SICHERHEIT & DATENSCHUTZ

NIS 2: Cyber Risks as a Top Priority for Companies

NIS 2: Cyber Risks as a Top Priority for Companies

With NIS 2, cybersecurity becomes a top priority. A new risk barometer shows that many medium-sized companies feel safer than they actually are.

The new NIS 2 directive, which came into effect in 2026, has far-reaching implications for corporate governance in Germany. In particular, for around 29,500 companies, cybersecurity is becoming a non-delegable responsibility of the management. Executives are now personally liable if they fail to meet the requirements of the directive. This represents a significant change in the responsibilities of leaders.

A current risk barometer from the SMK Group shows that many medium-sized companies feel more secure regarding their cybersecurity measures than reality reflects. According to the Federal Office for Information Security (BSI), these companies meet, on average, only 56 percent of the basic requirements. This discrepancy between self-perception and actual security level could have fatal consequences for many companies.

Liability Risks for Management

The introduction of NIS 2 not only brings new requirements but also personal liability risks for management. In case of non-compliance with the guidelines, executives can be held accountable, which further increases the importance of cybersecurity in corporate strategy. The directive aims to strengthen the resilience of companies against cyberattacks and raise security standards to a uniform level.

The SMK Group emphasizes that many companies underestimate the seriousness of the situation. While they may feel falsely secure, they could face not only financial losses but also legal consequences in the event of a cyber incident. The necessity to take cyber risks seriously is reinforced by the new legal framework.

The NIS 2 directive affects not only large companies but especially the medium-sized sector, which is often considered particularly vulnerable to cyberattacks. The challenge lies in implementing the necessary security measures while not disrupting business operations. Companies must therefore develop strategies to improve their IT security and ensure compliance with the new requirements.

The Role of Cybersecurity in the Company

Integrating cybersecurity into corporate strategy is now essential. Executives must ensure that their organizations have the necessary resources and expertise to meet the new requirements. This requires not only investments in technology but also in training and awareness-raising measures for employees.

The SMK Group recommends that companies conduct regular security reviews and continuously adjust their security policies. Proactively addressing cyber risks can not only avoid legal consequences but also strengthen the trust of customers and partners. In an increasingly digitalized world, the security of information and data is a crucial competitive factor.

Thus, the NIS 2 directive represents a turning point in corporate governance. The responsibility for cybersecurity no longer lies solely with the IT department but must be integrated into the entire corporate strategy. Management is called upon to actively engage with the challenges of digital security and take appropriate measures.

The implementation of the NIS 2 directive is seen by many companies as an opportunity to raise their security standards and better prepare against cyber threats. The necessity to regard cyber risks as a top priority will gain further importance in the coming years.

comment Kommentare (0)

Noch keine Kommentare. Schreiben Sie den ersten!

Kommentar hinterlassen