NIS2 · Director duties

Personally Liable by Kai London

NIS2 places cyber risk management squarely with the management body: it must approve the measures, oversee their implementation and be trained to do so. That shifts the question a director should be asking from "are we compliant?" to "what evidence exists that I discharged my duty?" This handbook addresses that directly.

Coming soonAll books

What the book covers

The management body's duties

Approval, oversight and training obligations, and what "approval" has to look like to be meaningful.

Reviewing the measures

How a non-specialist director can interrogate risk management measures without becoming a technologist.

Evidence of diligence

Minutes, papers, challenge recorded, decisions taken and follow-up tracked.

Delegation and assurance

What may be delegated, what may not, and how independent assurance supports the board.

Incidents at board level

The director's role during a significant incident, including notification approval and communications.

Committee design

Where cyber sits in the committee structure, reporting cadence and the standing agenda.

This book provides general guidance and is not legal advice. Liability and enforcement provisions differ across member-state implementations; directors should take qualified legal advice on their own position. Independent, with no endorsement by or affiliation with any regulator or standards body.

NIS2ISO 27001NIST CSF 2.0Corporate governance

Who it is for

Executive and non-executive directors of essential and important entities, company secretaries, general counsel, and CISOs preparing board-level material.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.