German firms face CEO liability under NIS2 cyber rules
The EU’s NIS2 directive tightens cyber‑security obligations for companies, shifting personal liability for security failures to senior executives. Under the rule, German firms must demonstrate documented processes such as multi‑factor authentication and robust incident‑response plans, or risk fines of up to €10 million or 2 % of global turnover and possible bans on directors.
Experts warn that AI‑driven attacks are boosting the success of phishing, business‑email‑compromise and ransomware, making compliance even more critical. A Bitkom study cited that 87 % of German companies experienced cyber incidents in 2024, with total damages estimated at €289.2 billion.
The rise of “shadow‑IT” – uncontrolled SaaS accounts outside central identity management – creates orphaned accounts that persist after employee off‑boarding, exposing sensitive data and further increasing the liability risk for CEOs and boards.