Blogpost, Video

NIS2 and management liability: why cybersecurity is also a board-level issue

NIS2 and management liability: why cybersecurity is also a board-level issue

Key takeaways

  • Cybersecurity is no longer solely the responsibility of the IT department.Under the Belgian NIS2 Act, management bodies must approve cybersecurity risk-management measures and oversee their implementation.
  • That responsibility cannot be fully delegated.A CISO, IT department or external service provider may play an important operational role, but the management body retains its own legal responsibility.
  • Training is mandatory.Members of management bodies must acquire sufficient knowledge and skills to identify cyber risks and assess the organisation’s risk-management measures.
  • Non-compliance can have far-reaching consequences.In addition to significant administrative fines for the organisation, the NIS2 Act provides for responsibility at management level and, for essential entities and under specific conditions, even a temporary prohibition on exercising certain managerial functions for directors.

Cybersecurity is not just an IT responsibility

Cybersecurity was long regarded primarily as a technical matter. Responsibility was placed with the IT department, the Chief Information Security Officer (CISO) or an external cybersecurity service provider.

The NIS2 Act makes clear that this approach is no longer sufficient.

For essential and important entities, Article 31 of the Belgian NIS2 Act expressly imposes obligations on management bodies. They must approve the measures for managing cybersecurity risks, oversee their implementation and bear responsibility where the entity fails to comply with its obligations relating to those measures.

Cybersecurity therefore also becomes a matter of corporate governance.

Responsibility cannot be fully delegated

This does not mean that directors must concern themselves with the day-to-day technical implementation of cybersecurity measures. Operational responsibility may, of course, be entrusted to specialised staff. A CISO, IT team or external service provider may carry out risk assessments, implement security measures and follow up on incidents.

However, the management body (and the directors that form part of it) cannot fully outsource its own legal role. It must remain sufficiently involved to assess the proposed measures, approve them and oversee their effective implementation.

In practice, this means that the management body should, among other things, have visibility over the organisation’s main cyber risks, the measures taken to address those risks and the manner in which their implementation is monitored.

Cybersecurity training for management bodies is mandatory

To enable management bodies to exercise that responsibility in an informed manner, the NIS2 Act also expressly provides for a training obligation.

Members of the management bodies of essential and important entities must undergo training so that they acquire sufficient knowledge and skills to identify cyber risks. This training should also allow them to better assess cybersecurity risk-management practices and their impact on the organisation’s services.

Directors are therefore not expected to become cybersecurity experts. They must, however, have sufficient knowledge to make informed decisions and exercise effective oversight.

What are the consequences of non-compliance?

The potential consequences of non-compliance are significant.

Where an essential entity fails to comply with its obligations relating to cybersecurity measures or incident reporting, the Belgian NIS2 Act provides for an administrative fine ranging from EUR 500 to EUR 10 million or 2% of the total worldwide annual turnover of the preceding financial year, whichever amount is higher.

For important entities, the fine may range from EUR 500 to EUR 7 million or 1.4% of total worldwide annual turnover, again whichever amount is higher. These administrative fines are imposed on the entity concerned.

The Belgian NIS2 Act also makes clear that responsibility does not lie solely with the organisation as a legal person. Article 31 places responsibility on management bodies for infringements of the obligations relating to cybersecurity measures. Article 61 further provides that certain natural persons who are responsible for or act as the legal representative of an essential or important entity are responsible for failures in their duty to oversee compliance with the Act.

This does not mean, however, that every cyber incident automatically gives rise to personal liability on the part of a director. NIS2 does make clear that cybersecurity cannot simply be passed on to the IT department without sufficient involvement and oversight at management level.

Can a director be temporarily removed from their role?

For essential entities, Article 60 of the Belgian NIS2 Act also provides for a particularly far-reaching enforcement measure.

Where the measures requested by the competent authority are not taken within the imposed deadline, a natural person exercising managerial responsibilities at the level of chief executive officer (CEO) or legal representative may be temporarily prohibited from exercising managerial responsibilities within the entity concerned.

From IT risk to governance responsibility

The message of NIS2 is clear: cybersecurity can no longer be organised exclusively within the IT department.

Management bodies must be able to demonstrate that they have sufficient visibility over the organisation’s cyber risks, have approved appropriate measures, monitor their implementation and possess sufficient knowledge to effectively exercise that responsibility.

Cybersecurity is therefore not only a technical risk, but also a governance and management responsibility.

Organisations that structurally embed cybersecurity into their decision-making, reporting and training of management body members are therefore better placed not only to manage cyber risks, but also to demonstrate compliance with their obligations under NIS2.

Share this:

Written by

Marie Manhaeve

Marie Manhaeve

Bernd Fiten

Bernd Fiten

Hi! How can we help?

In need of internal privacy help or an external DPO? Reach out and we’ll look for the best solution together with you.

  • Solutions
  • Expertise
  • Knowledge
  • Careers
  • About