NIS2 and joint and several liability: what public-sector directors should and should not fear
Published on June 5, 2026 · Updated on August 4, 2026
This article is general information about laws and regulations, not legal advice.
NIS2 raises the same question at many public organisations: will directors soon become personally or even jointly and severally liable when cybersecurity falls short? That question is understandable, but it mixes up two things you should keep sharply apart. The formal cybersecurity legislation (NIS2 and the Dutch Cybersecurity Act) imposes obligations on the organisation and its board: approving measures, overseeing implementation and having sufficient knowledge to assess cyber risks. The political and administrative accountability (answering to the council, provincial assembly or parliament when things go wrong) runs through the existing national frameworks and does not fundamentally change under NIS2. Whoever conflates these two tracks overestimates the legal risk and underestimates the governance risk.
Even so, the concept of joint and several liability deserves nuance, certainly for public-sector directors. NIS2 does not introduce a general, automatic joint and several liability for every mayor, alderman, provincial executive, water-authority chair, director or government official. For public-sector bodies, national law on the liability of public institutions, civil servants and elected or appointed officials remains decisive. Digitale Overheid (the Dutch digital government programme) states this explicitly: NIS2 brings no new liabilities for government directors beyond what already existed; liability for, say, gross negligence already existed before NIS2.
The core message: board-level responsibility must be given demonstrable substance. Anyone who has no view of the risks, has no appropriate measures taken and holds no evidence of follow-up stands weaker from a governance and regulatory perspective.
Three actions you as a director must take in any case:
- Complete the mandatory cybersecurity training and keep your knowledge current: NIS2 requires directors to be able to assess cyber risks and control measures themselves. The Dutch Cybersecurity Act (Article 24(3)) gives directors two years after entry into force to do so, which with entry into force on 15 August 2026 means by 15 August 2028 at the latest, and requires a certificate showing participation. The training may be provided externally or internally, for example by the CISO. Who counts as "the board" at public authorities is defined in Article 24(12): for ministries the minister, for independent administrative bodies of central government the body itself, for provinces the provincial executive (gedeputeerde staten), for municipalities the municipal executive (college van burgemeester en wethouders), for water authorities the executive committee (dagelijks bestuur), and for joint arrangements the executive committee of the public body, the board of the shared-services organisation or the joint body, respectively.
- Explicitly approve the security measures and record that decision: approval is a statutory board task that you cannot leave to the CISO or IT.
- Organise demonstrable oversight of implementation: a fixed reporting rhythm on risks, remediation and outstanding items, with a traceable record of what was decided and verified.
What does "joint and several" actually mean?
Joint and several liability means that each individual board member can be held to account for the entire damage. Whoever pays can subsequently seek recourse against fellow board members, but the risk initially sits with the individual member. That is different from personal liability, where someone is held to account only for their own acts or omissions, and from collective responsibility, where the board accounts for itself as a body. The concept comes from civil-law director liability at private entities, the sphere of Article 2:9 of the Dutch Civil Code: in the event of improper management, each director of a legal entity is in principle liable for the whole, unless no serious blame can be attached to an individual member and that member has not been negligent in taking measures to avert the consequences of improper management. That frame of reference helps to properly weigh the nuance for public-sector directors.
What does NIS2 say about director liability?
Article 20 of the NIS2 directive forms the heart of the governance obligation. The management bodies of essential and important entities must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements by the entity of Article 21. Article 21 contains the duty of care: appropriate and proportionate technical, operational and organisational measures to manage risks to network and information systems and to prevent or limit the impact of incidents.
"Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article."
— Directive (EU) 2022/2555 (NIS2), Article 20(1), first sentence
For public-sector directors, Article 20(1), second sentence, is especially important. The directive provides that this governance obligation is without prejudice to national law as regards the liability rules applicable to public institutions, as well as the liability of public servants and elected or appointed officials. This means that the Dutch implementation and existing administrative-law, civil-service-law, civil-law and political accountability mechanisms remain decisive for the concrete question of liability.
| Topic | What NIS2 makes clear | What this means in practice |
|---|---|---|
| Approval of measures | The board must approve cybersecurity measures. | Cybersecurity belongs at the board table. |
| Oversight of implementation | The board must oversee implementation. | There must be reporting, escalations and progress decisions. |
| Training obligation | Directors must build up knowledge and skills. | Cyber risks must be understood and assessed at board level. |
| Liability | Management bodies can be held liable for infringements. | For public-sector directors, the national liability context remains decisive. |
| Provability | Oversight and accountability presuppose that measures and decisions are demonstrable. | Organisations must be able to show records, decisions, measurements and follow-up. |
Public sector: no panic, but responsibility
Digitale Overheid provides an important clarification for public-sector bodies. According to this guidance, the liability provision of the NIS2 directive does not apply directly to government bodies, because the directive states that national law on the liability of civil servants and elected or appointed government officials is not affected.
The heaviest NIS2 sanction does not apply to government directors either. The power to request the temporary suspension of a director or a temporary ban on exercising managerial functions is explicitly excluded for public administration entities, both in the directive (Article 32(5)) and in the Dutch Cybersecurity Act. Other enforcement instruments, such as binding instructions, an order subject to a penalty payment and administrative fines, can certainly be applied to government organisations. Those fines are not symbolic: the NIS2 directive prescribes for essential entities a maximum fine of at least EUR 10 million or 2% of worldwide annual turnover (whichever is higher) and for important entities at least EUR 7 million or 1.4% (Article 34); the Dutch Cybersecurity Act adopts these amounts in Articles 80 and 87 (for infringements of the duty-of-care and notification provisions). According to the Digitale Overheid guidance, supervision of the government sector is assigned to the Rijksinspectie Digitale Infrastructuur; the act exempts public administration entities from the enforcement track that can end in the suspension of certifications or of board members (Articles 76 to 78, via Article 79); the administrative fine continues to apply to public administration entities.
That does not mean public-sector directors have nothing to do. On the contrary. Municipalities, provinces, water authorities and central government are named in the Digitale Overheid guidance as entities designated under NIS2 as essential entities. The size criteria that apply to many private sectors do not apply to government bodies. For public organisations, existing accountability structures are moreover taken into account: the intention is to give substance to the duty of care for government organisations through the BIO, and it is being examined how ENSIA can be adapted for NIS2 supervision. One caveat applies here: as self-assessments, BIO and ENSIA demonstrate that the paperwork is in order. An external measurement demonstrates whether reality matches that paperwork: what an attacker actually sees, measured from the outside, with a timestamp.
The message is therefore twofold. There is no reason for legal panic about automatic joint and several liability. There is every reason to organise board-level cyber care demonstrably. Directors cannot hide behind the CISO or IT department. The National Coordinator for Counterterrorism and Security (NCTV) emphasises that the board remains ultimately responsible for cybersecurity, even when tasks have been assigned to a CISO.
The Dutch Cybersecurity Act: directors must be able to participate
The NIS2 directive, adopted at the end of 2022 to strengthen the digital and economic resilience of European member states, has been transposed in the Netherlands into the Dutch Cybersecurity Act (Cyberbeveiligingswet). The Dutch Senate approved the bill on 7 July 2026; the act was published in Staatsblad 2026, 187 and enters into force on 15 August 2026. The Cybersecurity Act thereby replaces the Network and Information Systems Security Act (Wbni). Organisations covered by the act must also register via mijn.ncsc.nl; see the NCSC's explanation of the registration obligation.
The NCTV makes clear what this means at board level. Under the Cybersecurity Act, cybersecurity counts as a topic for the entire organisation. The board is responsible for policy and compliance, must have demonstrable knowledge and skills regarding risks to network and information systems, must have insight into risks and take appropriate measures, and must speak regularly with the CISO.
| Board-level obligation | Practical implementation | Evidence that must be available |
|---|---|---|
| Build up knowledge | Board training, periodic updates and CISO conversations. | Certificates, agendas, minutes and decisions. |
| Understand risks | Insight into critical processes, assets, suppliers and threats. | Risk register, asset overview, supply-chain analysis and threat picture. |
| Approve measures | Decision-making on duty-of-care measures, budget and priorities. | Board decisions, justification, risk appetite and exceptions. |
| Oversee implementation | Periodic reporting on progress, vulnerabilities and incidents. | Dashboards, remediation SLAs, audit trail and escalations. |
| Continuously improve | Re-checking after incidents, audits and scans. | Improvement plans, re-scans, lessons learned and management reviews. |
For directors, the word demonstrable is especially important. Every organisation must be able to explain why the chosen measures are appropriate and proportionate. Without up-to-date facts about the digital attack surface, vulnerabilities, supplier dependencies and remediation status, that explanation remains vulnerable.
The public-sector cybersecurity duty of care: from policy to measurable control
Article 21 of NIS2 obliges organisations to take appropriate and proportionate measures. The directive mentions, among other things, risk analysis, security policy, incident handling, business continuity, supply-chain security, security in acquisition, development and maintenance, policy for measuring effectiveness, cyber hygiene, training, cryptography, personnel security, access control, asset management, multi-factor authentication and secure communication.
The Rijksinspectie Digitale Infrastructuur (RDI, the Dutch Digital Infrastructure Inspectorate) emphasises that risk management under the Cybersecurity Act requires an integrated and continuous approach. Organisations must map risks, choose solutions, regularly check whether those solutions work and adjust where necessary. Supply-chain risks and supplier dependency must also be an explicit part of the risk analysis and the cybersecurity policy.
For public-sector directors, this is relevant because public service delivery is becoming increasingly dependent on digital supply chains. Municipalities, provinces and water authorities are not only responsible for internal office automation. They manage digital service desks, data flows, case- and document-management systems, connections to national facilities, supplier portals and sometimes operational technology. A vulnerability in an externally visible system can therefore have board-level consequences for continuity, privacy, trust and service delivery.
Why evidence from vulnerability management is relevant at board level
A board can only oversee cybersecurity when the information is reliable, up to date and understandable. A policy document or annual audit is in practice often insufficient to keep that picture current. Cyber risk changes continuously: new services come online, suppliers adjust configurations and new vulnerabilities are published daily. The threat picture changes constantly; the NCTV publishes the annual Cybersecuritybeeld Nederland (Cyber Security Assessment Netherlands) on this.
Vulnerability monitoring that builds up its evidence as the work is done helps public organisations make that dynamic governable. The essence is that every finding is registered and linked to context, owner, priority, decision and re-check. That makes the difference between "we scanned once" and "we can demonstrate what our current risk picture is and what we are doing about it".
| Board-level risk | Without demonstrable monitoring | With evidence-first monitoring |
|---|---|---|
| Unknown attack surface | Forgotten domains, test environments or open services remain out of view. | New subdomains, open ports and certificate changes appear in the next scan round, with the date of first observation. |
| Insufficient prioritisation | Teams work on low risks while critical exposure persists. | Every finding gets a severity and an owner; critical exposure sits at the top of the report. |
| Weak accountability | The board cannot substantiate which choices were made. | Decisions, exceptions and remediation actions can be looked up per finding, with date and decision-maker. |
| Supply-chain uncertainty | Supplier risks only become visible during incidents. | Externally visible supplier services and connections sit in the same risk picture as the organisation's own systems. |
| Audit or regulatory pressure | Information must be reconstructed after the fact. | Every scan result has a timestamp and a history; reconstruction after the fact is not needed. |
An example scenario for illustration, not a description of a customer case: ahead of the go-live of a new case-management system, a municipality sets up a test environment on a separate subdomain. After go-live, that environment is not cleaned up and remains externally reachable, without the security updates of the production environment. Continuous monitoring of the attack surface flags such a forgotten subdomain as soon as it becomes externally visible, and records when it was found and when it was resolved.
Exposentry aligns with this by approaching vulnerability monitoring as a traceably substantiated process. The goal is to give directors reliable management information. The CISO or security lead remains the substantive advisor; the board receives the evidence it needs to make choices and exercise oversight.
Exposentry builds on OpenKAT, the open-source security scanner that originates from the Dutch government. Edward Hasekamp, who develops Exposentry, contributes to OpenKAT himself. For public organisations this is relevant: the underlying tooling is transparent and verifiable, and connects to software already in use within government.
What should be on the board table?
An effective board discussion about NIS2 is about trend, priority, residual risk and decision-making. The NCSC advises directors to discuss with the CISO: security culture, knowledge, responsibility, board agenda, risk assessment, risk treatment, "continuous in control", and laws and regulations.
In practice, many public organisations choose a fixed quarterly rhythm for this report. For major incidents, critical vulnerabilities or board-level risk acceptance, escalation must take place more quickly. A short report will do, as long as it is consistent.
| Board-report component | Example question |
|---|---|
| Current attack surface | Which new or unknown external assets have been discovered? |
| Critical vulnerabilities | Which findings affect essential service delivery or sensitive data? |
| Remediation status | Which risks have been resolved within SLA and which have not? |
| Risk acceptance | Which risks are we accepting temporarily, why and until when? |
| Supply-chain risks | Which suppliers or connections require board-level attention? |
| Incident readiness | Have backup, incident response and continuity plans been tested? |
| Evidence position | Can we demonstrate what was found, decided, carried out and re-checked? |
What the board needs is sufficient knowledge to ask the right questions, weigh priorities and make decisions about money, capacity and risk appetite.
Conclusion: preventing liability starts with demonstrability
For public-sector directors, NIS2 is no reason to panic about automatic joint and several liability. The directive leaves national rules on the liability of public institutions, civil servants and elected or appointed officials intact. Digitale Overheid moreover confirms that NIS2 introduces no new liabilities for government directors beyond what already existed.
But that nuance must not be read as a free pass. NIS2 and the Cybersecurity Act make cybersecurity emphatically a board-level matter. Directors must understand risks, approve measures, oversee implementation, follow training and stay demonstrably in dialogue with the CISO.
The question that matters at board level: "Can I demonstrate that we know our cyber risks, have chosen appropriate measures and check follow-up?" How to organise that demonstrability step by step is covered in the NIS2 roadmap for public-sector boards.
Exposentry helps public organisations with the latter. By monitoring the digital attack surface and vulnerabilities evidence-first, the factual basis for board-level cyber care is created: current, traceable and suitable for dialogue between board, CISO, auditor and regulator.
Sources
- EUR-Lex, Directive (EU) 2022/2555, Article 20: eur-lex.europa.eu
- Digitale Overheid, "Veelgestelde vragen Cyberbeveiligingswet": digitaleoverheid.nl
- EUR-Lex, Directive (EU) 2022/2555, Article 21: eur-lex.europa.eu
- EUR-Lex, Directive (EU) 2022/2555, Article 34: eur-lex.europa.eu
- NCTV, "Bestuurlijke verantwoordelijkheid en trainingsplicht voor bestuurders": nctv.nl
- Rijksinspectie Digitale Infrastructuur, "Risicomanagement en cyberbeveiliging": rdi.nl
- NCSC, "Vragen die je als bestuurder kunt stellen aan de CISO": ncsc.nl
- NCTV, "Cybersecuritybeeld Nederland": nctv.nl
- Rijksoverheid, "Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht" (news item, 7 July 2026): rijksoverheid.nl
- Staatsblad 2026, 187 (Cyberbeveiligingswet): zoek.officielebekendmakingen.nl
Written by Edward Hasekamp, founder of Exposentry and collaborator on the open-source OpenKAT project. See the project on GitHub and the profile at github.com/hasecon. Exposentry provides EU-sovereign, forensically substantiated vulnerability monitoring based on OpenKAT. More articles in the Knowledge base.