A security incident occurs. Systems are affected, departments need to make decisions, customers and partners expect information, and legal reporting deadlines may already be in effect. At the same time, it is necessary to assess which systems should be prioritized, which measures should be approved, and which internal or external parties should be involved.
If there are no established procedures, roles, or decision-making processes in place for this scenario, virtually all questions suddenly converge on a single point: senior management. What may initially sound like a clear division of responsibility can actually become a risk in a crisis.
This is precisely where it becomes clear why NIS2 is not merely an IT project. Cybersecurity is a management responsibility. Senior management must ensure that the necessary structures are in place and oversee the implementation of risk management measures. At the same time, the organization must be structured in such a way that, in the event of an emergency, not every individual operational decision ends up on senior management’s desk.
NIS2 makes cybersecurity a management responsibility
The German implementation of the NIS2 requirements clearly establishes the responsibilities of senior management. For critical and important facilities, Section 38 of the BSIG requires executive management to implement the risk management measures specified in Section 30 and to oversee their implementation. In addition, there is a requirement for regular training to ensure that risks and risk management practices related to information security can be assessed at the management level.
This is an important shift in perspective: Information security cannot be treated as a purely technical task to be delegated to the IT department. Technical specialists, information security officers, and external service providers remain indispensable—but this does not absolve management of its organizational responsibility.
Good management accountability does not mean that CEOs must make every technical or operational decision themselves in the event of a crisis. On the contrary: Good governance establishes clear responsibilities, escalation procedures, and decision-making authority even before an incident occurs.
When everything falls on one person in an emergency
A major security incident generates numerous parallel tasks within a very short time. The technical cause must be investigated, business operations stabilized, and the impact on systems, data, and processes assessed. At the same time, customers, suppliers, government agencies, and other stakeholders may be affected.
Without a prepared incident and crisis management plan, an organizational bottleneck can quickly arise. Information must first be gathered, responsibilities are unclear, and nearly every decision is escalated to higher-ups. Management is then expected to simultaneously set priorities, grant approvals, coordinate communication, and assess the overall situation.
The problem is not a lack of willingness to make decisions. The problem is the sheer number of decisions and their interdependencies. Under time pressure, there is an increased risk that information will be missing, actions will be delayed, or decisions will not be documented in a sufficiently traceable manner.
1. Time Pressure Instead of Predictability
If you wait until a security incident occurs to clarify roles, contacts, and decision-making processes, you’re starting too late. Under normal conditions, you can define responsibilities, test reporting channels, and run through scenarios. In a crisis, the same questions must be answered within a very short time.
Preparation, therefore, does not create additional bureaucracy, but rather enables swift action. A clear process defines who assesses an incident, what decisions may be made at the operational level, when management is involved, and what information they need to make their decisions.
2. Lack of Traceability
NIS2 does not merely require appropriate risk management measures; affected organizations must also document their compliance. This makes traceability an essential component of a robust security organization.
In the context of an audit or incident, this otherwise creates a practical problem: Practices that are followed internally in some way but have neither been clearly described nor documented in a traceable manner are difficult to substantiate reliably after the fact.
Documentation should therefore not be viewed as an end in itself. When properly structured, it provides guidance in day-to-day operations while also serving as the necessary evidence for management, auditors, and regulatory authorities.
3. Reporting and Registration Requirements Require Predefined Processes
For companies covered by NIS2 or the BSIG, registration and reporting obligations are among the specific regulatory requirements. In the event of significant security incidents, tiered reporting processes with tight time frames come into effect.
In an emergency, such deadlines can only be reliably met if it has been clarified internally in advance who will assess an incident, who will gather the necessary information, who will prepare reports, and what approvals are required.
If these processes are lacking, an organizational scramble begins at the most critical moment: Who is responsible? What information is available? Who is authorized to communicate? Who documents the decision? It is precisely these inefficiencies that can cost valuable time.
4. Liability and Reputational Risks Affect Senior Management
Under NIS2, management responsibility is not merely an abstract add-on. Section 38 of the BSIG explicitly links the duties of senior management to the implementation and monitoring of risk management measures. Breaches of duty can—depending on the specific case and the respective legal form—trigger liability issues vis-à-vis the organization itself.
In addition to regulatory and legal risks, reputation plays an equally important role. A security incident becomes particularly problematic for customers and partners when, in addition to the technical event, organizational chaos becomes apparent: contradictory communication, unclear responsibilities, or avoidable delays.
A well-prepared organization therefore does more than just reduce compliance risks; it helps the company act in a controlled and transparent manner, even under pressure.
Good processes take the pressure off management
The key shift in perspective is this: managerial responsibility does not mean deciding everything yourself. It means ensuring that the company is capable of making decisions.
This includes clearly defined roles and responsibilities, defined escalation levels, a robust incident and crisis management system, documented communication and reporting channels, and regularly reviewed risk management measures.
Ideally, in a crisis, senior management does not have to address every individual operational issue. Instead, it receives a structured overview of the situation and makes decisions only where management decisions are actually required. Technical and operational tasks remain the responsibility of the designated roles.
This turns compliance into an organizational advantage: decisions are made faster, responsibilities are clearer, and business operations become more resilient.
Inaction is not a neutral state
The requirements of NIS2 highlight what good risk management demands anyway: responsibilities must be clarified, risks assessed, security measures implemented, and security incidents managed effectively at the organizational level.
Therefore, putting off necessary tasks does not automatically save effort. The effort is merely postponed to the worst possible time—a situation in which time, information, and attention are already in short supply.
This creates organizational, legal, and strategic risks for management. Preparation, on the other hand, enables planning and ensures that responsibilities can be fulfilled without turning management into an operational bottleneck in the event of a crisis.
Conclusion
NIS2 is not a task that can be completed simply by implementing a new policy or an additional IT tool. What matters most is how cybersecurity is embedded within the company’s organizational structure.
A robust structure ensures that, in the event of a security incident, not all decisions are concentrated at the executive level. It establishes clear responsibilities, transparent processes, and the necessary decision-making capacity under time pressure.
PECS-WORK helps companies translate regulatory requirements into practical frameworks—from cybersecurity and risk analysis to process and system structuring, as well as clear lines of responsibility and robust procedures for emergencies.