EU NIS2 Directive Shifts Cybersecurity Liability to Boards and Supply Chains
The European Union's NIS2 Directive represents a major overhaul of cybersecurity regulation, expanding its scope to roughly 150,000 additional organisations beyond those covered under the original 2016 NIS rules. Unlike its predecessor, NIS2 holds companies accountable not just for their own security but also for the security practices of their vendors and supply chain partners. Board-level executives are now required to demonstrate cybersecurity competence and maintain active oversight of cyber risk, with directors potentially facing personal liability for failures. The directive also tightens incident reporting requirements, moving away from the vague thresholds of the original framework toward more rigorous, forensic-style disclosure obligations. Cybersecurity professionals working with affected organisations report significant tension between compliance demands and practical constraints, particularly around vendor auditing and boardroom readiness.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in