 16 September 2026 · Oslo · London · New York

Enterprise · Explainer

NIS2 made directors personally accountable for cyber risk. Most boards still treat it as an IT budget line.

The European network and information security directive shifted responsibility upward. The organisations handling it well changed their governance, not their firewall.

A boardroom corridor, empty
A boardroom corridor, empty

Independent coverage

A

By AJ Dellinger

Contributing Writer — Cybersecurity / Tech Policy · Freelance

Edited by Clara Bergman

Published 25 August 2026

7 min read

Evidence: Analysis

NIS2 widened the set of European organisations subject to mandatory cybersecurity obligations, and it did something more consequential than widening scope. It attached management accountability.

Directors are expected to approve risk measures, to understand them, and to be trained. In several member state transpositions, failure carries personal consequence.

The misreading

The common board response has been to increase the security budget and to ask the security team for reassurance. This satisfies neither the letter nor the intent of the directive.

What is required is evidence that management identified the risks, decided what to do about them, and can explain the decision, including the risks it chose to accept.

The four practical obligations

Incident reporting within tight deadlines, which requires a decision process that works at two in the morning rather than a policy document.

Supply chain risk management, the obligation most organisations are furthest from meeting, since it requires knowing which suppliers can affect your service availability.

Business continuity that has been tested rather than written.

And management training that is documented.

What good looks like

The organisations assessed as well prepared in interviews for this piece share an unremarkable pattern. A standing board agenda item, a named executive owner who is not the head of IT, a supplier register with criticality ratings, and at least one incident exercise per year involving the executive team rather than only the security function.

None of that is expensive. All of it is governance work that cannot be delegated to the people it is meant to oversee.

Sources

Published 25 August 2026