Skip to content

NIS2: Why Your Data & Governance Game Just Went Board-Level

November 14, 20254 minute read

In late 2022 the EU took a step that should raise the pulse of any executive who treats cybersecurity as “just IT.” The NIS2 Directive (Directive (EU) 2022/2555) is now the law of the land across much of Europe, and it does three things at once: broadens the perimeter, deepens enforcement, and elevates accountability.

If you thought “security” was a back-office item, think again. Your data governance, your labelling of data, your enterprise-wide visibility — all of that just moved into the boardroom.

What’s Changed With NIS2?
Scope Explosion
Where the previous directive (NIS 1) focused on a handful of sectors, NIS2 covers much more. From energy, transport, digital infrastructure and health to public administration, space, waste management and critical manufacturing.

Who’s In Scope
All medium and large entities in the sectors in scope are included — not just the “operators of essential services.” Medium-sized enterprises can no longer hide behind size.

New Obligations
• Rigorous risk-management frameworks including supply-chain oversight, vulnerability management, backup/disaster-recovery.
• Incident-reporting (for “significant incidents”) with tight timeframes.
• Top-management accountability becomes explicit: Senior executives can be held personally liable for non-compliance, including being barred from holding management positions.

Stronger Enforcement
Large fines (10 millions of euros or 2% of global turnover) are now possible.
• Some EU Member States’ transposition laws may impose stricter rules for senior executives. For example, the German draft legislation (§ 38 BSIG-E) stipulates that members of the management may be held liable with their private assets, and that such liability cannot be waived or excluded by contract (i.e., agreements releasing them from recourse are invalid).
• Implementation deadline: While Member States were required to transpose by 17 October 2024, full, uniform application remains uneven with Germany leading the way.

Why Data Management & Data Labelling Become Core
Let’s get real: you can’t secure what you can’t see. Under NIS2, simply having a cybersecurity team is insufficient if you don’t know what data you hold, where it flows, who touches it, how it’s classified.

• Data labelling: Distinguishing data by criticality (operational, personal, export-controlled, regulated) becomes foundational.
• Traceability: Knowing who accessed what and when (and whether it matters under NIS2) is no longer optional.
• Chain of custody & supply-chain risks: If you’re a vendor or service-provider feeding data into another entity, you’re in the loop — you may become “important entity” and subject to NIS2 obligations.

In short: your data governance systems must shift from “nice to have”
to strategic enabler or regulatory risk.

What You Should Be Doing Right Now
Here’s your rapid-response checklist for action:
1. Applicability assessment
• Does your organization sit in one of the sectors? Are you medium or large size? If yes → you’re likely in scope.

2. Gap-analysis
• Map current controls (risk-management, incident-reporting, supplychain oversight, data-classification) against NIS2 minimums.
• Refer to ENISA’s technical implementation guidance for digital infra and service-providers.

3. Board-level commitment
• Elevate this to executive agenda: allocate budget, define roles, mandate reporting to top-table.
• Ensure data classification and labelling is built into the roadmap.

4. Incident-response & reporting system
• Define “significant incident” (per your national regulator) and build process flows for immediate escalation.
• Ensure supply-chain / third-party oversight is embedded: NIS2 focuses heavily here.

5. Gap-analysis
• Cyber-threats evolve. One-time compliance is not enough. You’ll need audit trails, metrics, dashboards.

6.Gap-analysis
• Your people are your first line. Awareness, roles and responsibilities, access control.
• Data labeling must be adopted by operations, not just IT.

Broader Implications for Firms Like Yours (and Mine)
If you’re a global firm operating in or serving the EU — this matters.
• Data-flows that cross borders (between China, US, EU) now sit in a more regulated world.
• If you supply into a German, French or Dutch “essential entity,” you may find yourself dragged into compliance demands.
• Compliance is not just risk-mitigation — it can become a competitive advantage: if you can show certified data governance and cybersecurity maturity, clients and regulators will note it.

Final Word
The engine of corporate risk just shifted. Under NIS2, cybersecurity is a governance issues. Data management and labelization must become foundational to compliance and resilience.

The question to ask is: Are you building visibility and control over your data now, or will you be reacting when regulators ask for incident reports, supply-chain logs, board-minutes with personal liability on the line?

I’ve started. Have you?

Share this article

Back To Top