How to Stifle Open Source Without Banning It
Benedikt Langer
6 Min. Read The sharpest argument against China’s top open AI comes from a man at OpenAI. Dean Ball, ...
The amended BSI Act has been in force since December 5, 2025. In April 2026 it starts to show its first operational effect. Germany’s NIS2 implementation turns cybersecurity into a topic for which the executive leadership is personally accountable. It can no longer be delegated, no longer be outsourced to the IT department, and carries fines of up to 10 million euros or 2 percent of global group revenue. The National Law Review’s current assessment sums it up: the new BSIG makes cybersecurity a board-level issue. As of: April 14, 2026.
Key Takeaways
RelatedReboot Germany: three decisions that stay in the boardroom/Cloud Repatriation 2026 from the CIO perspective
For executives of companies covered by NIS2, three concrete decisions arise from this shift and will be taken in the coming weeks. None of them is new. All three change in mechanics, because the legal consequences for inaction now land directly with the individual members of the leadership team.
The BSI advisory wave in late March on F5 BIG-IP, Citrix NetScaler and a Trivy supply chain compromise delivered the first real stress test. Three critical warnings in three weeks, each with a 24-hour reporting deadline upon confirmed exploitation. How quickly a leadership team can actually make decisions got its first concrete answer in April 2026.
At the core of the amendment are two shifts. The first concerns responsibility: executive leadership has to not only approve cybersecurity risk management measures but also oversee implementation and complete regular training. The second shift concerns sanctions: in addition to fines against the company, executives can now be held personally liable if the violation stems from an organizational failure.
For large companies with established compliance structures, this is a gradual adjustment. For mid-market companies that fall under the expanded NIS2 definition for the first time, it is a reassessment. The expanded scope now also covers postal and courier services, research organizations, food production, waste management and parts of the chemical industry.
The practical work begins with the classification: does the company fall into the “essential” or “important” category? The two categories carry different levels of duty. Essential entities are subject to proactive supervision, important entities are audited on an incident basis. The difference becomes tangible in daily operations the moment the BSI announces an audit.
From the operational experience of the first four months after the law took effect, three concrete decisions are crystallizing that are being handled by the leadership. None is a surprise, but the form in which they are documented and decided is new.
First decision: the escalation architecture. Who decides during an IT security incident whether a notification goes to the BSI? The 24-hour early warning deadline under NIS2 leaves no time for ad-hoc committee meetings. The answer is a predefined decision chain with clear authorities: who can decide alone, who has to be informed, at what severity level does the leadership get involved? The mechanics behind this are a RACI matrix, not an org chart.
Second decision: the investment sequence. Risk management under NIS2 demands ten concrete areas of measures, from supply chain security to business continuity. Which ones get implemented first? The decision depends on the company’s own risk profile. For manufacturing companies, supply chain risk management is the priority. For financial services providers, incident handling is the most urgent building block. For ICT companies, the focus is on cryptography and access control. The decision is not a standard checklist but a prioritization based on one’s own threat landscape.
Third decision: the governance structure. Who on the leadership team owns cybersecurity as a portfolio? In many mid-market companies there is no formal CISO role; responsibility sits with the IT director or an external service provider. The NIS2 amendment makes this construct risky: the leadership duty rests with the executive team, not with a service provider. The decision can be to create a dedicated CISO role, to explicitly anchor responsibility in an executive portfolio, or to build a documented co-governance with a certified partner. What no longer works is the previous silent delegation.
The three BSI advisories at the end of March and beginning of April were the first load test for the new structures. An F5 BIG-IP vulnerability with remote code execution, Citrix NetScaler with documented active exploitation, a Trivy container supply chain compromise. Each of these advisories triggered the same question at companies running the affected products: are we under an early warning notification duty?
The experience of the first two weeks reveals three patterns. Companies with clearly documented incident response processes achieved clarity within hours and notified when in doubt. Companies with semi-formalized processes needed days before an internal decision was made – in some cases past the 24-hour deadline. Companies facing NIS2 reporting duties for the first time understood the advisories as a wake-up call and built the missing structures in parallel to the acute incident.
None of these patterns is acceptable for the second half of 2026. Starting in July, the first larger BSI audits at essential entities will begin. That is where the quality of the decision architecture becomes visible. A leadership team that cannot precisely explain in an audit interview how escalation works, who decides what, and how effectiveness is measured, risks significantly more than a final fine.
Cybersecurity requirements don’t exist in isolation. They overlap with DORA for the financial sector (fully applicable since January 2025), the Cyber Resilience Act starting September 2026, the NIS2 sector laws for energy and health, and the AI Act with the first prohibitions entering into force on April 6, 2026. For companies that fall under several of these regimes, consolidation is the only realistic strategy. A unified risk management framework that covers all relevant regulations saves 40 to 60 percent of effort over the long run compared to isolated compliance silos.
The same applies to the governance question. Anyone introducing a Chief AI Officer role should define the interfaces to CISO and data protection officer clearly from the start. The three roles have overlapping responsibilities. A clean separation determines whether compliance runs efficiently or fragmented.
The strategic question of which technologies to bring in-house also has to be re-evaluated in light of NIS2. The much-cited move toward cloud repatriation as an answer to data sovereignty gains additional arguments once reporting chains, incident response and audit rights become decision criteria. A cleanly run hybrid architecture is often a better answer than a pure lift-and-shift into the public cloud.
By the end of June 2026, companies that start now can take and document the three decisions above. The escalation architecture can be built in two workshops with executive leadership, IT leadership, legal and communications, using a structured template. The investment sequence emerges from a threat analysis that an experienced security team can deliver in four to six weeks. The governance structure is a staffing decision that can be implemented within a quarter.
The parallel vendor consolidation roadmap that many CIOs are running is a natural ally: anyone reducing the SaaS portfolio anyway can review cybersecurity governance questions at the same time. Two decision fields merge into one, with a clear efficiency gain.
Anyone who starts later loses control of the timing. The BSI audits expected in the third and fourth quarter of 2026 will happen regardless of internal resource availability. The decision to start today with three clear steps is the only one that leaves room for your own priorities. Those who wait are still deciding indirectly – just under significantly more pressure and with less room for individual weighting.
Some industries went through the shift to leadership responsibility earlier. The financial sector has known comparable structures with MaRisk and DORA for more than ten years. Experience there points to three lessons that transfer directly. First: documented decisions matter more than particularly sophisticated ones. A traceable justification for why an investment was deferred holds up in any audit. An unwritten but well-considered decision does not.
Second lesson: effectiveness verification is the most effort-intensive part. Approving measures is done in a few meetings. Measuring effectiveness regularly and adjusting measures when needed is a continuous process that ties up resources. Financial institutions have built dedicated compliance teams for that. For mid-market companies, a simpler variant with an annual review plus a quarterly KPI dashboard is often enough.
Third lesson: communication between leadership and operational teams must be structured. Informal alignment doesn’t suffice when, during an audit, communication paths and decision outcomes have to be reconstructed. A monthly structured meeting with a fixed agenda and minuted decisions is the minimum setup. Adding an annual independent review by an external partner brings the level of maturity BSI auditors expect at essential entities.
A fourth lesson from the financial sector belongs here: leadership members who understand the topic noticeably relieve the executive team. Investing in leadership training pays off twice: reduced personal liability exposure and faster, better-founded decisions. A two-day intensive course in the next three months is a small investment with a clear effect. Comparable offerings exist at TÜV academies, Fraunhofer training programs and industry associations. Companies filling supervisory board seats now consider NIS2 and DORA literacy in their candidate selection – that, too, is a subtle but relevant lever over the coming 24 months. Companies that build competence now won’t groan under the third wave of regulation in 2027; they will accept it as a baseline.
NIS2 applies across sectors from 50 employees or 10 million euros in annual revenue. In particularly sensitive sectors such as energy, healthcare or digital infrastructure, the duty can also reach smaller companies if their failure would have significant impact. The concrete classification follows from the annex to the amended BSI Act.
Personal fines are not automatic. They require a culpable organizational failure. The threshold is lower than in general civil law because NIS2 defines clear minimum requirements. Anyone ignoring the leadership duty, skipping training or failing to implement risk management measures meets the criteria.
IT Security Act 2.0 already knew reporting duties for KRITIS operators. The amendment to the BSI Act expands these duties significantly: more companies in scope, more concrete catalogs of measures, tougher sanctions and, for the first time, personal responsibility of the executive team for implementation. The previous practice of fully delegating cybersecurity to IT is no longer legally safe.
DORA is lex specialis for financial services – it takes precedence in its areas. In practice that means: financial companies must primarily be DORA-compliant; NIS2 requirements only apply to areas not covered by DORA. The organizational structure can still be built uniformly if the company takes the stricter DORA requirements as the baseline.
The BSI typically reviews risk analysis, catalog of measures, incident response documentation, training records for the leadership, process descriptions for reporting chains and the effectiveness measurement of implemented measures. All documents should be structured, current and timestamped. Consistent versioning makes it easier to show that improvements happened systematically.
Editor’s picks
Further reading in the MBF Media network
AWS and Google Cloud launch a multicloud preview
EU AI Act in force since April 6, 2026
BSI warns on F5, Citrix and Trivy
Cover image source: Pexels / fauxels
Image source: AI-generated (Juni 2026), C2PA certificate embedded