Glossary
Management Accountability
A major shift under NIS 2: cyber compliance now personally engages the legal and financial liability of executives, not just that of the legal entity.
Management accountability is a major shift introduced by NIS 2: responsibility for cyber compliance no longer rests solely with the company as a legal entity — it now personally engages the legal and financial liability of its executives (managers, board members). They have a legal obligation to approve security measures and undergo training dedicated to cyber threats.
What the directive says
Article 20 of NIS 2 requires the management bodies of essential and important entities to:
- Approve the cybersecurity risk-management measures implemented by the entity.
- Oversee their effective implementation.
- Undergo training specific to cyber threats so they can make informed decisions.
- Be held personally accountable in the event of proven failures to comply with the directive's obligations.
Practical implications
- A CEO, managing director or board member can be held personally liable for a sanction imposed on their company for NIS 2 non-compliance.
- In the most serious cases, competent authorities can impose a temporary ban from holding management positions.
- Delegating cybersecurity to the CISO alone is no longer enough — management must be actively involved and trained.
Best practice
Appoint a NIS 2 lead within senior management, document cyber governance decisions, and keep evidence of executive training.