NIS2: the five things board directors are legally required to do

Daniel Garry, Director of Security at FutureRange, explains what the EU’s NIS2 Directive really requires of company boards, and how to tell genuine oversight from box-ticking.

NIS2 has become one of the most pressured conversations in Irish boardrooms over the past year. Most directors know cybersecurity is now their responsibility. Far fewer know whether their organisation is actually in scope, or what “doing enough” looks like in practice.

Daniel Garry has worked with a range of Irish boards on exactly this question, and he sees the same pattern again and again: boards that treat cybersecurity oversight as a genuine, ongoing responsibility fare far better than those relying solely on reassurance from the same team responsible for the controls being assessed. Here, he sets out the five legal obligations every board now needs to meet, and why independent oversight matters.

Who is in scope

Essential and important entities across energy, transport, banking, health, digital infrastructure and public administration. Scope is generally triggered by size as well as sector: broadly, organisations with 50 or more employees or annual turnover above €10 million, though some entity types are in scope regardless of size.

Cybersecurity used to sit with the IT department. Under the EU’s NIS2 Directive it is now a board responsibility. NIS2 (Directive EU 2022/2555) entered into force in January 2023, with EU member states required to transpose it into national law by October 2024. It replaces the original 2018 NIS Directive with a far wider scope and much more explicit accountability.

If your organisation falls within scope, Article 20 of the Directive makes clear that the company board is legally accountable for cybersecurity risk management. That accountability breaks down into five specific obligations.

  1. Approve the adequacy of cybersecurity risk management measures
    The board must sign off on whether the organisation’s approach to managing cyber risk is fit for purpose. In practice, this means reviewing the risk management framework being used, for example ISO 27001 or the NIST framework, understanding what risks it’s designed to address, and being satisfied it matches the scale of threats the organisation actually faces, rather than approving whatever the IT or security team presents without independent scrutiny.
  2. Supervise implementation
    The board must have ongoing visibility into how those measures are being put into practice, and confidence that what has been approved is actually happening. This isn’t a one-off sign-off. It means receiving regular reporting, asking pointed questions when assurances don’t match the evidence, and treating cybersecurity oversight as a standing agenda item rather than an annual review.
  3. Complete training
    Board members are required to learn how to identify cyber risks and assess how well they’re being managed. This doesn’t mean directors need to become technical experts. It means having enough grounding to recognise red flags, know what questions are worth asking, and judge whether a report from management actually stands up to scrutiny.
  4. Ensure staff receive equivalent training
    Employees across the organisation must undertake cybersecurity training appropriate to their role. The obligation sits with the board to make sure this training happens and stays current, covering everyone from frontline staff who might encounter a phishing attempt to specialist technical teams who need a deeper understanding of the threats they’re defending against.
  5. Be accountable for non-compliance
    Falling short of the NIS2 strictures can result in substantial fines. The exact scale depends on the type of entity and the severity of the failure, but penalties can run into the millions of euros, or be calculated as a percentage of global annual turnover, whichever is greater. This obligation is what turns the previous four from good practice into enforceable legal duties: directors can be held personally accountable for gaps in oversight, not just the organisation as a whole.

The Hard Part

A board hearing about its cybersecurity readiness only from the team responsible for those same controls has no outside check on whether the assessment is accurate.

The difficulty most boards run into is that cyber risk doesn’t speak the same language as the risks boards are used to assessing. This makes it harder to challenge management or judge whether the assurance being reported holds up.

Independent review against a recognised framework, backed by a practical remediation plan where gaps are found, gives boards a credible basis for oversight.

Independent assurance your board can stand behind

FutureRange works with management boards to build the independent assessment, technical delivery and ongoing assurance needed to meet these obligations.

Download the FutureRange advisory pack here – FutureRange Board Advisory Pack pdf.

_____________________________________________________________________________________________

About the author: Daniel Garry is our Director of Security at FutureRange, where he advises management boards on cybersecurity governance, independent assessment and regulatory compliance, including NIS2 and DORA. Reach out to him at [email protected].

Related Posts

Stay informed with practical guidance, industry developments and expert perspectives on IT intelligence and security.

Book a 30 minute consultation

See how we can help