An Edge Built on Knowledge and Experience
NIS2 / BSIG § 38 — Personal Liability

NIS2 Liability of Executive Management

§ 38 BSIG makes cybersecurity a personal matter for top management. We explain when managing directors and board members are personally liable — and how they can protect themselves.

Technical & Legal Expertise Experience From Numerous NIS2 Projects Based in Sindelfingen
§ 38 BSIG

What Is Executive Management Specifically Liable For?

§ 38 BSIG in conjunction with § 30 BSIG assigns executive management ultimate responsibility for structured cybersecurity risk management. This responsibility cannot be delegated — the operational implementation, however, can.

Triggers for Liability

When Does Personal Liability Arise?

Breach of the Duty of Oversight

Executive management does not have to implement every technical measure itself, but must actively oversee its implementation. Passive disregard does not protect against liability.

Missing Training Evidence

The training obligation under § 38 BSIG is an independent requirement. Missing evidence is a fine risk even without a security incident.

Missed Reporting Obligations

Late or omitted BSI notifications despite knowledge of a significant incident establish personal responsibility at the management level.

Important: Personal liability applies to managing directors, board members and authorised representatives — not just the CEO. All members of the management level are affected.

Protective Measures

How Executive Management Can Protect Itself Effectively

Is it enough to appoint a CISO and delegate the tasks to them?
No. Operational implementation can be delegated, ultimate responsibility cannot. Executive management must actively oversee the CISO's work, request regular reports, and be involved in strategic decisions. Passive trust does not protect against liability.
Does D&O insurance protect against NIS2 liability?
D&O insurance generally covers breaches of duty — but only if the insured person did not act intentionally. In cases of gross negligence or knowingly ignoring compliance obligations, the insurance often does not apply. It is no substitute for actual compliance.
What is the best protection against personal liability?
Documentation, documentation, documentation. Anyone who can demonstrate that they asked the right questions, received the right reports, made the right decisions, and justified them in a traceable way is substantially better protected than someone with no evidence trail. Plus: complete and document the training under § 38 BSIG regularly.
Related Topics

Further NIS2 Topics

Actively Limit Liability Risks

We advise managing directors and board members on their personal obligations under NIS2 and help build robust compliance documentation.

Request Consultation Now
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com