Management Summary
Cybersecurity used to be something boards could delegate downward. Under NIS2 and DORA, that comfort zone is disappearing. Management bodies are no longer expected only to approve budgets or receive annual risk updates. They are expected to understand cyber risk, approve the right measures, oversee implementation, and demonstrate that resilience is governed as a business risk.
This is not just a legal nuance. It changes the evidence that executives need in front of them. A board that cannot explain critical suppliers, incident response readiness, ICT concentration risk, and the quality of cyber governance is no longer simply uninformed. It may be exposed.
The practical question for executives is no longer are we compliant? It is: if a major supplier fails tomorrow, can we prove that we understood the dependency, challenged the risk, and made a defensible decision?
Executive lens
NIS2 and DORA do not ask boards to become security engineers. They ask boards to govern cybersecurity with the same seriousness as financial, operational, and legal risk.
1. What Changed
The old model of cyber governance was comfortable. Security teams owned the detail. Risk teams owned the reporting. The board received a dashboard, asked a few questions, and moved on. That model is no longer enough.
NIS2 Article 20 requires Member States to ensure that management bodies approve cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements. It also requires management body members to follow training so they can identify risks and assess cybersecurity practices.
DORA Article 5 is even more explicit for financial entities. The management body defines, approves, oversees, and is responsible for implementation of the ICT risk management framework. It bears ultimate responsibility for ICT risk, sets risk tolerance, approves resilience strategy, and must keep up to date with sufficient knowledge and skills to understand ICT risk.
The message is consistent: cybersecurity is no longer a technical control domain that reports to leadership. It is a leadership accountability domain that uses technical controls as evidence.
The boardroom shift
| Old question | New question |
|---|---|
| Do we have a cybersecurity policy? | Can management prove the policy is implemented, tested, and effective? |
| Did the CISO brief the board? | Did the board challenge risk assumptions and make documented decisions? |
| Do our suppliers complete questionnaires? | Do we know which suppliers could disrupt critical services? |
| Do we have an incident response plan? | Can we meet notification, escalation, recovery, and communication expectations under pressure? |
| Are we ISO 27001 certified? | Can the ISMS produce evidence for NIS2, DORA, supplier risk, incident response, and resilience? |
2. Why This Is Really a Supply Chain Problem
Boards often think about cyber risk as an internal security posture problem: patching, access control, awareness, vulnerability management, detection, and response. Those still matter. But modern cyber risk increasingly arrives through the organizations you depend on.
NIS2 makes this explicit. Article 21 includes supply chain security, including security-related aspects of relationships with direct suppliers and service providers. DORA requires financial entities to identify dependencies on ICT third-party service providers, manage ICT third-party risk, maintain registers of information, and consider concentration risk.
That means board oversight cannot stop at the perimeter. Management needs visibility into:
- which third parties support critical or important functions,
- which suppliers have privileged access, sensitive data, or operational dependencies,
- which providers are shared across multiple critical services,
- which subcontractors create hidden nth-party exposure,
- which contracts contain usable incident notification, audit, exit, and resilience clauses,
- which suppliers have been tested in incident response or continuity scenarios.
The board does not need to inspect every supplier questionnaire. It does need confidence that the organization can distinguish a low-risk vendor from a dependency that could stop the business.
Practical test
Ask management to list the ten external providers whose failure would create the fastest business disruption. If the answer is slow, inconsistent, or limited to obvious cloud vendors, supplier risk is probably under-governed.
3. Personal Liability Is Not the Starting Point
The phrase personal liability gets attention, but it can also distort the conversation. The useful question is not whether directors should be afraid. The useful question is what a reasonable, informed, diligent management body should be able to evidence.
In practice, liability risk grows when there is a visible gap between what leadership should have known and what leadership can prove it did. Regulators, auditors, customers, and courts rarely expect perfection. They do expect governance.
That governance usually comes down to five evidence areas:
- Awareness: management understood the organization's cyber and ICT risk profile.
- Decision-making: key cyber risk decisions were reviewed, challenged, approved, and documented.
- Oversight: implementation of risk treatment, remediation, supplier management, and resilience controls was monitored.
- Escalation: material incidents, overdue risks, and supplier weaknesses reached the right level quickly.
- Improvement: lessons from incidents, tests, audits, and supervisory feedback were built back into the control environment.
If those five areas are weak, the problem is bigger than regulatory compliance. It means the board is making decisions without a reliable operating picture.
4. What Boards Should Ask Now
A good board conversation should be specific enough to create accountability, but not so technical that it collapses into tool selection. The best questions expose whether the organization has evidence, ownership, and operating rhythm.
4.1 Risk ownership
- Who owns cybersecurity risk at management level?
- Who owns ICT third-party risk, and is that role independent enough to challenge procurement and business owners?
- Which risks exceed appetite today, and who accepted them?
4.2 Supplier dependency
- Which suppliers support critical or important functions?
- Which supplier failures would trigger customer, regulatory, or operational impact within 24 hours?
- Which suppliers are difficult to replace, and what are the tested exit options?
4.3 Incident readiness
- When was the last executive-level cyber incident exercise?
- Did it include legal, communications, privacy, operations, and supplier management?
- Can the organization classify, escalate, notify, and communicate a major incident within the required timelines?
4.4 Evidence quality
- Which metrics are based on actual testing, and which are self-attestations?
- Which overdue remediation items have stayed open for more than one reporting cycle?
- What would we show a regulator tomorrow if asked to prove effective governance?
These questions are uncomfortable by design. They are not meant to embarrass security teams. They are meant to make cyber risk governable.
5. The Evidence Pack a Board Should Expect
Boards should not be flooded with raw control detail. But they should receive a small, stable evidence pack that connects cyber risk to business operations and regulatory accountability.
| Evidence | Why it matters |
|---|---|
| Cyber risk appetite and current risk position | Shows whether leadership understands where risk is accepted, reduced, transferred, or overdue. |
| Critical supplier map | Links third-party dependencies to critical services, data, systems, and recovery expectations. |
| Material remediation tracker | Shows whether known weaknesses are moving or simply being re-reported. |
| Incident and crisis exercise results | Tests whether the organization can make decisions, communicate, and recover under pressure. |
| Regulatory obligation map | Connects NIS2, DORA, ISO 27001, GDPR, and sector obligations into one control picture. |
| Management training record | Shows that board and senior management knowledge is treated as a control, not a formality. |
The key is consistency. A board pack that changes format every quarter may look active, but it often hides the trend. Governance needs a repeatable view of exposure, decision points, exceptions, and progress.
6. A 90-Day Practical Plan
Most organizations do not need another theoretical governance framework. They need a short execution cycle that turns regulatory pressure into usable evidence.
Days 1-30: Establish the board view
- Confirm which NIS2, DORA, and sector obligations apply.
- Define the executive owner for cyber and ICT third-party risk.
- Create a first board-level view of critical services, critical suppliers, and major open risks.
- Identify any overdue high-risk remediation items that have not been escalated.
Days 31-60: Test the operating model
- Run a supplier-driven incident tabletop with security, legal, privacy, communications, procurement, and business owners.
- Test notification decision-making, not just technical containment.
- Review whether supplier contracts support the response process in practice.
- Document gaps in evidence, authority, escalation, and recovery assumptions.
Days 61-90: Lock the governance rhythm
- Approve a stable board cyber risk pack.
- Set thresholds for board escalation and risk acceptance.
- Update supplier risk governance for critical and high-impact providers.
- Schedule recurring management training and annual scenario testing.
- Connect the work to ISO 27001, NIS2, DORA, and internal audit evidence.
Control implication
The goal is not to show that every cyber risk is solved. The goal is to show that material cyber risk is visible, owned, challenged, tracked, and improved.
Conclusion: Governance Is the New Control
NIS2 and DORA do not make boards responsible for configuring firewalls. They make boards responsible for ensuring that cybersecurity and ICT risk are governed with enough knowledge, evidence, and discipline to protect the organization and the services it provides.
The organizations that will handle this well are not necessarily the ones with the longest policies. They are the ones where management can answer basic questions clearly:
- What are our most important cyber and ICT risks?
- Which suppliers could create material disruption?
- Which risks are outside appetite?
- What have we tested?
- What are we still unable to prove?
That is the board-level standard now. Cybersecurity is no longer only a technical capability. It is a test of governance.
Primary Regulatory Sources
Back to Writing