Skip to content
Knowledge Base

Management Board Liability under NIS2/KSC — What Exactly Leadership Is Responsible For

The amendment to the NCS Act implementing NIS2 explicitly introduces leadership liability for carrying out cybersecurity tasks. This is a breakthrough: the topic moves from the server room to the boardroom. We explain what the management board is specifically responsible for and how to reasonably limit that liability.

For years, cybersecurity was treated as an IT department problem — a technical topic, “somewhere down” the structure. The amendment to the National Cybersecurity System Act (NCS Act), implementing the NIS2 Directive and in force since 3 April 2026, puts an end to this state of affairs. It introduces liability of entities’ leadership for carrying out cybersecurity tasks.

For management boards, this is a fundamental change: digital security becomes a duty supervised at the highest level. In this article, we explain what this means in practice.

What exactly does the act say about management board liability?

The new provisions impose on entities the obligation to apply appropriate technical and organizational measures, while at the same time introducing leadership liability for carrying out these tasks. In other words: it is not an anonymous “department” that is responsible for security, but specific people managing the organization.

What exactly is the leadership responsible for?

The management board’s liability is supervisory and decision-making in nature, not executive. In practice, it covers:

  • approving risk management measures and security policies,
  • ensuring resources (budget, people, competencies) to carry out the program,
  • oversight of incident handling and reporting,
  • ensuring its own training in cybersecurity,
  • holding the organization accountable for fulfilling its obligations.

The management board does not have to configure firewalls — it has to ensure that someone competent does it, that policies exist, and that the whole thing works.

Why is this a breakthrough in the way organizations are managed?

Until now, the CISO often fought for the management board’s budget and attention. Now the roles are reversed: it is the management board that has an interest in the security program working, because liability rests on it. This change genuinely makes it easier to fund security initiatives — provided that leadership understands its role.

From when do real penalties apply?

Under the NCS Act, administrative fines for most obligations may be imposed after 3 April 2028 (two years from the amendment entering into force). This is, however, no reason for delay — the deadlines for implementing obligations run earlier (including entry into the register by 3 October 2026, and implementation of obligations by 3 April 2027). We described the full timeline in the article on the deadlines of the NCS Act/NIS2 amendment.

Does the management board have to train?

Yes. The regulations expect members of leadership to complete training that allows them to understand risks and supervise risk management measures. This is not about turning the management board into a team of technicians — it is about the ability to ask the right questions and to assess whether the security program is adequate to the risk.

How can the management board reasonably limit its liability?

The best line of defense is documented due diligence:

  1. Approved policies and a security strategy.
  2. A readiness audit (gap analysis) with a roadmap — proof that you know your state.
  3. A clear division of roles — e.g. appointing a CISO or using a vCISO.
  4. An incident handling process with reporting readiness.
  5. Evidence of oversight — minutes, decisions, reviews.

A management board that can demonstrate it consciously managed risk is in an incomparably better position than one that ignored the topic.

Where to start?

If you sit on the management board of an organization that may fall under NIS2/KSC, start with two questions: “do we fall under it?” and “what is our status?”. A KSC/NIS2 readiness audit will answer the first, and the category of entity can be determined with the help of the article on the differences between an essential and an important entity.

Check out our services

Management board liability under NIS2 is not a threat but a lever — for the first time, cybersecurity has a real owner at the highest level.

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist