04.03.2025
Blog
Resilience
Cyber Security

NIS2 Directive: Obligations for management

The EU’s NIS2 Directive is intended to strengthen cyber security in Europe and enhance the resilience of the economy. Although the German NIS2 Implementation Act should have been implemented by October 2024, it is in all likelihood set to be significantly delayed. However, key elements are already known and set out; the new training and monitoring obligations for management bodies are on the way and may provide fresh impetus.

Robert Stricker
Vice President, Security Consulting

NIS2 Implementation Act: The current situation 

As NIS2 is an EU directive, it must be transposed into German law. The deadline for this expired in October 2024. The latest available draft bill had already cleared a number of hurdles, including consultation with experts. Although the need for further adjustments was highlighted (including the absence of an exemption for the federal administration), on the whole there was a clear vision for transposing the EU requirement into national law. With the end of the ‘traffic light’ coalition and the resulting de facto suspension of legislative proceedings, the NIS2 Implementation Act is likely to be delayed until, it is anticipated, autumn 2025. 

As the NIS2 Directive is already very specific in many respects, sets out clear measures and the current draft for national implementation is at an advanced stage of development, the scope for implementation – regardless of the timing or the political agenda – remains rather limited. 

Training obligations for senior management in businesses and public authorities 

In the current draft of the NIS2 Implementation Act, the EU requirements regarding training obligations for senior management (Chapter 2, Section 38(2)) and heads of public authorities (Chapter 3, Section 43(2)) are worded in almost identical terms. 

It is required that training be attended on a regular basis in order to ‘acquire sufficient knowledge and skills to identify and assess risks […]’. Furthermore, the scope is defined as focusing on the risks affecting ‘services provided by the organisation’. 

This is noteworthy in that senior management should not only be aware of the risks (see next section), but should apparently also be capable of actively supporting risk management. Methodologically, this involves the processes of identifying, assessing and controlling risks, for example on the basis of the standards ISO 31000, ISO 27005 or BSI IT-Grundschutz 200-3. 

Neither business nor regulatory authorities will be able to carry out risk identification or the assessment of probabilities of occurrence and levels of damage at a highly technical level; so the phrase ‘sufficient knowledge’ will (necessarily) be limited to the methodological approach and the key, process-driven information security risks. 

Nevertheless, the approach offers great potential: senior management will no longer be mere consumers of risk reports and associated mitigation budgets, but will inevitably be empowered to scrutinise risk analyses and also to challenge their own security organisation.  

Monitoring of implementation or management review 

The wording regarding monitoring of implementation is not identical to that of the training obligation; whilst the heads of public authorities “are responsible for […] creating the conditions necessary to ensure information security” (Chapter 3, Section 43(1)), senior management must “approve the risk management measures in the field of cybersecurity and monitor their implementation” (Chapter 2, Section 38(1)). 

Whilst the former leaves scope for delegation, NIS2 directly integrates senior management into the continuous improvement process of an information security management system. The good news is that the tools required for this – such as management reviews and internal audits – have long been established and well-developed.  

From ‘must’ to ‘want’: Cybersecurity as a management responsibility 

Would you like to be kept regularly informed about the state of cyber security within your organisation? Then make a point of requesting regular management reviews from your security organisation. These should include, amongst other things, the progress of measures already decided upon, potential changes, KPIs for assessing the performance of the ISMS, the results of risk analyses, and opportunities for continuous improvement. 

It is often said that ‘the fish stinks from the head down’ when something isn’t working. But how often is it emphasised that successful organisations have strong management? In cyber security in particular, managers have far more influence than simply approving budgets. Their role as role models, their work on committees, their dialogue with stakeholders and colleagues, and the targeted promotion of security awareness are crucial levers. Management support makes all the difference in ensuring that “the fish shines from the head down”. 

You should also use the principle of compulsory training in information security to gain a fresh perspective on your security organisation: why not send your CISO or ISB to the finance department or the production floor for a change? A better understanding of the challenges faced by other departments encourages mutual dialogue and strengthens the overarching goal: building a productive, efficient and resilient organisation that fulfils its business purpose or public service remit to the highest standard. 

Robert Stricker
Vice President, Security Consulting

Robert Stricker is Vice President of Security Consulting at Materna.

Related articles

Short News
Think ahead
Cyber Security
26.08.2026
Quantum computers: The end of encryption as we know it

Why post-quantum readiness extends far beyond cryptography and is becoming a key prerequisite for digital sovereignty – for public administration, critical infrastructure, industry and all organisations with data that requires long-term protection.

Read more
Blog
Cyber Security
11.08.2026
Detecting and intercepting drones: the solutions are already available

How well are critical infrastructures protected against drone attacks? The security incident at Leipzig/Halle Airport has sent shockwaves through…

Read more
Blog
Cyber Security
11.08.2026
Cyber Security 2026: These trends are shaping both the business sector and public administration

In 2026, cyber security will be more of a focus than ever for businesses, government agencies and public institutions. According to the Lünendonk…

Read more
Short News
Corporate
Cyber Security
31.07.2026
From Rising Star to Leader: Materna has been recognised as a Leader in Strategic Security Services in the ISG Provider Lens™ Cyber Security – Services and Solutions 2026

ISG has recognised Materna as a leading provider of cyber security consultancy in Germany.

Read more
Blog
Cyber Security
28.07.2026
Security by Design: Why secure software isn’t just created just before going live

In many software projects, security is still viewed as a final testing step. Once the application is almost complete, security scans, penetration…

Read more
Blog
Cyber Security
21.07.2026
Information security: Clear lines of responsibility strengthen cyber resilience

Information security rarely fails due to a lack of awareness alone – it is often unclear lines of responsibility, a lack of coordination and…

Read more
Blog
Cyber Security
13.05.2026
KRITIS Framework Act: These new requirements now apply to KRITIS operators

The protection of critical infrastructure has been a key issue for many businesses and public authorities for years. With the new KRITIS framework law…

Read more
Blog
Cyber Security
24.03.2026
Cyber resilience in small and medium-sized enterprises: Why cyber security today determines the future

Cyber resilience in small and medium-sized enterprises is no longer merely an optional IT issue, but a strategic necessity. Whilst large corporations…

Read more
Blog
Cyber Security
30.10.2025
A systematic approach to information security: Why an ISMS is essential

In an age of growing cyber threats and complex digital interdependencies, information security has long since become a strategic factor for success.…

Read more
Blog
Data & AI
Cyber Security
28.10.2025
Prompt Injection – How AI can be misled by hidden commands

Imagine this: you ask a chatbot to summarise a web page. At first glance, the text seems completely harmless, but hidden somewhere in the small print…

Read more