For years, cyber security in a company was seen as a technical expense. Somewhere in the IT department’s budget, next to software licenses and new laptops, there was a line item for “firewall” or “antivirus.” It was a technical problem, delegated to IT specialists, and management was mainly interested in it when something stopped working or when the hardware budget seemed too high. That era has just come to an end, and the change is fundamental.
The amendment to the National Cyber Security System (NSC) Act, implementing the EU’s NIS2 directive, is not just another technical update. It’s a revolution in business risk management, shifting the burden of responsibility directly onto the shoulders of management. The new regulations explicitly state that it is the company’s “management” that must oversee the implementation of security measures and can face personal, severe financial consequences for negligence. It’s a change that irreversibly shifts the decision-making process and, crucially, the budget, from the IT level to the top management level.
Shortcuts
- What exactly is the NIS2 directive and who is affected by the new KSC law?
- What is the revolution in accountability that KSC/NIS2 introduces?
- What specific financial penalties do board members face for negligence?
- Does the board now have to undergo specialized training?
- Why has cyber security ceased to be a problem only for the IT department?
- How does KSC/NIS2 change the approach to risk analysis in an organization?
- What do “appropriate and proportionate” technical measures mean in practice?
- What new procedural requirements (policies, plans) fall on the company?
- What is supply chain risk management (SCRM) in the context of NIS2?
- Why is the 24-hour incident reporting requirement an operational revolution?
- How can the board effectively oversee KSC/NIS2 compliance?
- How to turn a regulatory obligation into a strategic business advantage?
What exactly is the NIS2 directive and who is affected by the new KSC law?
The NIS2 (Network and Information Systems 2) Directive is an EU law that aims to raise and standardize the level of cyber security in all member countries. It replaces the previous NIS Directive of 2016, significantly expanding its scope and tightening its requirements. In Poland, the NIS2 Directive is being implemented through an amendment to the national law on the National Cyber Security System (KSC).
The key change is a drastic expansion of the number of entities that will be regulated. Until now, the KSC Law mainly applied to operators of key services (such as energy or transportation). The new legislation introduces two categories: “key entities” and “important entities.” This change means that thousands of new companies in sectors such as manufacturing, waste management, postal services, food processing or digital service providers will be subject to regulation.
For management, this means that even if the company has not been subject to any cybersecurity regulations so far, it is very likely that once the new KSC law comes into force, it will be on the list of entities required to implement stringent measures. Ignoring this fact is not an option - it is now a legal obligation.
📚 Read the complete guide: NIS2: Kompletny przewodnik po dyrektywie NIS2 - obowiązki, kary, terminy
What is the revolution in accountability that KSC/NIS2 introduces?
The revolution in question is the direct designation of governing bodies (board of directors, management) as those personally responsible for overseeing cyber security. This is a fundamental change from the previous model, where responsibility was usually diluted and rested with the organization as a whole or was delegated to the level of IT directors.
The new KSC law clearly states that it is the board of directors that must approve security measures and actively supervise their implementation. This puts an end to viewing cyber security as an “IT problem.” It is becoming an integral part of business risk management, on par with financial, operational or market risks.
In practice, this means that a board member will not be able to excuse technical ignorance or trust in the IT department. The regulations explicitly require executives to understand the risks and take appropriate countermeasures. It is this change that moves budgets and decisions from the server room to the boardroom.
What specific financial penalties do board members face for negligence?
This is the most tangible evidence of the change. The new legislation introduces severe sanctions not only for the company, but also directly for the “key/important entity manager” - that is, in practice, the chairman or members of the board of directors. The law provides for severe financial penalties for failure to fulfill supervisory duties.
The bill explicitly mentions penalties of up to 600% of the average monthly salary for the head of the entity if violations are found. Crucially, the penalty is not imposed for the mere fact that a cyberattack occurred - because that can never be 100% eliminated. It is imposed for a lack of due diligence, i.e. for ignoring the obligation to analyze risks, failing to approve appropriate policies or not allocating adequate resources for security.
Financial risk thus becomes personal. It is no longer just a risk to the company’s budget, but a potential serious burden on the manager’s private wealth. This is an argument that completely changes the priorities and importance of the topic of cyber security in C-level discussions.
Does the board now have to undergo specialized training?
Yes, and this is one of the most direct duties imposed on executives. The legislator made a logical assumption: if the board is to oversee something, it must understand it. That’s why the new regulations require governing bodies to receive specialized training in cyber security.
The goal of these trainings is not to make CEOs into firewall configuration experts. The goal is to ensure that they understand the nature of today’s threats, can assess the business risks posed by them, and know their new legal responsibilities. It is these trainings that are meant to build a bridge between the technical world of IT and the business world of management.
For companies like nFlo, this is a key entry point. A strategy workshop for the board is no longer just a “nice-to-have,” but the implementation of a specific requirement of the law. It is the first step so that the board can make informed decisions going forward and protect both the company and itself.
Why has cyber security ceased to be a problem only for the IT department?
Cyber security is no longer an IT problem because its failure is no longer an IT problem. A modern cyber attack, such as a ransomware attack, is not a minor technical glitch. It’s an existential crisis for business that halts production, blocks logistics, prevents customer service and leads to the leakage of sensitive data . It’s a problem that directly hits operational continuity.
The new KSC/NIS2 legislation fully understands this. Therefore, instead of rigid, technical checklists, the law emphasizes a risk-based approach. It requires the implementation of “appropriate and proportionate” measures, and that risk is inherent in business processes.
The IT department, operating in isolation, is not in a position to independently assess which business process is critical and what is an acceptable level of risk for the entire organization. Such decisions are the domain of management. This is why the entire process must start with a risk analysis at the business level, and only then be translated into specific technical solutions.
How does KSC/NIS2 change the approach to risk analysis in an organization?
New law makes systematic risk analysis mandatory. The era of intuitive security management is coming to an end. The regulations require entities to regularly estimate and manage incident risks in a documented manner.
The approach promoted by NIS2 is in line with international standards such as ISO 27005. The process must include inventorying key assets (data, systems, processes), identifying threats and vulnerabilities, and assessing the potential business impact of an incident. It is this impact assessment that is crucial.
For many companies, this means having to build an entire risk management process from scratch. This is no longer a task that can be outsourced to a single IT professional. It requires the establishment of a team, the implementation of a methodology and tools, and above all - the involvement of the business in identifying what is truly critical. The result of this analysis becomes the foundation for all further activities - from technology purchase to the creation of procedures.
What do “appropriate and proportionate” technical measures mean in practice?
This is a key phrase that appears in the directive. It signifies a move away from one-size-fits-all solutions to “tailor-made” security that is directly linked to the results of a risk analysis. It is up to management, based on recommendations, to decide what is “appropriate” for its organization.
If the risk analysis (which we discussed earlier) shows a high risk of data loss, the “appropriate” measure will be to implement encryption and backup systems. If the key risk is unauthorized access to critical systems, the “proportionate” measure will be the implementation of multi-factor authentication (MFA).
For manufacturing companies (OT sector), where the risk is to stop a production line, the “appropriate” measure will be network segmentation to isolate industrial systems from the rest of the company. The law does not give a ready-made shopping list; it gives management the responsibility to make a rational choice of measures appropriate to the identified risks.
What new procedural requirements (policies, plans) fall on the company?
Technology is only one pillar. KSC/NIS2 places great emphasis on procedures and documentation, that is, a complete Information Security Management System (ISMS). Merely buying the most expensive equipment will not ensure compliance if it is not part of a well-thought-out system.
Every organization will have to develop and implement a whole suite of documents. We’re talking about fundamental policies such as incident management procedures (who reports what and to whom), business continuity plans (BCPs) (what do we do when systems go down) and supply chain security policies.
For the board of directors, this means formally approving these documents and, more importantly, providing the resources to implement and test them. Having a business continuity plan that has never been tested is tantamount to not having one, from the perspective of the law. This is another organizational and management challenge.
What is supply chain risk management (SCRM) in the context of NIS2?
This is one of the most important innovations and also one of the biggest challenges. KSC/NIS2 clearly states that a company’s responsibility does not end at its own door. Organizations are required to manage the risks associated with their IT and technology service providers (the so-called ICT supply chain).
In practice, this means that a company needs to assess the security level of its key partners - a software provider, hosting company, third-party IT service or cloud service provider. Why? Because an attack on a poorly secured provider is one of the most common ways to breach a large company’s security today.
Management must therefore make sure that supplier evaluation policies are in place. This can mean conducting security audits of partners, renegotiating contracts and writing specific security requirements into them, and in extreme cases, changing suppliers to one that meets exacting standards.
Why is the 24-hour incident reporting requirement an operational revolution?
If there’s one KSC/NIS2 provision that should keep boards up at night, it’s this one. The new regulations introduce strict deadlines for reporting serious security incidents. We’re talking about an initial notification sent to the relevant authorities (CSIRT) even within 24 hours of the discovery of an incident.
This is a gigantic operational challenge. Ask yourself: is your company capable within 24 hours - whether it’s a Tuesday at noon or a Saturday at three in the morning - of not only detecting an attack, but also confirming it, classifying its severity and preparing a formal notification?
For most companies, the answer is “no.” In-house IT departments rarely work 24/7/365, and this one requirement in practice necessitates having constant security monitoring and the ability to respond immediately. For many companies, the only viable and cost-effective solution will be to use external Security Operations Center (SOC) services to provide such monitoring.
How can the board effectively oversee KSC/NIS2 compliance?
Surveillance as defined by the new regulations means proactive action, not passively waiting for reports. The first step to effective supervision is to get the full picture. Management cannot manage risks it does not understand or the scale of which it does not know.
A fundamental action is to conduct a KSC/NIS2 compliance audit. This is a diagnosis that will show where the company is, what the key gaps are (in technology, procedures, awareness) and what areas of risk need immediate attention. Such an audit provides management with a report with recommendations, which becomes a roadmap to compliance.
The second step is to establish clear organizational governance. Who in the company is responsible for coordinating activities? What are the channels for reporting to the board? How often are risks reassessed? Effective oversight requires a partner who can combine strategic/legal (GRC) with technical (IT/OT) and operational (SOC) competencies.
How to turn a regulatory obligation into a strategic business advantage?
At first glance, KSC/NIS2 looks like another costly regulatory obligation. However, a strategically thinking management can turn this necessity into a real competitive advantage. In a world where everyone is subject to the same regulations, those who implement them smarter and faster win.
First, KSC/NIS2 compliance becomes a sales argument. Remember supply chain requirements - your customers will also need to audit their suppliers. Having documented, audited NIS2 compliance makes your company a trusted and preferred partner for large, regulated customers.
Second, it is an investment in business resilience (resilience). The process of implementing NIS2 forces you to organize your processes, prepare business continuity plans and implement monitoring. All of this simply makes the company better prepared for any crisis - not just a cyberattack, but also equipment failure or human error. It’s an investment in operational continuity, which is the foundation of a stable business.
Key Findings for Management (KSC/NIS2): Summary Box
- Risk is Personal: From now on, the board of directors (management) is personally responsible for overseeing cyber security. Negligence will result in severe financial penalties imposed on managers (up to 600% of salary).
- It’s Not an IT Problem: KSC/NIS2 is a strategic business risk. Security decisions and budget irreversibly move to the C-level. * Required Action Immediately: The law requires management to receive specialized training and implement mandatory, documented risk analysis. * Key Challenges: The biggest challenges are ensuring the security of the supply chain (IT vendors) and meeting the stringent 24-hour incident reporting requirement , which in practice forces a 24/7 SOC capability. * First Step is Diagnosis: Effective management of this risk must begin with a gap audit and strategic workshop for the board to understand the full scope of responsibilities and plan actions.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
- Ransomware — Ransomware is a type of malicious software (malware) that blocks access to a…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
Learn More
Explore related articles in our knowledge base:
- KSC NIS2 and cyber insurance: How compliance with the act becomes key to lowering the cost of risk.
- KSC NIS2 and the human firewall: How must a CISO build an ongoing security culture program?
- National Security and Cyber Resilience - How will PLN 20 billion from the NIP change Polish defense and implement NIS2?
- Why is KSC NIS2 fundamentally changing the rules of the game in OT/ICS security?
- Blockchain in cyber security: Applications and benefits for companies
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Related topics
See also:
