Governance and management accountability
Governance and management accountability requires that the organization's leadership—specifically its "management bodies"—take ultimate responsibility for cybersecurity. They must formally approve the risk-management measures implemented by the entity and ensure they receive specific training to manage those risks.
What it means
Under NIS2, cybersecurity is no longer treated as a purely technical issue delegated to IT; it is a legal requirement of corporate governance. The intent is to bridge the gap between operational security teams and executive decision-makers, ensuring that resources are allocated and strategic priorities are aligned with risk levels.
In practice, this means the board or senior management cannot claim ignorance of cybersecurity failures. They are required to oversee the implementation of the measures mandated by the directive and may be held personally liable in some jurisdictions for non-compliance.
How to meet it
- Establish a formal process where the governing body reviews and signs off on the organization's cybersecurity strategy, risk assessments, and security policies.
- Implement a mandatory cybersecurity training program specifically tailored for executive leadership, focusing on strategic risk rather than technical configuration.
- Define clear roles and responsibilities (e.g., via a RACI matrix) that link operational security tasks to management accountability.
- Create a recurring reporting cadence—such as quarterly board briefings—where the CISO or equivalent provides updates on the threat landscape and compliance status.
- Integrate cybersecurity risks into the organization's overarching Enterprise Risk Management (ERM) framework rather than maintaining it as a separate IT silo.
Evidence an auditor asks for
- Board meeting minutes showing documented discussions, challenges, and formal approval of security measures and budgets.
- Training logs or certificates proving that all members of the management body have completed their required cybersecurity training.
- A signed organizational chart or governance charter clearly outlining who is accountable for risk-management decisions.
- Copies of executive-level reports (dashboards/KPIs) presented to leadership throughout the year.
Common pitfalls
- "Rubber-stamping," where management signs documents without evidence of review or critical inquiry, which auditors may view as a failure of oversight.
- Providing executives with overly technical training that is irrelevant to their governance role, failing to meet the requirement for "appropriate" training.
- Assuming that having a CISO automatically satisfies management accountability; the responsibility remains with the board regardless of who manages the day-to-day operations.