Management Summary

Cybersecurity used to be something boards could delegate downward. Under NIS2 and DORA, that comfort zone is disappearing. Management bodies are no longer expected only to approve budgets or receive annual risk updates. They are expected to understand cyber risk, approve the right measures, oversee implementation, and demonstrate that resilience is governed as a business risk.

This is not just a legal nuance. It changes the evidence that executives need in front of them. A board that cannot explain critical suppliers, incident response readiness, ICT concentration risk, and the quality of cyber governance is no longer simply uninformed. It may be exposed.

The practical question for executives is no longer are we compliant? It is: if a major supplier fails tomorrow, can we prove that we understood the dependency, challenged the risk, and made a defensible decision?

Executive lens

NIS2 and DORA do not ask boards to become security engineers. They ask boards to govern cybersecurity with the same seriousness as financial, operational, and legal risk.


1. What Changed

The old model of cyber governance was comfortable. Security teams owned the detail. Risk teams owned the reporting. The board received a dashboard, asked a few questions, and moved on. That model is no longer enough.

NIS2 Article 20 requires Member States to ensure that management bodies approve cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements. It also requires management body members to follow training so they can identify risks and assess cybersecurity practices.

DORA Article 5 is even more explicit for financial entities. The management body defines, approves, oversees, and is responsible for implementation of the ICT risk management framework. It bears ultimate responsibility for ICT risk, sets risk tolerance, approves resilience strategy, and must keep up to date with sufficient knowledge and skills to understand ICT risk.

The message is consistent: cybersecurity is no longer a technical control domain that reports to leadership. It is a leadership accountability domain that uses technical controls as evidence.

The boardroom shift

Old question New question
Do we have a cybersecurity policy? Can management prove the policy is implemented, tested, and effective?
Did the CISO brief the board? Did the board challenge risk assumptions and make documented decisions?
Do our suppliers complete questionnaires? Do we know which suppliers could disrupt critical services?
Do we have an incident response plan? Can we meet notification, escalation, recovery, and communication expectations under pressure?
Are we ISO 27001 certified? Can the ISMS produce evidence for NIS2, DORA, supplier risk, incident response, and resilience?

2. Why This Is Really a Supply Chain Problem

Boards often think about cyber risk as an internal security posture problem: patching, access control, awareness, vulnerability management, detection, and response. Those still matter. But modern cyber risk increasingly arrives through the organizations you depend on.

NIS2 makes this explicit. Article 21 includes supply chain security, including security-related aspects of relationships with direct suppliers and service providers. DORA requires financial entities to identify dependencies on ICT third-party service providers, manage ICT third-party risk, maintain registers of information, and consider concentration risk.

That means board oversight cannot stop at the perimeter. Management needs visibility into:

The board does not need to inspect every supplier questionnaire. It does need confidence that the organization can distinguish a low-risk vendor from a dependency that could stop the business.

Practical test

Ask management to list the ten external providers whose failure would create the fastest business disruption. If the answer is slow, inconsistent, or limited to obvious cloud vendors, supplier risk is probably under-governed.


3. Personal Liability Is Not the Starting Point

The phrase personal liability gets attention, but it can also distort the conversation. The useful question is not whether directors should be afraid. The useful question is what a reasonable, informed, diligent management body should be able to evidence.

In practice, liability risk grows when there is a visible gap between what leadership should have known and what leadership can prove it did. Regulators, auditors, customers, and courts rarely expect perfection. They do expect governance.

That governance usually comes down to five evidence areas:

  1. Awareness: management understood the organization's cyber and ICT risk profile.
  2. Decision-making: key cyber risk decisions were reviewed, challenged, approved, and documented.
  3. Oversight: implementation of risk treatment, remediation, supplier management, and resilience controls was monitored.
  4. Escalation: material incidents, overdue risks, and supplier weaknesses reached the right level quickly.
  5. Improvement: lessons from incidents, tests, audits, and supervisory feedback were built back into the control environment.

If those five areas are weak, the problem is bigger than regulatory compliance. It means the board is making decisions without a reliable operating picture.


4. What Boards Should Ask Now

A good board conversation should be specific enough to create accountability, but not so technical that it collapses into tool selection. The best questions expose whether the organization has evidence, ownership, and operating rhythm.

4.1 Risk ownership

4.2 Supplier dependency

4.3 Incident readiness

4.4 Evidence quality

These questions are uncomfortable by design. They are not meant to embarrass security teams. They are meant to make cyber risk governable.


5. The Evidence Pack a Board Should Expect

Boards should not be flooded with raw control detail. But they should receive a small, stable evidence pack that connects cyber risk to business operations and regulatory accountability.

Evidence Why it matters
Cyber risk appetite and current risk position Shows whether leadership understands where risk is accepted, reduced, transferred, or overdue.
Critical supplier map Links third-party dependencies to critical services, data, systems, and recovery expectations.
Material remediation tracker Shows whether known weaknesses are moving or simply being re-reported.
Incident and crisis exercise results Tests whether the organization can make decisions, communicate, and recover under pressure.
Regulatory obligation map Connects NIS2, DORA, ISO 27001, GDPR, and sector obligations into one control picture.
Management training record Shows that board and senior management knowledge is treated as a control, not a formality.

The key is consistency. A board pack that changes format every quarter may look active, but it often hides the trend. Governance needs a repeatable view of exposure, decision points, exceptions, and progress.


6. A 90-Day Practical Plan

Most organizations do not need another theoretical governance framework. They need a short execution cycle that turns regulatory pressure into usable evidence.

Days 1-30: Establish the board view

Days 31-60: Test the operating model

Days 61-90: Lock the governance rhythm

Control implication

The goal is not to show that every cyber risk is solved. The goal is to show that material cyber risk is visible, owned, challenged, tracked, and improved.


Conclusion: Governance Is the New Control

NIS2 and DORA do not make boards responsible for configuring firewalls. They make boards responsible for ensuring that cybersecurity and ICT risk are governed with enough knowledge, evidence, and discipline to protect the organization and the services it provides.

The organizations that will handle this well are not necessarily the ones with the longest policies. They are the ones where management can answer basic questions clearly:

That is the board-level standard now. Cybersecurity is no longer only a technical capability. It is a test of governance.


References

Primary Regulatory Sources


Back to Writing