NIS2 Implementation Act: The current situation
As NIS2 is an EU directive, it must be transposed into German law. The deadline for this expired in October 2024. The latest available draft bill had already cleared a number of hurdles, including consultation with experts. Although the need for further adjustments was highlighted (including the absence of an exemption for the federal administration), on the whole there was a clear vision for transposing the EU requirement into national law. With the end of the ‘traffic light’ coalition and the resulting de facto suspension of legislative proceedings, the NIS2 Implementation Act is likely to be delayed until, it is anticipated, autumn 2025.
As the NIS2 Directive is already very specific in many respects, sets out clear measures and the current draft for national implementation is at an advanced stage of development, the scope for implementation – regardless of the timing or the political agenda – remains rather limited.
Training obligations for senior management in businesses and public authorities
In the current draft of the NIS2 Implementation Act, the EU requirements regarding training obligations for senior management (Chapter 2, Section 38(2)) and heads of public authorities (Chapter 3, Section 43(2)) are worded in almost identical terms.
It is required that training be attended on a regular basis in order to ‘acquire sufficient knowledge and skills to identify and assess risks […]’. Furthermore, the scope is defined as focusing on the risks affecting ‘services provided by the organisation’.
This is noteworthy in that senior management should not only be aware of the risks (see next section), but should apparently also be capable of actively supporting risk management. Methodologically, this involves the processes of identifying, assessing and controlling risks, for example on the basis of the standards ISO 31000, ISO 27005 or BSI IT-Grundschutz 200-3.
Neither business nor regulatory authorities will be able to carry out risk identification or the assessment of probabilities of occurrence and levels of damage at a highly technical level; so the phrase ‘sufficient knowledge’ will (necessarily) be limited to the methodological approach and the key, process-driven information security risks.
Nevertheless, the approach offers great potential: senior management will no longer be mere consumers of risk reports and associated mitigation budgets, but will inevitably be empowered to scrutinise risk analyses and also to challenge their own security organisation.
Monitoring of implementation or management review
The wording regarding monitoring of implementation is not identical to that of the training obligation; whilst the heads of public authorities “are responsible for […] creating the conditions necessary to ensure information security” (Chapter 3, Section 43(1)), senior management must “approve the risk management measures in the field of cybersecurity and monitor their implementation” (Chapter 2, Section 38(1)).
Whilst the former leaves scope for delegation, NIS2 directly integrates senior management into the continuous improvement process of an information security management system. The good news is that the tools required for this – such as management reviews and internal audits – have long been established and well-developed.
From ‘must’ to ‘want’: Cybersecurity as a management responsibility
Would you like to be kept regularly informed about the state of cyber security within your organisation? Then make a point of requesting regular management reviews from your security organisation. These should include, amongst other things, the progress of measures already decided upon, potential changes, KPIs for assessing the performance of the ISMS, the results of risk analyses, and opportunities for continuous improvement.
It is often said that ‘the fish stinks from the head down’ when something isn’t working. But how often is it emphasised that successful organisations have strong management? In cyber security in particular, managers have far more influence than simply approving budgets. Their role as role models, their work on committees, their dialogue with stakeholders and colleagues, and the targeted promotion of security awareness are crucial levers. Management support makes all the difference in ensuring that “the fish shines from the head down”.
You should also use the principle of compulsory training in information security to gain a fresh perspective on your security organisation: why not send your CISO or ISB to the finance department or the production floor for a change? A better understanding of the challenges faced by other departments encourages mutual dialogue and strengthens the overarching goal: building a productive, efficient and resilient organisation that fulfils its business purpose or public service remit to the highest standard.