Skip to content
Knowledge base Updated: February 5, 2026

NIS2 directive in practice: What does a manufacturing plant manager need to know about the new obligations?

Until now, cyber security at your facility has been a concern of the IT department. With the NIS2 directive coming into effect, that era is over. The new law makes you, the manager in charge of operations, personally responsible for your factory's digital resilience. This isn't just another regulati

For years, as a manager in charge of manufacturing, you focused on the tangible, physical aspects of factory operations: machine efficiency, product quality, employee safety and process optimization. Cyber security, if it appeared on your radar at all, was an abstract problem from the distant world of IT, dealt with by specialists in an office building. The NIS2 directive shatters that order in a definitive way.

The new European law makes it clear: cyber security is no longer just a matter of technology, but a fundamental part of operational and strategic management. What’s more, NIS2 introduces the concept of personal liability of executives for non-compliance. This means that you, as the person who oversees and manages the production infrastructure, become directly responsible for its digital resilience.

Ignoring this fact is not an option. The consequences are not only gigantic financial penalties for the company, but also potential sanctions for managers, including being banned from holding managerial positions. Therefore, it becomes crucial to understand what these new responsibilities mean in practice. You don’t have to become a cyber security expert, but you do need to become an informed and committed leader who can manage this new type of operational risk.

Shortcuts

Why is the NIS2 directive not an “IT problem” but your new personal responsibility?

The biggest mistake that can be made in the context of NIS2 is pushing all responsibility onto the IT department. The directive was deliberately structured to shift the burden from technical departments to top management. Regulators are well aware that without involvement and support “from the top,” no security initiative has a chance of success.

Your new responsibility is not to personally configure firewalls. It is for you to ensure that your organization has the resources, processes and structures in place to effectively manage risk. You are responsible for overseeing the process, asking the tough questions, and making sure that the declarations of the technical departments have coverage in reality.

If a major incident occurs, and an investigation reveals that you ignored the security team’s requests for years to budget for key security features because “there was no money for it,” it is you, as the manager, who can be held accountable for negligence. NIS2 ends an era in which cyber security was a cost that could be cut with impunity. Today, it is an investment in compliance and your personal legal security.

📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać

Does my manufacturing facility fall under NIS2 and what are the implications?

The first step is to determine whether your organization falls under the new regulations at all. NIS2 significantly expands the list of sectors considered vital or important to the economy and society. If your facility operates in industries such as energy, transportation, health care, chemical production and distribution, food production and processing, or the manufacture of medical devices, computers or machinery, the likelihood that you fall under NIS2 is very high.

The directive divides entities into “key” and “important,” based mainly on their size and criticality. Regardless of this classification, the consequences are serious. The primary one is the need to implement a series of minimum security measures, conduct a risk analysis, secure the supply chain and implement incident reporting procedures.

The most important consequence, however, is the potential sanctions. For key players, financial penalties can be up to €10 million or 2% of total global annual turnover (whichever is higher). For important entities, it’s up to €7 million or 1.4% of turnover. What’s more, regulators gain the right to impose sanctions directly on individuals in managerial positions.

What, in practice, is your responsibility for cyber security risk management?

The NIS2 directive requires you, as a manager, to implement “appropriate and proportionate technical, operational and organizational measures” to manage risk. What does this mean in practice? This means that you must stop being a passive observer and become an active participant in the risk management process.

Your job is to ensure that a comprehensive risk analysis for OT systems is conducted at your facility. You need to ask your teams: “What are our most important production processes? What will happen if the control system for these processes is attacked? What are the potential financial and, more importantly, human safety consequences?”

Based on this analysis, you need to make sure that adequate countermeasures are implemented. You don’t need to know the technical details of each firewall, but you do need to understand what risks it mitigates. Your job is to ensure that the team has the necessary resources to implement and maintain these measures, and to regularly verify that they are effective.

How does NIS2 change the conversation about the OT security budget from “cost” to “investment in compliance”?

Until now, discussions about OT cyber security budgets have often been extremely difficult. The security department presented abstract risks, and you, as a manager, had to compare them with concrete, tangible production needs. Investing in a new SCADA system that would increase productivity often won out over investing in “some” monitoring system.

The NIS2 directive completely changes these rules. Investment in minimum legally required security measures ceases to be an optional cost and becomes a mandatory investment in compliance, just like investment in meeting environmental or occupational health and safety standards. The absence of these measures is no longer just “risk acceptance,” but is a potential violation of the law.

This is a powerful argument that you can and should use. NIS2 gives you unprecedented leverage to get the budget to solve perennial problems that you previously “didn’t have the money for.” - from asset inventory to network segmentation to building business continuity plans. An investment in security becomes an investment in the continuity of your own career.

What are your tasks when a major incident needs to be reported within 24 hours?

NIS2 introduces a very strict timeframe for incident reporting. In the case of a “major” incident, a company must send an early warning to the national CSIRT team within 24 hours of discovery. This is an extremely short timeframe, which requires having efficient and rehearsed procedures in place.

Your role as plant manager in this process is crucial. You will not personally write the report, but you must ensure that the response team has all the necessary information and support to be able to do so. In practice, this means that when the security team informs you of an incident, you must help them quickly assess its potential impact on operations, customers and security.

You need to be available, decisive and cooperative. You also need to understand that in those first 24 hours, the priority is to meet the regulatory obligation, even if all the technical details are not yet known. Your job is to create a culture where the flow of information between the technical team and decision makers is immediate and transparent.

Why are you also responsible for the cyber security of the machines you buy from now on?

One of the most far-reaching requirements of NIS2 is its emphasis on supply chain security. The directive makes it clear that your responsibility does not end with your own infrastructure. You must also manage the risks associated with the products and services you buy from third-party suppliers.

In practice, as a manager overseeing the procurement of new machines and systems, you must incorporate cyber-security criteria into the bidding and purchasing process. You can no longer choose a supplier based on price and functionality alone. You need to start asking the hard questions: “What security standards does this vendor follow? Will it provide us with a list of software components (SBOM)? What is its vulnerability response process like?”.

This means working closely with purchasing and safety to create new, safe requirements for suppliers. From now on, you too are responsible for ensuring that the new robot that enters your production floor does not turn out to be a Trojan horse.

NIS2 in a Nutshell: An Action Plan for the Plant Manager

Area of ResponsibilityKey action of the managerThe question you need to ask1. risk managementEnsure that a risk analysis is conducted for the OT and allocate budget for countermeasures.”Do we know what our most important processes are and what risks threaten them?“2 Incident ReportingSupport the response team in quickly assessing the business impact of an incident.”Do we have a procedure in place to report an incident within 24 hours?“3 Supply ChainIncorporate cybersecurity criteria into purchasing processes for new machines.”Do we verify the security of our suppliers before we sign a contract?“4 Personal ResponsibilityActively oversee the security program and document decisions made.”Can I prove to the auditors that I did my due diligence?”

What does the personal liability of the board of directors mean in practice, and what might be its consequences?

This is the most important and sobering aspect of NIS2 for executives. The directive gives national authorities the power to hold individuals in management positions accountable for violations. This means that accountability ceases to be anonymous and corporate and becomes personal.

If an audit or investigation after an incident finds that a company has been grossly negligent in its cybersecurity responsibilities, the regulator may find fault. The consequences can be twofold. First, financial - severe fines can be imposed on these individuals.

Second, and perhaps even more threatening, are non-financial sanctions. Supervisors can issue a public statement naming the individual responsible for the violation. They can also issue an order to ensure that the individual ceases the violation and does not repeat it. In extreme cases, even temporary suspension from management functions is possible. This is a risk that no manager can ignore.

Why does NIS2 require that you and your managers also receive cyber security training?

Since executives have such a heavy responsibility, they must also have the minimum necessary knowledge to carry out that responsibility effectively. That’s why the NIS2 directive explicitly requires that “members of the governing bodies of key and important entities receive training” in cyber security.

The goal of this training is not, of course, to make you a technical expert. The goal is to ensure that you are able to identify risks and evaluate cybersecurity management practices and their impact on your organization’s services. You must learn to ask the right questions of your team and understand the answers you receive.

Training for managers should focus on strategic aspects: What is the current risk landscape for our industry? How to read and understand risk analysis reports? What are the key performance indicators of a security program? What are our legal obligations? Investing in your own education is now not just a good practice, but an obligation.

How to use NIS2 as leverage to solve long-standing problems at the interface between IT and OT?

While the new responsibilities may seem overwhelming, the wise manager will see NIS2 not only as a threat, but as a tremendous opportunity. The directive is a powerful catalyst for change, giving you the arguments and tools to solve problems that may have been ignored for years in your organization.

NIS2 is the ideal lever to finally break down the historical silos between IT and OT. You can now, citing legal requirements, formally demand the creation of a joint steering committee and the development of common procedures. The “we have to do this because NIS2 requires it and we face millions of dollars in fines for doing so” argument is far more effective than any request for “better cooperation.”

Likewise, the directive is a powerful tool for justifying investments in long-needed but postponed projects: finally conducting a full inventory of resources, implementing network segmentation or creating a business continuity plan. NIS2 allows you to transform these projects from a “it would be nice to have” to a “we must have in order to be compliant” position.

Why does careful documentation of your decisions become your “insurance policy”?

In a world of regulation and personal liability, the principle of “if something isn’t documented, it didn’t happen” takes on tremendous power. In the event of an audit or incident, you will need to be able to prove that you and your company did your due diligence. Your memory and verbal assurances will not be sufficient proof.

This is why careful, continuous documentation becomes your personal “insurance policy.” All key decisions made in the area of OT cyber security must be formally documented. Minutes of steering committee meetings, formal risk analysis reports, approved policies and procedures, and records of training and exercises conducted all become evidence.

For example, if the steering committee, after analyzing the risks, made a conscious decision to accept a certain vulnerability because patching it was too risky, and appropriate compensating controls were implemented - such a documented decision-making process is the best defense against a charge of negligence. Documentation shows that you managed the risk in an informed and responsible manner.

What will the audit look like and what will the auditors want to see at your facility?

The NIS2 directive gives regulators broad inspection powers. Auditors will be able to conduct regular, as well as ad hoc (e.g., after an incident) inspections of your facility. Their purpose will be to verify that the security measures you have implemented are adequate and in compliance with legal requirements.

The audit won’t just be talking to the IT department. The auditors will want to talk to you, your engineers and operators. They will want to see not just documentation, but evidence of practical implementation. Show us your risk analysis. Show us your incident response plan and exercise reports. Show us how you manage remote access. Show us how you verify your suppliers.

Preparing for such an inspection requires a systematic approach. It’s not something that can be done at the last minute. It requires having a mature, working security management program in which all elements - from policies to technology to people awareness - are consistent with each other and documented.

What are the three most important things you, as a plant manager, need to do regarding NIS2?

Facing so much change, it’s easy to feel overwhelmed. However, your actions can be boiled down to three key fundamental steps you need to take to successfully enter the new reality.

First: Accept and take responsibility. Stop treating OT cyber security like someone else’s problem. Understand that it is now part of your job and your responsibility. Actively seek knowledge, ask questions and become a leader of this change in your organization.

Second: Build your team and break the silos. You are not in this alone. Your job is to create a formal platform (e.g., a steering committee) where your top IT, OT and security experts can work together on solutions. Your role is to be a facilitator, not a referee.

Third: Demand and allocate resources. Use NIS2 as an argument to fight for budget. You can’t take responsibility for security without the right tools, people and money. Your job is to make a clear business case to management for the necessary investments.

Is NIS2 just a regulation to “tick off” or an opportunity to build real operational resilience?

One can look at NIS2 in two ways. One can view it as another onerous bureaucratic chore - a list of tasks to “tick off” to satisfy auditors. This approach, while it may ensure minimal compliance “on paper,” will not build real security and will leave the company vulnerable to attacks.

A wise manager, however, will look at NIS2 differently - as a historic opportunity. It’s a powerful push that forces the entire industry to sort out the chaos that has built up at the interface between IT and OT over the past two decades. It’s an opportunity to finally build bridges between teams, take a full inventory, segment networks and create plans that realistically prepare the company for a crisis.

By treating NIS2 as a strategic roadmap rather than a list of penalties, you can transform your organization. You can build not only compliance, but more importantly, real, sustainable operational resilience, which in today’s world is one of the greatest competitive advantages. The choice of perspective is yours.

How can nFlo help you understand and implement NIS2 requirements in your production environment?

At nFlo, we specialize in “translating” complex regulatory requirements, such as the NIS2 directive, into practical and understandable language for managers and engineers. We understand that your job is to manage production, not to follow every paragraph of the new law. That’s why our role is to take on that burden and provide you with a clear roadmap to compliance, tailored to your company.

Our consultants will conduct a dedicated workshop for you and your team, during which we will explain which specific NIS2 requirements apply to your facility and what they mean in practice. We will conduct a gap analysis, which will show in which areas your company is already compliant and which require urgent action.

Based on this analysis, we will work with you to develop a prioritized plan of action that is realistic and grounded in your operational and budgetary realities, taking you step by step to full compliance. Our goal is not just to help you “tick off” the requirements, but to build a sustainable security program that realistically protects your business and gives you peace of mind.

What due diligence looks like on a factory floor

Personal accountability sounds abstract until it is reduced to what an inspector will actually ask to see, and in a plant that is a short list of very ordinary documents. A dated decision approving the risk treatment plan, including the risk knowingly accepted for systems that cannot be patched. A record showing security was a standing item in operational reviews rather than a one-off. Evidence that you and your managers completed the required training, not that the IT department did. And a named person holding the incident reporting duty, with the deadline beside the name.

What does not count is the list of installed equipment or a contract with an integrator — a duty can be delegated in execution but not in accountability. The cheapest way to close that gap is for the people carrying the liability to understand what they are approving before they approve it, which is the purpose of NIS2 training for management boards.

Learn key terms related to this article in our cybersecurity glossary:

  • Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
  • SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
  • Backup — Backup, also known as a backup copy or safety copy, is the process of creating…
  • Network Security — Network security is a set of practices, technologies, and strategies aimed at…
  • Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…

Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


Cybersecurity for Your Industry

Learn more about cybersecurity in your industry:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist