NIS2: Why Your Board Can't Delegate Cyber Risk (And Why That's a Good Thing)

Table of Contents
The Board's New Reality: No More Cyber Buck-Passing
Featured Snippet Bait: Under NIS2, the board of directors must personally approve cyber risk management measures, allocate adequate resources, and ensure regular audits—these duties are non-delegable.
Imagine your board chair saying, 'I’ll take care of cyber risk next quarter, after the golf tournament.' Under NIS2, that’s not just negligence—it’s illegal. The Italian Cybersecurity Agency (ACN) has published FAQ clarifying that the board’s obligations under the NIS2 Directive are deeply personal. You can’t outsource accountability.
What's Non-Delegable? More Than You Think
The ACN FAQ spells out a list of duties that sit squarely on the board's shoulders. These include approving the overall risk management framework, ensuring adequate budget for cybersecurity, and reviewing incident response plans. Sounds like a lot? It is. But NIS2 is designed to make cyber risk a board-level priority, not an IT side project.
Think of it this way: if your company's network goes down, you can't blame the intern who clicked a phishing link. The board is on the hook for creating a culture of security from the top. According to official guidance from the EUR-Lex NIS2 Directive, top management is directly liable for compliance failures.
Gone Are the Days of 'Just Comply'
In the old days, companies could slap on a cybersecurity policy and call it a day. NIS2 demands *active* engagement. The board must not only approve measures but periodically review their effectiveness. That means quarterly reports, not just a yearly nod.
One FAQ even clarifies that the board must ensure that risk management is integrated into overall corporate governance. Translation: cyber risk isn't a separate issue—it's woven into every business decision.
Practical Steps for Your Board Meeting (Without Falling Asleep)
- Start with a brief 'cyber health' update—no jargon, real numbers.
- Review the risk register: are we still comfortable with our exposure?
- Debate the budget: is it enough to secure our crown jewels?
- Ask the tough question: 'What would happen if we went dark for a week?'
And if any board member starts daydreaming about golf, remind them that NIS2 penalties include personal liability and fines up to €10 million or 2% of global turnover. That should wake them up.
From Boredom to Urgency: A Little Humor Helps
Let's be real: reading compliance documentation is about as fun as cleaning grout with a toothbrush. But NIS2 forces a shift from 'check-the-box' to 'heart-of-the-business.' That's actually good news. You get to shape your company's cyber destiny rather than react to breaches.
Still, the ACN FAQ is a lifesaver—it cuts through the legalese and tells you exactly where the buck stops. So print it out, hand it to your board, and watch the newfound interest in phishing simulations.
FAQ
What specific duties cannot be delegated under NIS2?
Approval of risk management measures, allocation of cybersecurity budget, ensuring regular audits, and oversight of incident response plans are non-delegable board responsibilities.
How often should the board review cyber risk measures per NIS2?
The ACN FAQ suggests a continuous review cycle, with formal board-level evaluation at least annually, and more frequently for high-risk changes.
What are the penalties if the board fails to comply with NIS2?
Penalties can include personal liability for directors, fines up to €10 million or 2% of annual global turnover, and potential criminal sanctions for gross negligence.
Board's NIS2 Non-Delegable Duties Checklist
- ✓Approve Cyber Risk Management FrameworkPolicy and methodology must be board-approved
- ✓Allocate Sufficient BudgetEnsure resources match actual risk exposure
- ✓Oversee Incident Response PlansReview and test at least annually
- ✓Ensure Regular AuditsIndependent audits of cybersecurity measures
- ✓Review Risk Register QuarterlyBoard-level discussion of emerging threats

NakedPact Editorial Committee
Article created by the NakedPact editorial team. Our mission is to analyze, simplify, and expose unfair terms and hidden risks in everyday contracts to protect citizens and consumers.
Sources and Legal References

Do you own a website?
Want to communicate your data processing transparency to your users? Dynamically use our badge and showcase your platform's compliance.
Recommended Readings
🛡️ Protect your rights with one click
Don't risk signing abusive clauses. Install the free NakedPact extension for Chrome or Firefox and instantly analyze any contract on the web.
Don't trust, verify.
Now that you know the risks, don't sign blindly. Upload your contract to NakedPact and let AI find the hidden clauses for you. It's 100% free.
Analyze Your Contract Now