Daniel Garry, Director of Security at FutureRange, explains what the EU’s NIS2 Directive really requires of company boards, and how to tell genuine oversight from box-ticking.
NIS2 has become one of the most pressured conversations in Irish boardrooms over the past year. Most directors know cybersecurity is now their responsibility. Far fewer know whether their organisation is actually in scope, or what “doing enough” looks like in practice.
Daniel Garry has worked with a range of Irish boards on exactly this question, and he sees the same pattern again and again: boards that treat cybersecurity oversight as a genuine, ongoing responsibility fare far better than those relying solely on reassurance from the same team responsible for the controls being assessed. Here, he sets out the five legal obligations every board now needs to meet, and why independent oversight matters.

Who is in scope
Essential and important entities across energy, transport, banking, health, digital infrastructure and public administration. Scope is generally triggered by size as well as sector: broadly, organisations with 50 or more employees or annual turnover above €10 million, though some entity types are in scope regardless of size.
Cybersecurity used to sit with the IT department. Under the EU’s NIS2 Directive it is now a board responsibility. NIS2 (Directive EU 2022/2555) entered into force in January 2023, with EU member states required to transpose it into national law by October 2024. It replaces the original 2018 NIS Directive with a far wider scope and much more explicit accountability.
If your organisation falls within scope, Article 20 of the Directive makes clear that the company board is legally accountable for cybersecurity risk management. That accountability breaks down into five specific obligations.

The Hard Part
A board hearing about its cybersecurity readiness only from the team responsible for those same controls has no outside check on whether the assessment is accurate.
The difficulty most boards run into is that cyber risk doesn’t speak the same language as the risks boards are used to assessing. This makes it harder to challenge management or judge whether the assurance being reported holds up.
Independent review against a recognised framework, backed by a practical remediation plan where gaps are found, gives boards a credible basis for oversight.
Independent assurance your board can stand behind
FutureRange works with management boards to build the independent assessment, technical delivery and ongoing assurance needed to meet these obligations.
Download the FutureRange advisory pack here – FutureRange Board Advisory Pack pdf
_____________________________________________________________________________________________

About the author: Daniel Garry is our Director of Security at FutureRange, where he advises management boards on cybersecurity governance, independent assessment and regulatory compliance, including NIS2 and DORA. Reach out to him at [email protected].