NIS2: what every executive needs to know (obligations, penalties and action plan)
The European NIS2 directive makes you personally accountable. Here is what you need to understand, decide and put in place.
NIS2: why this is your problem as an executive
The NIS2 directive (Network and Information Security 2) came into force on 17 October 2024 across the European Union. It replaces NIS1 and considerably widens the scope of organisations concerned: from a few hundred entities to more than 100,000 organisations in France alone. Since that date, the organisations concerned must bring their cyber governance into compliance. As a result, executives are directly accountable.
What fundamentally changes with NIS2 is the personal accountability of company leaders. Members of executive committees and management boards can now be held personally liable where their organisation fails to meet its cybersecurity obligations.
Who is covered by NIS2?
NIS2 distinguishes two categories of entity. This distinction determines whether your organisation is subject to the strictest obligations, and the penalties differ accordingly.
| Essential entities | Important entities |
|---|---|
| Energy, transport, banking, health, water, digital infrastructure | Postal services, waste management, chemicals, food, manufacturing |
| Over 250 employees or turnover above €50m | Over 50 employees or turnover above €10m |
| Penalties up to €10m or 2 % of global turnover | Penalties up to €7m or 1.4 % of global turnover |
The 5 key NIS2 obligations for your organisation
- Cyber governance at board level: the board must approve risk management measures and monitor their implementation.
- Risk management: a documented risk analysis, a formal security policy and proportionate technical measures.
- Business continuity: a tested continuity plan, backup procedures and operational crisis management.
- Supply chain security: assessment of the security of your critical suppliers and service providers.
- Incident notification: reporting to the national authority within 24 hours for significant incidents, with a full report within 72 hours.
What NIS2 changes in practice for your board
Before NIS2, cybersecurity was often delegated to the CIO or the CISO. With NIS2, that is over. The directive requires governing bodies to:
- approve and oversee the security policy
- undertake specific cybersecurity training
- be liable in the event of negligence
- embed cybersecurity in strategic decisions
An executive who ignores their NIS2 obligations is exposed to personal penalties, fines for their organisation and a challenge to their civil and criminal liability.
Ignoring NIS2 is no longer an option. Executives need to take ownership of the subject personally and without delay.
A 7-step NIS2 action plan for executives
- Check whether you are covered: sector, size, criticality of your services.
- Appoint a NIS2 owner: CISO, DPO or external consultant with a clear mandate.
- Map your critical assets: systems, data and providers essential to your business.
- Assess your maturity: a rapid audit to identify gaps against NIS2 requirements.
- Define a prioritised roadmap: actions at 30, 60 and 90 days with an allocated budget.
- Train your board: an awareness session on the stakes and responsibilities.
- Test your continuity plan: a crisis simulation to validate your operational responses.
Key takeaways
- More than 100,000 organisations concerned in France
- Personal accountability of company leaders
- Penalties up to €10m or 2 % of global turnover
- Mandatory notification within 24 hours
- Mandatory board-level training
Are you covered by NIS2?
The CyberMasterClass Executives gives you, in 90 minutes, a clear view of your obligations and an action plan you can use immediately.
Get the next publications.
One analysis per publication on cyber governance, resilience and compliance.
Take action in 90 minutes
Our CyberMasterClasses train executives, sales teams and HR on cyber issues, without technical jargon.
See the masterclasses