Insights

NIS2 board liability: Why CEOs can no longer delegate cyber risk

NIS2 board liability reflects a fundamental shift in cybersecurity governance. Executive leadership now plays a direct role in overseeing cyber risk, supporting resilience efforts, and helping ensure effective incident response.

For years, cybersecurity was viewed as a technical responsibility managed by IT and security teams. Boards received periodic updates, CISOs oversaw security programs, and executive leadership focused on broader business priorities. That approach is becoming increasingly difficult to justify as cyberattacks grow more disruptive, supply chain risks expand, and regulators demand greater accountability from organizational leadership.

The European Union’s NIS2 Directive represents a new approach to governing cyber risk. Unlike its predecessor, NIS2 places explicit responsibility on senior leadership through strengthened management accountability requirements. Boards and executives are expected to approve cybersecurity risk management measures, oversee their implementation, and ensure their organizations can respond effectively to cyber incidents. In other words, cybersecurity can no longer be delegated entirely to technical teams.

For organizations operating in Sweden and across the EU, cyber risk is now a governance issue with operational, financial, and regulatory implications. As a result, NIS2 board liability, executive accountability, and CEO personal responsibility are becoming important business considerations.

This article explores what NIS2 means for executive leadership, how accountability requirements are changing, and the steps boards, CEOs, and CISOs can take to strengthen governance, resilience, and compliance efforts.

DIVIDER

At a glance

DIVIDER

Why NIS2 changes executive accountability

The cybersecurity threat landscape has evolved significantly since the original NIS Directive was introduced in 2016. Ransomware, software supply chain compromises, and attacks targeting critical infrastructure have demonstrated that cyber incidents can disrupt operations, impact revenue, damage reputations, and create regulatory exposure. Cybersecurity is now viewed as a business risk rather than solely an IT issue. NIS2 management accountability requirements place greater emphasis on executive oversight and cybersecurity governance in response to these challenges.

The directive also reflects growing concerns about the interconnected nature of modern organizations. Third-party suppliers, cloud providers, operational technology (OT) environments, and digital infrastructure can introduce risk beyond traditional corporate networks. Disruptions can extend across entire ecosystems, making executive oversight essential to strengthening resilience and protecting critical services.

The evolution from NIS1 to NIS2 reflects these changing realities. The original NIS Directive established baseline cybersecurity requirements for operators of essential services, but regulators determined that expanded coverage, stronger oversight, and clearer accountability were needed to address today’s threat landscape. According to European Commission estimates, more than 160,000 entities fall within the scope of NIS2. The updated framework also expands coverage across 18 critical sectors, underscoring the growing importance of protecting essential services, supply chains, and digital infrastructure throughout the EU.

DIVIDER

NIS1 vs. NIS2 for executives

The most important change is the move from indirect oversight to direct accountability. The original NIS framework primarily focused on organizational cybersecurity obligations. NIS2 goes further by establishing clearer expectations around leadership involvement, cybersecurity governance, and management oversight. As regulatory expectations continue to evolve, executive teams are responsible for ensuring that cybersecurity is governed at the highest levels of the organization.

DIVIDER

Board and executive responsibilities under NIS2

While security teams remain responsible for day-to-day operations, NIS2 requires leadership to oversee how cyber risk is identified, managed, and monitored across the organization.

Boards and executive teams must approve cybersecurity risk management measures, oversee their implementation, and ensure sufficient resources are allocated to support organizational resilience.

The directive also establishes ongoing governance responsibilities. Boards are expected to incorporate cyber risk into business decision-making processes and consider its potential impact on operations, supply chains, compliance, and business continuity.

Accountability involves more than approving policies. Leadership teams must ensure that cybersecurity risks are actively governed and that appropriate measures are in place to strengthen resilience across the organization. These expectations are central to evolving discussions around NIS2 board liability and CEO personal liability.

DIVIDER

Executive cybersecurity training requirements

NIS2 introduces expectations around executive cybersecurity knowledge. The directive recognizes that effective oversight requires more than periodic security updates. Management bodies are expected to undertake cybersecurity training and promote a culture of cybersecurity awareness throughout their organizations. Boards and senior leaders must possess sufficient understanding of cyber risks to make informed governance decisions.

Directors are not expected to become cybersecurity experts, but they should understand how cyber threats could affect business operations, financial performance, regulatory obligations, and customer trust. Developing this level of cyber literacy helps leadership teams ask better questions, challenge assumptions, and evaluate whether security programs align with business priorities.

Executive cybersecurity education helps boards meet their oversight responsibilities under NIS2 without requiring directors to become security practitioners.

DIVIDER

Why incident reporting creates new executive responsibilities

NIS2 strengthens incident reporting expectations and places greater emphasis on timely communication during major cybersecurity events. While security teams remain responsible for incident detection and response, leadership must ensure that reporting processes, escalation procedures, and decision-making frameworks are in place before an incident occurs.

Under the directive, organizations may need to provide an early warning notification shortly after becoming aware of an incident and submit additional reports as more information becomes available. NIS2 24-hour incident reporting requirements reinforce the need for well-defined escalation and notification procedures.

Organizations may have limited time to assess the scope of an incident, coordinate stakeholders, and prepare initial regulatory notifications. These requirements are intended to improve situational awareness, support coordinated responses, and help authorities assess potential impacts across sectors and supply chains.

Meeting NIS2 reporting requirements depends on clearly defined escalation paths that ensure critical information reaches executive leadership, legal teams, communications teams, and regulatory contacts. Effective reporting depends on coordination across the organization and a shared understanding of roles and responsibilities during a cyber event.

Leaders must have sufficient visibility into incidents to evaluate business impacts, support response efforts, and make informed decisions regarding operational continuity, regulatory communications, and stakeholder engagement. Incident reporting is no longer solely an operational concern but a governance responsibility that requires active executive involvement.

DIVIDER

Cyber incidents are now board-level events

Major cyber incidents can affect far more than technology systems. Regulatory investigations, operational disruptions, financial losses, and reputational damage can emerge from a single event, making executive oversight essential during incident response and recovery activities.

Boards and executive teams are expected to understand the potential business impact of cyber incidents and participate in critical decision-making when major incidents occur. This may include evaluating business continuity risks, approving response strategies, coordinating stakeholder communications, and overseeing recovery efforts designed to restore operations and strengthen resilience.

DIVIDER

The 10 mandatory cybersecurity measures under NIS2

NIS2 establishes 10 cybersecurity risk management measures that organizations subject to the directive must implement:

  1. Risk management
  2. Incident handling
  3. Business continuity
  4. Crisis management
  5. Supply chain security
  6. Secure development practices
  7. Vulnerability management
  8. Cyber hygiene
  9. Identity and access controls
  10. Communications security

While many of these requirements involve technical controls and operational processes, boards and executive teams should view them primarily through a governance and risk management lens. The objective is not for leadership to manage security operations directly, but to ensure that safeguards, oversight mechanisms, and accountability structures are in place across the organization.

Many of these obligations apply to operational technology, IoT devices, cloud services, and interconnected digital environments, not just traditional IT systems. As digital ecosystems become more interconnected, weaknesses in one area can quickly affect business operations and supply chains.

Supply chain security is a key focus under NIS2. Organizations must assess and manage cybersecurity risks associated with vendors, service providers, software suppliers, and other third parties that support business operations.

These measures are designed to support long-term operational resilience rather than simple regulatory compliance. Effective governance requires ongoing visibility into cyber risks and confidence that incident response, business continuity, and recovery capabilities can support the organization during periods of disruption.

DIVIDER

NIS2 compliance in Sweden

Sweden has implemented the NIS2 Directive through its Cybersecurity Act, strengthening security requirements for organizations that provide essential and important services. The legislation introduces enhanced requirements around risk management, incident reporting, executive accountability, and operational resilience while aligning Sweden’s cybersecurity framework with EU cybersecurity objectives.

Organizations pursuing NIS2 compliance initiatives in Sweden should be aware that the framework emphasizes governance, management oversight, and active cybersecurity risk management.

The Swedish Civil Contingencies Agency (MSB), known as Myndigheten för samhällsskydd och beredskap, plays a key role in supporting NIS2 implementation. MSB provides guidance, maintains national processes, and coordinates implementation activities across sectors. Organizations should monitor evolving MSB NIS2 guidelines and sector-specific requirements issued by relevant authorities to ensure compliance obligations are properly addressed.

Oversight is distributed across multiple supervisory authorities, with organizations potentially subject to both national coordination and sector-specific supervision depending on their activities and classification under the legislation.

DIVIDER

What sectors are covered under NIS2 in Sweden?

The directive applies to sectors that provide services critical to economic stability, public safety, and societal resilience.

Key sectors covered under NIS2 in Sweden include:

• Energy
• Transportation
• Healthcare
• Banking and financial services
• Water and wastewater
• Digital infrastructure
• Telecommunications and electronic communications
• Manufacturing
• Public administration

Organizations subject to NIS2 face enhanced requirements around cybersecurity governance, incident reporting, supply chain risk management, and operational resilience. These obligations support the directive’s goal of strengthening the security and reliability of services that underpin economic stability and public well-being across Sweden and the EU.

DIVIDER

How managed security services can support NIS2 compliance

Meeting NIS2 requirements can be challenging for organizations that must balance cybersecurity, regulatory obligations, operational resilience, and resource constraints. External security providers can help strengthen cybersecurity programs by providing additional expertise, operational support, and visibility across complex environments.

Many organizations use managed security providers to support continuous monitoring, threat detection, incident response, and security operations. These capabilities can improve visibility into emerging threats, accelerate response efforts, and strengthen resilience across cloud, IT, OT, and IoT environments while supporting supply chain security initiatives.

These providers improve visibility into security operations and support reporting and documentation requirements. Governance dashboards, reporting capabilities, and security metrics give leadership teams greater insight into risk exposure, incident activity, and program effectiveness. This visibility supports more informed decision-making while helping organizations track progress toward cybersecurity and compliance objectives.

They also contribute to security operations maturity by providing specialized expertise, established processes, and advanced technologies that may be difficult to sustain internally, particularly for organizations facing cybersecurity skills shortages or resource constraints.

However, outsourcing security operations does not transfer responsibility for governance and oversight. While external providers can support monitoring, incident management, compliance efforts, and reporting, NIS2 management accountability requirements remain the responsibility of executive leadership and management bodies.

The most effective approach combines strong executive governance with operational support from trusted security partners to strengthen cyber resilience and support long-term compliance objectives.

DIVIDER

Final thoughts: Cybersecurity starts in the boardroom

NIS2 represents more than a compliance mandate. It formalizes cybersecurity as a leadership responsibility and reinforces the expectation that cyber risk be governed at the highest levels of the organization.

As NIS2 implementation continues, organizations should view cybersecurity not simply as a compliance obligation, but as a business priority that supports resilience, trust, and long-term performance.

Preparing for NIS2 requires strong governance, clear accountability, and continuous visibility into cyber risk. Learn how CyberProof’s managed security services help organizations strengthen cyber resilience, improve security operations, enhance regulatory readiness, and support effective threat detection and incident response.

DIVIDER

FAQs

What are CEO responsibilities under NIS2?

Under NIS2, CEOs oversee cybersecurity risk management, support security measures, and help ensure the organization can respond effectively to cyber incidents. The directive places greater emphasis on executive oversight and accountability.

Can a CEO be personally fined under NIS2?

NIS2 strengthens management accountability requirements and allows EU Member States to establish enforcement mechanisms for non-compliance. Specific penalties vary by national implementation.

How does NIS2 affect board-level accountability?

NIS2 increases board-level accountability by requiring directors to actively oversee cybersecurity risk management rather than delegating responsibility entirely to technical teams.

What are the NIS2 reporting requirements in Sweden?

Organizations subject to NIS2 must establish processes for identifying, escalating, and reporting significant cyber incidents, including early warning notifications and follow-up reporting obligations.

What is the penalty for non-compliance with NIS2?

Penalties for non-compliance with NIS2 vary by Member State and may include administrative fines, supervisory actions, and other enforcement measures depending on the nature and severity of the violation.

Do boards need cybersecurity training under NIS2?

Yes. NIS2 requires management bodies to undertake cybersecurity training and promote cybersecurity awareness throughout their organizations.

How does NIS2 differ from NIS1 for executives?

NIS2 expands sector coverage, strengthens management accountability, introduces executive cybersecurity training requirements, and increases reporting and governance obligations.

DIVIDER

Resources

Why the NIST privacy framework maturity assessment drives organizational value

The importance of bridging cybersecurity and engineering for secure innovation

Is Tech the answer? How Automation, AI, Cloud, and Cybersecurity address challenges in banking