EU NIS2 Directive – Cybersecurity Is Now a Management Responsibility
The European NIS2 Directive is intended to significantly strengthen cybersecurity in the EU – and in future it will affect far more organisations than before. IT security is therefore no longer an optional IT issue, but an integral part of responsible corporate governance. NIS2 has become binding through its national implementation. In Germany, this has been in force since 6 December 2025; affected companies were required to register with the Federal Office for Information Security (BSI) by March 2026.
NIS2 Becomes Mandatory: Why Companies Must Act Now
Irrespective of NIS2, the following applies: companies must be aware of their risks and manage them appropriately. This also includes protecting their own IT systems. Those who fail to take action here are not only taking an economic risk but are also exposing themselves to significant legal consequences.
Added to this is growing pressure from the market. Clients, business partners and insurers are already aligning themselves with the new requirements and passing these on along the supply chain. Anyone currently involved in projects that extend beyond national borders is already facing these expectations. The crucial question is therefore not whether NIS2 is formally in effect yet – but whether their own IT systems would withstand a targeted attack.
IT security begins with the question: Which systems are truly critical to our operations? In construction companies, these are often project platforms, cost estimation software, email systems, document management systems or ERP solutions. If any of these systems fails, it has a direct impact on workflows, schedules and payment processes.
On this basis, responsibilities must be clearly defined. Who is accountable for IT security? Who makes the decisions in an emergency? And who takes charge of coordination when rapid action is required? Equally crucial is a robust assessment of the actual risks. Which systems are particularly vulnerable? Which data is indispensable? And what specific consequences would a failure have?
Technology: Less Is More – if Done Right
From a technology perspective, it is not about deploying as many solutions as possible, but the right ones – consistently and reliably. Key to this is ensuring that systems are up to date. Outdated software remains one of the most common targets for attacks. Regular updates are therefore essential.
The decisive factor here is not achieving a certain level of protection once and for all, or purchasing individual products, but rather their continuous review and adaptation. This is the only way to ensure that protection remains effective even under changing conditions. Clearly defined access rights are equally crucial. Not every employee needs access to all systems or data. Making a clear distinction here significantly reduces the risk.
Another key area is data backup. Backups must be in place – and, above all, regularly tested and accessible in an emergency. In such cases, this is precisely what determines whether a company can resume operations within hours or remains at a standstill for days.
End-user devices also play a greater role than is often assumed. Laptops, smartphones and mobile devices are frequently the gateway for attacks – particularly when used outside the company network.
IT Security Is Not a Project, but a Process
If a security incident occurs, preparedness determines the extent of the damage. Companies should not wait until an emergency arises to consider how they will respond. One of the most important initial measures is to quickly isolate affected systems to prevent the threat from spreading further. At the same time, it must be clarified which systems are affected and how operations can be stabilised.
Specialised IT security service providers are often indispensable in this regard. Many companies do not have the necessary resources to manage complex incidents on their own. Added to this are reporting obligations that must be met within short timeframes. Without prepared procedures, this can quickly become an additional burden. Communication is equally crucial – both internally and externally. Unclear or delayed information can significantly exacerbate the damage.
IT security cannot be “implemented” once and for all. The threat landscape is constantly evolving – and so are the requirements. Companies should regularly review their security measures and adapt them to changing threat landscapes. This includes clear processes, defined responsibilities and recurring tests.
Liability: Inaction Becomes a Risk
IT security has become a matter of corporate responsibility. Directors are obliged to organise their companies in such a way that foreseeable risks are managed – and today, this explicitly includes IT.
If an incident occurs and it becomes apparent that fundamental measures were neglected – such as a lack of backups, inadequate access controls or outdated systems – this may be deemed organisational negligence. Appropriate protective mechanisms and software solutions, such as those offered by the international cybersecurity company ESET, are now widely available, economically viable and considered state of the art. However, many companies are still not using them consistently.
The crucial factor is not whether NIS2 has already been formally implemented, but whether a company has responded appropriately to identifiable risks. Anyone who remains inactive in this regard faces a twofold risk: financial – and personal.
Eugen Schmitz
