Back to Blog
LegalTech & IA

NIS2 Just Got Real: Why Your Board Can’t Hide from Cyber Security Anymore

NakedPact Editorial Committee
Reviewer: Carmelo G.
Comitato Editoriale NakedPact
July 23, 2026
10 min read
NIS2 Just Got Real: Why Your Board Can’t Hide from Cyber Security Anymore

Is Your Board Ready for the NIS2 Hot Seat?

If GDPR felt like a speeding ticket, NIS2 is a criminal investigation. Italy's Agency for National Cybersecurity (ACN) just dropped an updated FAQ that makes one thing crystal clear: top management can no longer delegate cyber risk to the IT department and sleep soundly. The new rules impose personal liability on directors and executives for non-compliance – and ignorance isn't a defense.

Let's cut the legalese: as of the NIS2 transposition into Italian law, your board members are personally on the hook for failing to ensure adequate cybersecurity measures. This isn't a theoretical risk – ACN's FAQ spells out specific duties, enforcement actions, and fines that can go up to €10 million or 2% of global turnover.

Top management must approve cybersecurity policies, ensure they are implemented, allocate sufficient resources, and undergo regular training. They can be held personally liable for breaches caused by negligence, including fines and potential disqualification from managerial roles.

ACN's FAQ: The Devil in the Details

The updated FAQ clarifies several grey areas. First, it confirms that 'top management' includes both formal directors and de facto decision-makers – so no hiding behind a title. Second, it outlines a mandatory requirement for management to *actively* oversee cybersecurity risk management, not just sign off on an annual report.

But here's where it gets juicy: the FAQ states that even if a company outsources its cybersecurity operations, the board remains ultimately responsible. That's like hiring a chef and then blaming them if you get food poisoning – the restaurant owner still goes to jail.

If you think this is all doom and gloom, think again. ACN also provides practical compliance paths: companies can follow the 'Cybersecurity Framework' from the national scheme, which aligns with international standards like ISO 27001. The key is documentation – keep a clear record of decisions, risk assessments, and training sessions. If the regulator comes knocking, you'll need to show you did your homework, not just passed the test.

But Wait, There's More: Enforcement and Penalties

ACN made it clear that enforcement won't be a paper tiger. The FAQ outlines a graduated approach: from warnings and corrective orders for minor infractions to large fines and public naming-and-shaming for serious or repeated violations. In addition, directors can face personal fines of up to €1 million and be banned from holding management positions for up to two years.

Humor break: ever read your company's terms and conditions? Think of NIS2 compliance like that – only this time, reading them is more interesting than cleaning grout with a toothbrush, because your freedom and wallet depend on it.

What Should Your Board Do Now?

First, stop treating cybersecurity as a checkbox exercise. Read the full NIS2 directive (yes, really) and the updated ACN FAQ. Second, conduct a gap analysis – identify where your current posture falls short. Third, assign a specific board member to lead cybersecurity oversight, but ensure collective accountability. Finally, schedule regular training and tabletop exercises. The clock is ticking: Italy's transposition deadline is October 2024, and ACN is already ramping up inspections.

If this sounds overwhelming, remember: NIS2 is a wake-up call, not a death sentence. Use it as an opportunity to build resilience, protect your reputation, and maybe sleep a little better at night – if you do the work.

FAQ

Is personal liability of top management unlimited under NIS2?

No, personal liability is limited to cases of intent or gross negligence. However, the burden of proof is on the company to show that management took all reasonable steps to comply. ACN's FAQ emphasizes that simply delegating tasks without oversight constitutes gross negligence.

Do non-EU companies with Italian subsidiaries fall under NIS2?

Yes, if the subsidiary provides essential services in Italy (e.g., energy, transport, healthcare) or meets the size thresholds. The FAQ clarifies that foreign ownership does not exempt the Italian legal entity from compliance, and its top management must reside or be represented in the EU.

Can a company delegate all NIS2 compliance to a CISO?

No. While a CISO can manage day-to-day operations, the board retains ultimate responsibility. The FAQ requires top management to approve and periodically review the cybersecurity strategy, ensure adequate resources, and actively monitor implementation. Written delegation alone is insufficient.

Board NIS2 Readiness Checklist

  • Approved cybersecurity policy with board vote
  • Documented risk assessment for each critical service
  • Allocated dedicated budget for NIS2 measures
  • Assigned board member for cyber oversight
  • Conducted at least 1 tabletop exercise in last 12 months
  • Verified insurance coverage for director liability
NakedPact Logo

NakedPact Editorial Committee

Article created by the NakedPact editorial team. Our mission is to analyze, simplify, and expose unfair terms and hidden risks in everyday contracts to protect citizens and consumers.

Do you own a website?

Do you own a website?

Want to communicate your data processing transparency to your users? Dynamically use our badge and showcase your platform's compliance.

🛡️ Protect your rights with one click

Don't risk signing abusive clauses. Install the free NakedPact extension for Chrome or Firefox and instantly analyze any contract on the web.

Don't trust, verify.

Now that you know the risks, don't sign blindly. Upload your contract to NakedPact and let AI find the hidden clauses for you. It's 100% free.

Analyze Your Contract Now

Rispettiamo la tua privacy

Usiamo i cookie per migliorare la tua esperienza e personalizzare gli annunci. Scopri di più.

NakedPact Logo

Estensione Chrome

Analizza i contratti e i Termini di Servizio direttamente sul tuo browser con l'estensione NakedPact.