
The NIS 2 Directive is not just a set of new legal obligations. Above all, it represents a shift in the way organisations think about cybersecurity. Until now, many companies have treated IT security as a technical matter, confined to the IT department. NIS 2 introduces a completely different approach – a systemic one, based on risk management and business accountability.
One of the most significant changes is the move away from treating security as solely an IT matter. Companies must now identify key assets – such as systems, data and processes – and then analyse threats and assess their impact on business continuity.
This means adopting a risk-based approach, where measures are tailored to actual threats rather than merely to formal requirements. Regular security testing, updating procedures and continuous monitoring of the IT environment are becoming increasingly important.
Cybersecurity is no longer a one-off implementation, but is becoming an ongoing process, integrated into the wider management system of the organisation and its operational resilience.
The new regulations clearly shift responsibility to board level. It is the company’s senior management that is responsible for overseeing cybersecurity, making decisions and ensuring adequate resources – both technological and organisational.
As a result, the issue of security is elevated to a strategic level and becomes part of business risk management. The board must not only approve measures, but also understand the key threats, their potential consequences and their impact on the company’s operations.
This translates into greater involvement from senior management, the need to make informed decisions, and the integration of cybersecurity into the organisation’s long-term development planning.

Many companies still treat the NIS 2 Directive as ‘just another formal obligation’. This is a serious mistake.
The new regulations introduce not only obligations, but also real financial penalties and personal liability for senior management. In practice, this means that ignoring NIS 2 can have very costly consequences. Financial penalties can be as high as 10 million euros or up to 2 per cent of global annual turnover.
Penalties may be imposed, amongst other things, for:
1. Failure to implement security measures. If a company fails to adequately secure its IT systems, it exposes itself to sanctions – even in the absence of an incident.
2. Failure to report an incident. Failing to report a cyberattack within the required timeframe is one of the most common breaches.
3. Inadequate risk management. Failure to carry out a threat analysis or ignoring risks.
4. Supply chain issues. Liability also extends to suppliers and partners.
Preparing early for the requirements of NIS 2 helps to minimise risk and ensure your organisation adapts smoothly to its new obligations. Find out how we can help your company achieve compliance with NIS 2.