Skip to content

Governance

LEGAL BASIS

§38(1) BSIG – Management of essential and important entities is obligated to implement the risk management measures to be taken by these entities per §30 and to supervise their implementation.

§38(3) BSIG – The management of essential and important entities must regularly participate in training in order to acquire sufficient knowledge and skills for identifying and assessing risks and risk management practices in the field of information technology security, and in order to be able to assess the impact of risks and risk management practices on the services provided by the entity.

Management Duties

The German NIS2 implementation establishes, for the first time, personal obligations of management for cybersecurity:

DutyDescriptionEvidence
ImplementationResponsibility for implementing the measures per §30 – also where tasks are delegated (§38(1) BSIG)Implementation orders, resource allocation
ApprovalFormal approval of the measures as appropriate (explanatory memorandum to §38(1); Art. 20(1) NIS2)Documented sign-off
SupervisionOngoing control of implementation (§38(1) BSIG)Regular reports
TrainingPersonal participation in cybersecurity training (§38(3) BSIG)Attendance record
LiabilityLiability towards the entity itself for culpable breach of duty (§38(2) BSIG)

LIABILITY

Under §38(2) BSIG, members of management who breach their duties under paragraph 1 are liable to their entity for culpably caused damage – under the company-law rules of the entity's legal form (e.g. §43 GmbHG, §93 AktG). Only where company law contains no such liability rule do they become liable directly under the BSIG.

Governance Structure

RoleResponsibility
ManagementResponsibility for implementation, approval and supervision of measures, resource allocation, personal training
Information Security Officer (ISO)Operational control, risk analysis, incident coordination, BSI contact
IT LeadTechnical implementation, system security, patch management
Department HeadsCompliance with security policies in their area

Reporting

ReportRecipientInterval
Security statusManagementQuarterly
Incident reportsManagementEvent-driven (high/critical immediately)
Annual security reportManagementAnnually
KPI reportISO / ManagementMonthly

Management Training Obligation

Management participates at least annually in cybersecurity training covering:

  • Current threat landscape and relevant incidents
  • NIS2/BSIG obligations and liability
  • Risk management and measure assessment
  • Incident response process and escalation

AI Act Synergy

The AI Act governance framework complements NIS2 governance requirements for AI-powered systems. Details in the AI Act Governance Documentation.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT