- Meaning
- Leadership, responsibility and decision structures
- Link to NIS2
- Cybersecurity is a leadership duty
- Liability
- Management bodies can be held liable
- Related
- GRC, management body
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is governance?
Governance describes the overarching steering level of an organisation: it sets out who is responsible for security and compliance and how decisions are taken, approved, documented and monitored. Governance makes sure that security is steered deliberately and not left to chance or to individual IT staff. In contrast to the concrete work of Risk management, which deals with individual risks, governance sets the frame: objectives, roles, responsibilities and reporting lines. It is the strategic bracket around risk management and compliance.
Governance under NIS2
NIS2 makes cybersecurity expressly a task for the leadership. Under Article 20 the management body must approve the risk management measures, oversee their implementation and take part in regular training itself. The directive thereby moves cybersecurity from a purely technical question to a leadership and oversight task. Governance is the mechanism that translates these legal expectations into concrete responsibilities, approval processes and evidence – the precondition for an organisation being able to demonstrate its NIS2 duties in an audit-proof way.
Liability of the management body
Responsibility can no longer be handed downwards. Article 20 provides that the members of the management body can be held liable for infringements; on top of that, Article 34 sets minimum fine ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, whichever is higher, and Member States may set higher amounts. Because the directive has applied since 18 October 2024 and each Member State transposes it on its own timetable, the management body should be able to show that it has not simply nodded measures through once, but has approved them, overseen them and, where necessary, adjusted them on an ongoing basis. Operational tasks may sit with IT. The ultimate responsibility stays at the top. Good governance lowers the liability risk, because decisions, approvals and controls are documented without gaps.
Governance, risk and compliance
Governance is the first pillar of GRC. Together with risk management and compliance with legal duties it forms the frame for compliance that is actually lived – written down in Security policies. Picture a mid-sized energy supplier that sets up a quarterly security committee once NIS2 applies to it: the management has the risk status reported there, approves measures and minutes every decision, and those minutes later serve as evidence. Talking alone is not enough. Only the minutes turn an intention into solid proof that cybersecurity really is steered at leadership level.
What do you need to do?
Governance stays abstract until it is translated into meetings, approvals and minutes. These five steps make a start:
- Name the ultimate responsibility: Record in writing that the management body carries the responsibility for cybersecurity – not the IT department.
- Introduce a fixed reporting rhythm: Report the risk status to the leadership at least quarterly and minute the meeting.
- Document approvals: Record every approval of risk management measures with the date, the body and the decision, so that it can be evidenced.
- Evidence the leadership training: Schedule the training of the management body that NIS2 requires and archive the attendance records.
- Check your registration: Ask your national authority whether your entity has to register, and in what form – the channel and the deadline are set by each Member State.
Who decides, who implements?
Governance depends on clearly assigned roles. The overview below separates the decision from the implementation:
| Task | Decides | Implements |
|---|---|---|
| Approve risk management measures | management body | CISO / IT security |
| Oversee implementation | management body | Compliance / internal audit |
| Operate technical protective measures | CISO / head of IT | IT team / service provider |
| Notification to the competent authority (24 h / 72 h / 1 month) | management body | Incident response / reporting officer |
Further reading: European Commission – NIS2 Directive
Frequently asked questions
What does governance mean?
Governance covers the leadership, responsibility and decision structures with which an organisation steers security and compliance. It sets out who carries which risks, who approves measures and how their effectiveness is monitored and documented. Governance is therefore the strategic bracket around risk management and compliance. It makes sure that security is steered deliberately and not left to chance or to individual IT staff – with clear objectives, roles and reporting lines.
Why does governance matter under NIS2?
The NIS2 Directive puts the leadership expressly under obligation. Article 20 requires the management body to approve the risk management measures, to oversee their implementation and to take part in regular training. Cybersecurity thereby moves from a purely technical question to a leadership task. Article 34 sets minimum fine ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts. On top of that, members of the management body can be held liable for infringements.
Can cybersecurity be delegated to IT?
Operational measures can be delegated to the IT team or to service providers, but the ultimate responsibility for cybersecurity cannot. It stays with the management body, which has to understand, steer and evidence security even when the technical work sits elsewhere. NIS2 requires the leadership to approve measures and to oversee their implementation. Good governance lowers the liability risk, because decisions, approvals and controls are documented without gaps and can therefore be produced in an inspection.