TURGERLEGAL - Expertise. Reliability. Dedication

Managing director liability in the event of cyberattacks and data leaks: NIS2 and reporting obligations

Specialist article in corporate law

Management liability in the event of cyberattacks and NIS2

A cyberattack brings IT systems to a standstill, customer data falls into the wrong hands, and the question of liability arises. Since December 6, 2025, the NIS2 Implementation Act has been in effect in Germany, significantly tightening cybersecurity regulations. For managing directors, this means they face personal liability in the event of cyberattacks and data leaks.

The new regulations affect not only traditional operators of critical infrastructure, but also approximately 29,500 companies from 18 different sectors. Section 38 of the reformed BSI Act explicitly declares cybersecurity a management responsibility. In addition, there are strict reporting obligations to the BSI and, in the event of data breaches, to the data protection authority.

This text explains when your company falls within the scope of application, what obligations management has, what reporting deadlines must be met in the event of a security incident, and how liability risks can be limited. This will help you maintain an overview even in a crisis and effectively fulfill your responsibilities as managing director.

What the NIS2 regulation means for managing directors since December 2025

The NIS2 Implementation Act transposed the European NIS2 Directive into national law and comprehensively restructured the BSI Act. The law has been directly applicable since December 6, 2025. Affected companies are obligated to comply with all requirements from this date onward, without any transition period.

Whether a company falls under the regulation depends on the specific sector and the company size. A distinction is made between particularly important and important establishments. Particularly important establishments in the relevant sectors typically include companies with at least 250 employees or an annual turnover exceeding €50 million, combined with a balance sheet total of more than €43 million. Important establishments are usually companies with at least 50 employees or an annual turnover exceeding €10 million.

A total of 18 sectors are covered, including energy, healthcare, transport, manufacturing, chemicals, food, and IT service providers. Unlike previous regulations, numerous medium-sized enterprises are now also included. Affected organizations are required to register with the BSI (Federal Office for Information Security), implement risk management measures, and report significant security incidents. Assessing one's own vulnerability is therefore the starting point for achieving NIS2 compliance.

A common difficulty is registration. Affected companies were required to register via the BSI's reporting portal; this initial deadline has now passed. Failure to register constitutes a separate offense and must be rectified immediately. Those who misjudge their eligibility lose valuable time and expose themselves to unnecessary risk.

Managing director liability according to § 38 BSIG: approval, monitoring, further training

At the heart of the newly regulated responsibilities is Section 38 of the reformed BSI Act. This section obligates the management bodies of particularly important and important institutions to implement the risk management measures pursuant to Section 30 of the BSIG and to monitor their implementation. Furthermore, they are required to participate in regular continuing education courses in the field of cybersecurity.

These obligations are personal in nature and cannot be fully delegated. While the practical implementation can be entrusted to an IT manager or an external service provider, the final responsibility for approval and oversight remains with management. Simply relying on the IT department to take care of this will no longer be sufficient.

If the management fails to comply with these obligations, it is liable to its own company for any damages caused through negligence. Section 38, paragraph 2 of the German Federal Financial Supervisory Authority (BaFin) refers in this regard to the provisions of corporate law regarding liability, specifically Section 43 of the German Limited Liability Companies Act (GmbHG) for limited liability companies (GmbHs) and Section 93 of the German Stock Corporation Act (AktG) for stock corporations (AGs). This is an internal liability: The company is entitled to assert claims for recourse against the managing director if avoidable damage has occurred. This liability cannot be excluded by either the articles of association or by agreements within the company.

This responsibility is not fundamentally new: it clarifies the existing duty of care of company management. If several managing directors are appointed, the obligation applies in principle to all members of the management body. If the implementation was not monitored by anyone, no one can claim that someone else was responsible. A clear division of responsibilities does not absolve any member of the duty to monitor others.

Reporting obligations after cyberattacks: 24 hours, 72 hours and one month

If a significant security incident occurs at an affected institution, a multi-stage reporting obligation to the BSI (Federal Office for Information Security) is triggered. An initial early warning must be issued within 24 hours of becoming aware of the incident. A more detailed report with an initial assessment of the incident is required within 72 hours. A final report must be submitted no later than one month after the incident.

The crucial factor is the start of the deadline. The 24-hour period begins when the company becomes aware of the incident, not only after the events have been fully investigated. This creates considerable time pressure in the first few hours of an attack, while technical defenses must simultaneously be implemented.

An incident is considered significant, in particular, if it causes serious operational disruptions or financial losses, or if it can adversely affect other people through substantial damage. A functioning internal reporting process with clearly defined responsibilities is therefore of paramount importance. Anyone who fails to meet the reporting deadline risks a separate fine, regardless of how the incident is handled.

The reports are submitted via the BSI's designated portal. In addition to the initial report, the BSI may request interim reports and, upon request, further information. Companies should provide the necessary access details, contact information, and responsibilities in advance to avoid wasting time on organizational clarifications in an emergency.

Data breaches and GDPR: the second reporting obligation to the data protection authority

If a cyberattack affects personal data, a second, independent obligation under data protection law applies in addition to the NIS2 reporting requirement. According to Article 33 of the GDPR, a data breach must generally be reported to the competent data protection supervisory authority within 72 hours.

If a data breach poses a high risk to the affected individuals, they must be additionally informed in accordance with Article 34 of the GDPR. A ransomware incident involving the leakage of customer data can therefore trigger several reporting obligations simultaneously: one to the BSI (Federal Office for Information Security) under NIS2 and one to the data protection supervisory authority under the GDPR.

Both procedures are aimed at different recipients, have different deadlines and requirements, but practically overlap in time. Anyone who complies with only one of the two obligations in a serious situation risks additional fines. A coordinated reporting strategy that combines IT security and data protection is therefore essential.

The data protection deadline also begins when the breach becomes known. If the full extent of the breach cannot yet be assessed at that time, an initial report with the information already available is permissible, which can be supplemented later. Thorough documentation of the incident forms the basis for both procedures.

Overview of fines, professional bans and sanctions

Violations result in substantial sanctions. According to Section 65 of the German Federal Office for Information Security Act (BSIG), particularly important institutions can be fined up to €10 million or 2 percent of their worldwide annual turnover – whichever is higher. Important institutions face fines of up to €7 million or 1.4 percent of their annual turnover.

If the breaches of duty also involve data protection regulations, fines under the GDPR are added, which can amount to up to €20 million or 4 percent of the company's global annual turnover. Both sanction systems apply concurrently. Furthermore, the BSI (Federal Office for Information Security) is authorized to temporarily prohibit responsible managers from performing their management duties in the case of particularly important institutions.

In addition, personal liability pursuant to Section 38 of the German Federal Office for Information Security Act (BSIG) applies. Many companies protect themselves with D&O insurance. However, the scope of coverage does not encompass all consequences. Direct fines against the company, ransom demands, or damages resulting from business interruptions are typically excluded. The actual extent of the insurance coverage therefore warrants careful examination.

Furthermore, the separation of responsibilities must be considered. Fines under the BSI Act primarily affect the institution itself, whereas liability under Section 38 of the BSIG applies to the management internally. Both levels can relate to the same incident, and their economic consequences are cumulative.

Mandatory areas of risk management according to § 30 BSIG

The core of the technical requirements is Section 30 of the German IT Security Act (BSIG). This provision mandates comprehensive risk management, encompassing technical and organizational measures that meet current technological standards and are proportionate to the respective risk. The law specifies various areas that must be addressed:

  • Risk analysis: Develop and maintain up-to-date security concepts for information systems.
  • Incident management: Identifying, processing, and documenting security incidents.
  • Business continuity: Ensure backup management, emergency and crisis management.
  • Supply chain: ensuring the security of relationships with suppliers and service providers.
  • System security: Protecting the procurement, development, and maintenance of systems, including vulnerability management.
  • Access and personnel: Organize access control, personnel security, and IT resource management.
  • Cryptography: Use encryption and multi-factor authentication.
  • Cyber hygiene: Implement training and verify the effectiveness of all measures.

These precautions must not only be implemented, but also documented and their effectiveness regularly reviewed. In the event of a dispute, the company must be able to prove that it has complied with the requirements. This evidence also serves to protect management in the event of liability claims.

What the NIS2 Implementation Act means for managing directors since December 2025

The NIS2 Implementation Act transposes the European NIS2 Directive into national law and fundamentally amends the BSI Act. It has been in effect without a transitional period since December 6, 2025. Affected companies are obligated to comply with the new requirements from the date of entry into force; no transitional period for adaptation is provided by law.

Whether a company is affected depends on its industry and size. The law differentiates between particularly important and important establishments. In the covered industries, particularly important establishments are typically companies with at least 250 employees or more than €50 million in annual revenue and a balance sheet total exceeding €43 million. Important establishments are typically companies with at least 50 employees or more than €10 million in annual revenue.

A total of 18 sectors are covered, including energy, healthcare, transport, manufacturing, chemicals, food, and IT service providers. Unlike the previous legal situation, numerous medium-sized enterprises are now also included in the scope of application. Affected organizations are required to register with the BSI (Federal Office for Information Security), implement risk management measures, and report significant security incidents. Therefore, assessing eligibility is the first step in any NIS2 compliance process.

A practical hurdle is the registration process. Affected companies were required to register via the BSI's reporting portal; the initial registration deadline has now passed. Failure to register constitutes an independent offense subject to a fine and must be rectified immediately. Those who misjudge their eligibility will waste valuable time and incur unnecessary risk.

Make an inquiry now
We will be happy to provide you with comprehensive, personal advice on your concerns.

Area of law

AdobeStock_284557154-Mobile

lawyer

Volkan-Erogan

Happy to help you

Contact

Your law firm TURGERLEGAL.

address

Grugaplatz 2 (c/o Regus)
45131 Essen

Opening hours

Mon. – Fri. 10:00 – 17:00

Contact

en_US