NIS2 clearly shifts responsibility to management level:
Managing directors and board members must ensure that information security is organizationally anchored and adequately funded.
Delegation to the IT department alone is no longer sufficient – management remains liable if measures are not taken.
In concrete terms, this means
- Information security is becoming a top priority.
- Documented policies and responsibilities are needed.
- Verifiable training for management and employees is mandatory.
This responsibility is also made clear in the BSI’s training material for managing directors.


Leave A Comment