The End of the Corporate Shield
For years, the standard complaint about cybersecurity at the board level was that executives did not take it seriously enough because they did not personally face consequences when things went wrong. The company paid the fine. The company paid the lawyers. The company settled with affected customers. The individual who approved the insufficient budget and signed off on the inadequate risk framework walked away.
Germany just changed that.
Personal Liability Under the BSI Act
Germany’s implementation of the EU’s NIS2 Directive, which came into force in early 2026 with a registration deadline of April 2026 for in-scope organisations, introduces personal liability for members of management bodies under Section 38 of the BSI Act.
Fines for cybersecurity failures are structured by entity tier:
- Particularly Important Entities: Covering sectors like energy, banking, health, and digital infrastructure. Fines reach up to 10 million euros or 2% of global annual turnover.
- Important Entities: Fines reach up to 7 million euros or 1.4% of global turnover.
Those monetary fines apply to the organisation. The personal liability provision, however, applies directly to the individuals who approved the cybersecurity risk management measures and oversaw their implementation. A board member who approved a security budget that demonstrably failed to meet the requirements of the directive is not shielded by the corporate entity. The law now looks past the company and directly at the person who signed the decision.
This is the most significant shift in corporate cybersecurity governance in a generation, and most boards outside Germany have not yet registered what it means.
The European Context & 2026 Amendments
The NIS2 Directive itself covers 18 critical sectors across the EU and applies to organisations operating in the European single market, regardless of where they are headquartered. It requires management bodies to approve their entity’s cybersecurity risk management measures, oversee their implementation, and explicitly states that management bodies can be held personally liable for non-compliance.
Germany is the first major EU economy to implement this provision with full legal force, while other member states are in various stages of transposition and enforcement.
On January 20, 2026, the European Commission proposed targeted amendments to NIS2 designed to:
- Simplify compliance for approximately 28,700 companies, including a newly introduced “small mid-cap” category.
- Introduce a unified approach to ransomware reporting.
- Establish certification-based compliance pathways.
Full adoption of these amendments is expected in late 2026 or 2027. Meanwhile, the existing directive is already in force, and Germany is actively enforcing it.
The New Standard for Boardroom Governance
The practical consequence for any organisation with operations, customers, or digital services in the EU is that cybersecurity governance is no longer a delegation item. A board that delegates cybersecurity to the CISO and checks in quarterly is now operating in a regime where that delegation does not transfer the liability. The board approved the framework. The board owns the consequences.
What this actually requires is not dramatically different from what good governance looked like before personal liability entered the picture:
- Deep Comprehension: Boards must fully understand the cybersecurity risk management programmes they are signing off on.
- Provable Compliance: There must be documented evidence that the approved programme meets the specific technical and organisational requirements of the applicable regulation.
- Active Oversight: Management requires documented, continuous oversight of implementation, rather than just a quarterly update slide.
The Global Direction of Travel
The reason this matters beyond Europe is that global organisations do not get to apply different governance standards to their EU operations and their domestic ones. A board sitting in Singapore, Mumbai, New York, or Riyadh that oversees a company with EU operations is now operating under a legal framework where their personal exposure depends on decisions they are making right now.
NIS2 is not the only regulation moving in this direction. Global regulatory frameworks are consistently evolving to ensure accountability follows decisions:
- The United States: The SEC’s cyber disclosure rules introduced material incident reporting obligations that place cybersecurity explicitly in the domain of board-level governance.
- Australia: Proposed reforms to the Security of Critical Infrastructure Act are expanding mandatory cyber standards across more sectors.
Regulators are done treating cybersecurity as an isolated IT department concern. They are placing it squarely at the level of corporate governance.
Germany was first. It will not be last.

Leave a Reply