Personally Liable by Kai London
NIS2 places cyber risk management squarely with the management body: it must approve the measures, oversee their implementation and be trained to do so. That shifts the question a director should be asking from "are we compliant?" to "what evidence exists that I discharged my duty?" This handbook addresses that directly.
What the book covers
The management body's duties
Approval, oversight and training obligations, and what "approval" has to look like to be meaningful.
Reviewing the measures
How a non-specialist director can interrogate risk management measures without becoming a technologist.
Evidence of diligence
Minutes, papers, challenge recorded, decisions taken and follow-up tracked.
Delegation and assurance
What may be delegated, what may not, and how independent assurance supports the board.
Incidents at board level
The director's role during a significant incident, including notification approval and communications.
Committee design
Where cyber sits in the committee structure, reporting cadence and the standing agenda.
This book provides general guidance and is not legal advice. Liability and enforcement provisions differ across member-state implementations; directors should take qualified legal advice on their own position. Independent, with no endorsement by or affiliation with any regulator or standards body.
Who it is for
Executive and non-executive directors of essential and important entities, company secretaries, general counsel, and CISOs preparing board-level material.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.