NIS2: what every executive needs to know (obligations, penalties and action plan)

avril 2, 2025
Gouvernance cybersécurité COMEX

The European NIS2 directive makes you personally accountable. Here is what you need to understand, decide and put in place.

NIS2: why this is your problem as an executive

The NIS2 directive (Network and Information Security 2) came into force on 17 October 2024 across the European Union. It replaces NIS1 and considerably widens the scope of organisations concerned: from a few hundred entities to more than 100,000 organisations in France alone. Since that date, the organisations concerned must bring their cyber governance into compliance. As a result, executives are directly accountable.

What fundamentally changes with NIS2 is the personal accountability of company leaders. Members of executive committees and management boards can now be held personally liable where their organisation fails to meet its cybersecurity obligations.

Who is covered by NIS2?

NIS2 distinguishes two categories of entity. This distinction determines whether your organisation is subject to the strictest obligations, and the penalties differ accordingly.

Essential entities Important entities
Energy, transport, banking, health, water, digital infrastructure Postal services, waste management, chemicals, food, manufacturing
Over 250 employees or turnover above €50m Over 50 employees or turnover above €10m
Penalties up to €10m or 2 % of global turnover Penalties up to €7m or 1.4 % of global turnover

The 5 key NIS2 obligations for your organisation

  1. Cyber governance at board level: the board must approve risk management measures and monitor their implementation.
  2. Risk management: a documented risk analysis, a formal security policy and proportionate technical measures.
  3. Business continuity: a tested continuity plan, backup procedures and operational crisis management.
  4. Supply chain security: assessment of the security of your critical suppliers and service providers.
  5. Incident notification: reporting to the national authority within 24 hours for significant incidents, with a full report within 72 hours.

What NIS2 changes in practice for your board

Before NIS2, cybersecurity was often delegated to the CIO or the CISO. With NIS2, that is over. The directive requires governing bodies to:

  • approve and oversee the security policy
  • undertake specific cybersecurity training
  • be liable in the event of negligence
  • embed cybersecurity in strategic decisions

An executive who ignores their NIS2 obligations is exposed to personal penalties, fines for their organisation and a challenge to their civil and criminal liability.

Ignoring NIS2 is no longer an option. Executives need to take ownership of the subject personally and without delay.

A 7-step NIS2 action plan for executives

  1. Check whether you are covered: sector, size, criticality of your services.
  2. Appoint a NIS2 owner: CISO, DPO or external consultant with a clear mandate.
  3. Map your critical assets: systems, data and providers essential to your business.
  4. Assess your maturity: a rapid audit to identify gaps against NIS2 requirements.
  5. Define a prioritised roadmap: actions at 30, 60 and 90 days with an allocated budget.
  6. Train your board: an awareness session on the stakes and responsibilities.
  7. Test your continuity plan: a crisis simulation to validate your operational responses.

Key takeaways

  • More than 100,000 organisations concerned in France
  • Personal accountability of company leaders
  • Penalties up to €10m or 2 % of global turnover
  • Mandatory notification within 24 hours
  • Mandatory board-level training

Are you covered by NIS2?

The CyberMasterClass Executives gives you, in 90 minutes, a clear view of your obligations and an action plan you can use immediately.

Publications

Get the next publications.

One analysis per publication on cyber governance, resilience and compliance.

Take action in 90 minutes

Our CyberMasterClasses train executives, sales teams and HR on cyber issues, without technical jargon.

See the masterclasses