§ 38 BSIG personally obligates managing directors and board members to complete regular cybersecurity training — with a duty to provide evidence to the BSI.
The training obligation under § 38 BSIG is not a bureaucratic add-on. It reflects the recognition that cybersecurity is shaped top-down: without competence at the top, responsible governance of cyber risk cannot be ensured.
In its guidance of April 2026, the BSI specified which content an NIS2-compliant executive training must cover. Four topic areas are central.
Current attack scenarios, typical attack vectors against companies of your size and industry, ransomware risks.
How cyber risks are assessed and factored into business decisions — budget responsibility and prioritisation.
Personal liability under § 38 BSIG, the fine framework, reporting obligations, and consequences of non-compliance.
The role of executive management in an actual incident: decision-making paths, external communication, contact with authorities.
Breaching the training obligation under § 38 BSIG is an independent ground for a fine — regardless of whether a security incident has occurred. In addition, there is personal liability for damage arising from inadequate risk management.
Personal liability: Managing directors and board members are personally liable under § 38 BSIG for implementing NIS2 requirements. Missing training can be treated as a breach of duty in the event of damage — with direct consequences for personal assets.
We offer tailored executive training that fulfils § 38 BSIG and is practically aligned with your industry and company situation.
Request Training