Who in the company bears responsibility for failing to meet NIS2 obligations?

FAQ

The new legislation (and the Czech Cybersecurity Act) targets top management directly. Responsibility can no longer be delegated solely to the IT department or an external administrator. Statutory bodies have a duty to educate themselves in the field of cybersecurity and to oversee the implementation of measures. In the event of gross negligence, senior staff may even face a temporary ban on holding office.

More questions and answers