§ 38 BSIG makes cybersecurity a personal matter for top management. We explain when managing directors and board members are personally liable — and how they can protect themselves.
§ 38 BSIG in conjunction with § 30 BSIG assigns executive management ultimate responsibility for structured cybersecurity risk management. This responsibility cannot be delegated — the operational implementation, however, can.
Executive management does not have to implement every technical measure itself, but must actively oversee its implementation. Passive disregard does not protect against liability.
The training obligation under § 38 BSIG is an independent requirement. Missing evidence is a fine risk even without a security incident.
Late or omitted BSI notifications despite knowledge of a significant incident establish personal responsibility at the management level.
Important: Personal liability applies to managing directors, board members and authorised representatives — not just the CEO. All members of the management level are affected.
We advise managing directors and board members on their personal obligations under NIS2 and help build robust compliance documentation.
Request Consultation Now