// Executive Overview
Article 20 of the NIS2 Directive marks a significant shift in legislative focus: Personal Liability and Accountability. For the first time, "management bodies" can be held personally responsible for non-compliance with cyber risk-management measures.
Member States must ensure that management bodies of essential and important entities are required to approve the cybersecurity risk-management measures and oversee its implementation.
// Key Requirements for Managers
// 01. Mandatory Training
Top management must undergo periodic cybersecurity training to identify risks and assess cybersecurity management practices.
// 02. Risk Measure Approval
Management must formally sign off on the technical and organizational measures implemented under Article 21.
// 03. Oversight Responsibility
Management must actively monitor the effectiveness of security measures and ensure adequate ресурing for cybersecurity.
// Telecom Implementation Strategy
For telecom operators, this means moving cybersecurity from a "Technical Ticket" to a "Board Agenda Item".
- Establish a direct Reporting Line (CISO to Board)
- Document formal Approval Sessions for NIS2 controls
- Implement 'Managerial Dashboards' for real-time risk visibility
