Until 2024, many German managing directors saw cyber security as a job for "IT" or "the insurance". In 2026 that view is over. Soft law did not end it. Hard liability case law did.
Three Legal Bases That Lock Together
- §43 GmbHG (duty of care of an orderly businessman): Directors are liable with their own private assets for harm caused by a breach of duty. A cyber incident without written-down security measures counts as a breach of duty.
- §93 AktG (board duty of care): The same rule for stock corporations. On top, the burden of proof is reversed. The board must prove that it took due care.
- NIS-2 Art. 20: Management bodies are clearly in charge of approving cyber risk measures and keeping watch over them. A breach can lead to personal sanctions.
What is new is how these fit together. NIS-2 makes the duty of the board explicit. §43 and §93 make it personal. "I didn't know" no longer works.
What a Court Accepts as Duty Fulfilled in 2026
- Risk list signed by the director: Updated each year. For each of the top 10 risks, it shows how you chose to treat it.
- ISMS built on a known standard: ISO 27001 or BSI IT-Grundschutz. An "own method" is only enough if you can show in writing that it is better.
- Incident response plan, tested: A tabletop exercise with the board once a year. The minutes go into the audit trail.
- Awareness program with proof: Phishing tests, training rates and proof of how well it works.
- Supplier risk checks (TPRM): NIS-2 Art. 21(2)(d) makes supply chain security a clear must.
- Audit trail of all key decisions: Who accepted which risk, when and why.
Say one of these is missing and an incident occurs. Then the board will struggle to prove it did its job. D&O insurance does not cover personal liability when a willful breach of duty is in play. And "no ISMS despite a NIS-2 duty" gets read in just that way.
The Cost Math That Wakes Directors Up
Take a real-world case. A mid-sized firm has 200 staff. Ransomware hits. It brings 5 days of downtime and €80,000 in ransom talks. The direct damage is about €1.2 M. A shareholder sues the directors for the money, saying the cyber measures were not good enough. With no written-down ISMS, the claim is sound.
Now the other side. An ISMS on a GRC platform (e.g. SecTepe.Core), plus self-hosted mail security with CTI and sandbox (SecTepe.Comm). The cost over 3 years is about €150–250 k. Risk drops a great deal, and the shield against liability is on record.
What Directors Should Do – This Month
- Check the status: Do you have a written ISMS? Did an outside party last check it? When?
- Ask for the top 10 risks: Get them from the CISO or IT lead, with the status of each. If the answer is "we have it in our heads", that alone is a finding.
- Book an incident response test: Run a tabletop exercise led by an outside host. Keep the minutes.
- Settle whether NIS-2 applies: Does it apply to us? Which sector and size class? Who is in charge of what?
- Read the D&O policy: What does it truly cover for cyber? Which clauses rule things out?
Compliance Mapping
- NIS-2 Art. 20: The board must approve cyber risk measures and watch over them.
- NIS-2 Art. 21: A list of minimum security measures (10 areas).
- §43 GmbHG / §93 AktG: Personal liability with a reversed burden of proof.
- BSI Standard 200-1/-2/-3: The known ISMS method in Germany.
- D&O standard clauses: Check whether "gross cyber negligence" is left out.
Conclusion
"Cyber is IT's job" was a poor line in 2018. In 2024 it was a risky one. In 2026 it can lead to personal bankruptcy. Some directors will not start an ISMS project in the next 12 months. They take on a liability risk that can badly hurt their own finances. The good news: an ISMS is doable and you can plan it. With the right platform, it is not the 18-month Excel project of the 2010s.