04.03.2025
Blog
Resilience
Cyber Security

NIS2 Directive: Obligations for management

The EU’s NIS2 Directive is intended to strengthen cyber security in Europe and enhance the resilience of the economy. Although the German NIS2 Implementation Act should have been implemented by October 2024, it is in all likelihood set to be significantly delayed. However, key elements are already known and set out; the new training and monitoring obligations for management bodies are on the way and may provide fresh impetus.

Robert Stricker
Vice President Security Consulting

NIS2 Implementation Act: The current situation 

As NIS2 is an EU directive, it must be transposed into German law. The deadline for this expired in October 2024. The latest available draft bill had already cleared a number of hurdles, including consultation with experts. Although the need for further adjustments was highlighted (including the absence of an exemption for the federal administration), on the whole there was a clear vision for transposing the EU requirement into national law. With the end of the ‘traffic light’ coalition and the resulting de facto suspension of legislative proceedings, the NIS2 Implementation Act is likely to be delayed until, it is anticipated, autumn 2025. 

As the NIS2 Directive is already very specific in many respects, sets out clear measures and the current draft for national implementation is at an advanced stage of development, the scope for implementation – regardless of the timing or the political agenda – remains rather limited. 

Training obligations for senior management in businesses and public authorities 

In the current draft of the NIS2 Implementation Act, the EU requirements regarding training obligations for senior management (Chapter 2, Section 38(2)) and heads of public authorities (Chapter 3, Section 43(2)) are worded in almost identical terms. 

It is required that training be attended on a regular basis in order to ‘acquire sufficient knowledge and skills to identify and assess risks […]’. Furthermore, the scope is defined as focusing on the risks affecting ‘services provided by the organisation’. 

This is noteworthy in that senior management should not only be aware of the risks (see next section), but should apparently also be capable of actively supporting risk management. Methodologically, this involves the processes of identifying, assessing and controlling risks, for example on the basis of the standards ISO 31000, ISO 27005 or BSI IT-Grundschutz 200-3. 

Neither business nor regulatory authorities will be able to carry out risk identification or the assessment of probabilities of occurrence and levels of damage at a highly technical level; so the phrase ‘sufficient knowledge’ will (necessarily) be limited to the methodological approach and the key, process-driven information security risks. 

Nevertheless, the approach offers great potential: senior management will no longer be mere consumers of risk reports and associated mitigation budgets, but will inevitably be empowered to scrutinise risk analyses and also to challenge their own security organisation.  

Monitoring of implementation or management review 

The wording regarding monitoring of implementation is not identical to that of the training obligation; whilst the heads of public authorities “are responsible for […] creating the conditions necessary to ensure information security” (Chapter 3, Section 43(1)), senior management must “approve the risk management measures in the field of cybersecurity and monitor their implementation” (Chapter 2, Section 38(1)). 

Whilst the former leaves scope for delegation, NIS2 directly integrates senior management into the continuous improvement process of an information security management system. The good news is that the tools required for this – such as management reviews and internal audits – have long been established and well-developed.  

From ‘must’ to ‘want’: Cybersecurity as a management responsibility 

Would you like to be kept regularly informed about the state of cyber security within your organisation? Then make a point of requesting regular management reviews from your security organisation. These should include, amongst other things, the progress of measures already decided upon, potential changes, KPIs for assessing the performance of the ISMS, the results of risk analyses, and opportunities for continuous improvement. 

It is often said that ‘the fish stinks from the head down’ when something isn’t working. But how often is it emphasised that successful organisations have strong management? In cyber security in particular, managers have far more influence than simply approving budgets. Their role as role models, their work on committees, their dialogue with stakeholders and colleagues, and the targeted promotion of security awareness are crucial levers. Management support makes all the difference in ensuring that “the fish shines from the head down”. 

You should also use the principle of compulsory training in information security to gain a fresh perspective on your security organisation: why not send your CISO or ISB to the finance department or the production floor for a change? A better understanding of the challenges faced by other departments encourages mutual dialogue and strengthens the overarching goal: building a productive, efficient and resilient organisation that fulfils its business purpose or public service remit to the highest standard. 

Robert Stricker
Vice President Security Consulting

Robert Stricker ist Vice President Security Consulting bei Materna.

Related articles

Event
Frankfurt am Main
18.11.2026
BMC Helix Roadshow 2026

Meet Materna at the BMC Helix Roadshow 2026 on 18 November in Frankfurt and discover how modern service management, Agentic AI and compliance requirements work together successfully. Look forward to exclusive insights into the BMC Helix roadmap, the…

Read more
Event
Dortmund
05.11.2026
XCS Day (Xchange in Cyber Security)

At XCS Day, experts from the business and public sectors will once again come together to discuss current challenges and strategies relating to cyber security and regulation. Find out how organisations are strengthening their resilience to cyber…

Read more
Event
Dortmund
03.11.2026
FMS Information Day

On 3 November 2026, we will update you on the latest developments relating to the Federal Government’s FMS and encourage mutual exchange. The keen interest you show in every issue demonstrates that the FMS is, and will remain, a key element of…

Read more
Event
Wien
13.10.2026
Agentic AI Roundtable in Vienna

How does Agentic AI deliver real added value for IT and service organisations? At the Agentic AI Roundtable in Vienna, Materna, BMC Helix and other experts will discuss specific use cases, current challenges and next steps for businesses. Look…

Read more
Event
Berlin
13.10.2026 - 15.10.2026
Smart Country Convention (SCCON)

Come and meet us in Hall 27 at Stand 206 at the leading event for the digital state and public services. SCCON is a must-attend event for all stakeholders actively driving and shaping digital transformation. At our stand, you’ll find a use case…

Read more
Event
Amsterdam
06.10.2026 - 08.10.2026
Atlassian Team ’26 Europe

From 6 to 8 October 2026, Atlassian will be bringing the community together for ‘Team ’26 Europe’ in Amsterdam. Look forward to hands-on sessions covering AI, new products and features, live demos and certification opportunities. You’ll also have the…

Read more
Event
Berlin
01.10.2026
Open Insurance Dialog 4.0 (#OID4.0)

Open Insurance Dialog 4.0: FiDA, Identity and New Opportunities for Insurers

The insurance industry is facing a profound transformation: FiDA (Financial Data Access) and Open Insurance are creating new opportunities for data-driven services,…

Read more
Event
Online
30.09.2026
Webcast: ‘Understanding the mainframe, accelerating migration: How banks and insurers are harnessing hidden knowledge’

Mainframe and legacy systems contain decades of business logic – often inadequately documented and difficult to access. From 10.00 to 11.30, Materna and Nomain will demonstrate how AI-powered analyses can make business logic, dependencies and…

Read more
Event
Düsseldorf
30.09.2026
27th NRW ÖV Symposium

Artificial intelligence, digital sovereignty, the cloud, the data economy and cyber security form the framework for the digital transformation of public administration in North Rhine-Westphalia. This popular platform for information and dialogue on…

Read more
Event
Public Sector
Online
24.09.2026
Webcast: ‘From a jungle of registers to a digital ecosystem.’

How register modernisation, the ‘once-only’ principle and NOOTS are bringing about lasting change in public administration. Find out what challenges public authorities face, which strategies are proving effective, and how a future-proof register…

Read more