13.02.2026

4 min Reading Time

NIS2 and DORA hold executives and board members personally liable if cybersecurity is grossly neglected within the company. For CIOs and CISOs, this fundamentally changes the rules of the game: implementing technical measures alone is no longer enough. Documenting one’s duty of care has become a personal shield.

TL;DR

  • ⚖️ Personal liability enshrined: NIS2 Article 38 and DORA Article 5 obligate executive management to oversee cybersecurity. Gross negligence may trigger personal liability.
  • 💰 Fines up to €10 million: NIS2 stipulates penalties of up to €10 million or 2% of global annual turnover. The EU AI Act goes as high as €35 million.
  • 📋 Documentation is mandatory: Only demonstrable compliance measures protect against personal liability. Board resolutions, audit reports, and risk assessments constitute legal safeguards.
  • 🎓 Mandatory training for board members: NIS2 explicitly requires executives to attend cybersecurity training and be able to demonstrate sufficient knowledge.
  • 🛡️ Five protective measures: A governance framework, regular board training, documented risk decisions, review of D&O insurance, and external audits.

The End of Delegated Responsibility

For decades, executives and managing directors could delegate cybersecurity responsibility to the CISO or IT department. As long as no major incidents occurred, the topic remained at the operational level. NIS2 ends that model. Paragraph 38 of the revised BSI Act (Federal Office for Information Security Act) states unequivocally: Executive management must supervise the implementation of risk management measures – and is liable for violations.

Concretely, this means: If a company falls under NIS2 and executive management can be shown to have approved inadequate measures, those individuals may be held personally liable – even if no actual damage has occurred. The duty applies from the outset, in prevention – not only after an incident.

DORA intensifies this approach for the financial sector. Article 5 mandates that the management body of a financial undertaking bears ultimate responsibility for ICT risk management. While delegation to operational units remains permissible, it does not relieve the management body of overall accountability. Germany’s Federal Financial Supervisory Authority (BaFin) has signaled it will enforce this obligation rigorously.

“We must continue building Germany’s ‘Cyber Nation’. The threat landscape has never been more severe – and cybersecurity must be top-management business.”Claudia Plattner, President of the BSI (Federal Office for Information Security), IT Security Situation Report 2025

What the Laws Specifically Require

NIS2 (Paragraph 38, BSI Act): Executive management must supervise the implementation of risk management measures outlined in Paragraph 30. It must attend cybersecurity training and be able to demonstrate adequate knowledge. Personal liability applies in cases of gross negligence – and cannot be excluded by corporate bylaws or shareholder agreements.

DORA (Article 5): The management body bears ultimate responsibility for ICT risk management. It must approve the ICT risk framework, define the cyber-resilience strategy, and supervise implementation. At least once per year, the management body must assess the appropriateness of these measures. Violations may incur sanctions imposed by national financial regulators.

EU AI Act: For high-risk AI systems, the provider or operator bears responsibility for conformity. Breaches of high-risk obligations may trigger fines of up to €35 million or 7% of global annual turnover. Although the EU AI Act does not explicitly prescribe personal liability for executives, general corporate law on organ liability may apply if executives fail to supervise compliance obligations.

10 Mio. €
NIS2 fine (maximum)
35 Mio. €
EU AI Act (maximum)
§ 38
BSI Act: Executive liability

Sources: NIS2 Implementation Act (NIS2UmsuCG), EU AI Act (2024/1689), DORA (2022/2554)

D&O Insurance: Not Automatic Protection

Many executives rely on their Directors-and-Officers (D&O) insurance. Yet coverage has limits. D&O policies typically exclude intentional breaches of duty. Coverage for gross negligence depends entirely on the specific policy terms. It is reasonable to expect insurers to tighten requirements for demonstrating due diligence following the entry into force of NIS2 obligations.

CIOs and CISOs – jointly with the legal department – should urgently verify: Does the existing D&O policy cover cybersecurity liability risks under NIS2 and DORA? Does it contain exclusions for regulatory violations? Is the coverage limit sufficient given the new fine ceilings? This review must be completed without delay.

Five Protective Measures for CIOs and Executives

1. Document a Governance Framework. A written cybersecurity governance framework that clearly defines responsibilities, processes, and escalation paths. The framework must be formally adopted by the board and updated regularly. It serves as the central proof that executive management fulfills its supervisory duty.

2. Conduct Regular Board Training. NIS2 explicitly requires executive management to attend cybersecurity training. Documented attendance at a minimum of two sessions per year is the baseline standard. Training should address current threat landscapes, regulatory updates, and industry-specific risks.

3. Document Risk Decisions. Every board decision concerning cybersecurity measures must be recorded in minutes. Even the conscious acceptance of residual risk must be documented and justified. In liability proceedings, documentation of the decision-making process offers the strongest protection against allegations of gross negligence.

4. Review and Adapt D&O Insurance. Audit existing policies for coverage of cybersecurity liability risks and regulatory violations. Where necessary, expand coverage – or procure dedicated cyber-D&O policies. This insurance review must be completed immediately.

5. Commission External Audits as Evidence. An independent audit conducted by a qualified auditor objectively documents the state of cybersecurity measures. ISO/IEC 27001 certification – or equivalent attestations – significantly strengthens the board’s position in liability proceedings. Audits should be repeated at least annually.

What CIOs Must Tell the Board – Now

The message to the board is uncomfortable – but essential: Since the NIS2 Act entered into force, cybersecurity has become a matter of personal liability for each individual board member. Delegation to the CISO or IT department no longer shields executives from personal accountability. The board must actively supervise, undergo regular training, and meticulously document its decisions.

CIOs who deliver this message early – and simultaneously build the required governance structures – lay the foundation for legally secure IT leadership. Ignoring the issue risks not only corporate fines but also personal careers and private assets. The time to act is now.

Frequently Asked Questions

Is the CIO personally liable under NIS2?

Yes – if the CIO is part of executive management or has formally assumed cybersecurity responsibility, personal liability may apply in cases of gross negligence. Paragraph 38 of the BSI Act assigns the supervisory duty to executive management and expressly prohibits exemption from liability via corporate bylaws.

What constitutes gross negligence under NIS2?

Gross negligence arises when executive management disregards fundamental duties of care – for example, by failing to implement any risk management system, lacking incident response processes, or ignoring known security vulnerabilities. A documented governance framework and regular audits are the strongest defenses against such allegations.

Does D&O insurance protect against NIS2 liability?

Conditionally. D&O policies typically exclude intentional breaches of duty. Coverage for gross negligence depends on the precise policy wording. CIOs should audit their D&O policy for cybersecurity liability exposure and adjust coverage where needed.

What training must executives demonstrate?

NIS2 requires executives to prove sufficient cybersecurity knowledge. We recommend at least two documented training sessions per year covering current threats, regulatory requirements, and sector-specific risks.

When do the new liability rules take effect?

The NIS2 Implementation Act entered into force in December 2025; the registration deadline with the BSI was March 2026. DORA has applied since January 2025. The EU AI Act becomes applicable to high-risk systems from August 2026. Companies therefore have only a few months left to establish compliant governance structures.

Editor’s Reading Recommendations

Header Image Source: Vlada Karpovich / Pexels

Share this article:

More Articles

11.04.2026

Chief AI Officer 2026: Real Role or Just Another C-Level Title?

Tobias Massow

⏳ 9 min read The Chief AI Officer is the most frequently announced-and least understood-C-level ...

Read Article
10.04.2026

Cloud Repatriation 2026 Is a Statistical Illusion

Benedikt Langer

7 Min. Lesezeit "86 Prozent der CIOs planen Cloud Repatriation" lautet die Überschrift, die sich seit ...

Read Article
08.04.2026

AI Governance 2026: Only 14% Have Clarified Who Is Responsible

Tobias Massow

7 Min. Reading Time 87 percent of companies are increasing their AI (Artificial Intelligence) budgets. ...

Read Article
07.04.2026

18 Percent Pay Gap, an EU Deadline, and Little Preparation: Salary Transparency from June 2026

Benedikt Langer

8 min. reading time Starting June 2026, salary ranges must appear in job postings. Inquiring about current ...

Read Article
06.04.2026

Cyber Insurance 2026: Premiums Doubled, Coverage Halved – The Calculation No CFO Wants to See

Benedikt Langer

6 Min. Read 15.3 billion US dollars in premium volume, a 15 to 20 percent price increase for 2026, and ...

Read Article
05.04.2026

IT Budget 2027: Three Quarters for Operations – That’s the Problem

Benedikt Langer

6 min read By 2026, companies worldwide will spend $6.15 trillion on IT. That sounds like an unprecedented ...

Read Article
A magazine by Evernine Media GmbH