NIS2 moves cyber to the executive layer
NIS2 requires cybersecurity to be governed as part of the enterprise operating model. That means executive accountability for decisions, risk acceptance, incident oversight and the ability to demonstrate action.
- Board and process-owner accountability model.
- Risk management, continuity and service resilience.
- Incident reporting and ICT supplier control.