Reports
NCSC - NIS2 Directive Resources
Learn more
In this article, Brian Honan, Cybersecurity Expert, BH Consulting, discusses how new EU regulations are elevating cybersecurity to a board-level responsibility. He outlines directors’ growing accountability and the practical actions boards should take to strengthen governance and resilience.
For many years, cybersecurity has operated in a somewhat laissez-faire environment. Nearly every organisation claims that it “takes cybersecurity seriously”, although sadly, experience tells us some take it considerably less seriously than others. That unregulated approach is becoming increasingly difficult to sustain, particularly as our businesses, public services, critical infrastructure, and personal lives are now heavily dependent on technology. At the same time, cyberattacks, supply-chain compromises, and the rapid adoption of artificial intelligence are demonstrating how weaknesses in one organisation can quickly affect many others.
The European Union’s response is to make the digital world a more regulated, resilient, and ultimately more trusted environment. For directors, this means cybersecurity and technology risk are rapidly moving from matters traditionally delegated to the IT department into the realm of corporate governance and board accountability.
Directors are now facing an expanding collection of cyber-related EU legislation such as the revised Network Information Security Directive (NIS2), the Digital Operational Resilience Act (DORA), the Cyber Resilience Act (CRA), the AI Act, and the proposed Cybersecurity Act 2.0 (CSA2).
NIS2 focuses on the cybersecurity and resilience of essential and important organisations. DORA applies similar thinking specifically to financial services and their technology dependencies. The CRA introduces cybersecurity requirements throughout the lifecycle of any product with a digital elements including software and hardware products. The AI Act regulates the development and use of artificial intelligence according to risk, while the proposed CSA2 aims, amongst other things, to strengthen cybersecurity certification and address ICT supply-chain risk. It is tempting for a director to look at that list and ask: “Which of these actually applies to my organisation and why should I care?” That is an important question, but it is no longer the only question directors should be asking.
The common theme running through this legislation is accountability. Under NIS2, management bodies of regulated organisations must approve cybersecurity risk-management measures, oversee their implementation, and undertake appropriate training. Members of management bodies, including directors, can potentially be held liable where those obligations are not met.
DORA similarly places responsibility for ICT risk and operational resilience firmly with the management body of regulated financial entities.
The CRA and AI Act do not simply replicate NIS2's personal-liability provisions, but they introduce potentially significant regulatory, financial, operational, and reputational consequences for organisations that fail to manage their obligations appropriately.
The direction of travel should therefore be clear to every director that regulators increasingly expect organisations to demonstrate who is responsible, how risks are being managed, what decisions have been taken, and what formal evidence exists to support those decisions. In other words, saying “we take cybersecurity seriously” will no longer be enough. You will increasingly have to prove it.
This is potentially the bigger issue for many Irish businesses. Your organisation may not be directly regulated under NIS2 or DORA. You may not manufacture products covered by the CRA or develop high-risk AI systems. However, you customers may. A bank regulated under DORA must manage the risks associated with its technology suppliers. An organisation regulated under NIS2 must address cybersecurity risks in its supply chain. Organisations using AI will increasingly need assurance about the systems, data, and providers they depend upon. As a result, regulated customers will push many of their cybersecurity and assurance requirements downstream into their supply chains.
For an Irish business, the most immediate consequence of these laws may therefore not arrive in a letter from a regulator, but in a customer questionnaire, tender document, or contract. You could be asked to demonstrate your cybersecurity controls, incident response capability, data protection practices, AI governance, supply-chain security, and business continuity arrangements. Contractual requirements for reporting security incidents may become stricter and customers may demand independent evidence that your cybersecurity controls are effective. Failing to satisfy those requirements is not simply a compliance problem. It is now a business risk. If you cannot provide the assurance a major customer requires, you could lose that customer or find yourself excluded from future contracts.
Directors do not need to become cybersecurity engineers, AI specialists, or regulatory lawyers. They do, however, need sufficient understanding to ask appropriate questions and challenge the answers they receive. For many Irish companies, therefore, the commercial consequences of these regulations may arrive long before the regulatory consequences do
I recommend boards take these five practical steps:
Cybersecurity regulation is no longer something directors can leave solely to the IT department. Neither is AI governance, privacy, or digital resilience. The EU is steadily turning what was once considered good practice into an expectation of demonstrable governance. For directors, the objective should not simply be to avoid regulatory penalties or personal liability. It should be to ensure that, should something go wrong, you can demonstrate that you understood the risks, asked the right questions, made informed decisions, and took reasonable steps to protect the organisation. That is not just good cybersecurity governance. It is good corporate governance.
This article is the view of the author(s) and does not necessarily reflect IoD Ireland’s policy or position.
Brian Honan is the Founder and CEO of BH Consulting, an independent cybersecurity and data protection consultancy based in Dublin. Recognised internationally as a leading cybersecurity expert, Brian has more than 25 years' experience advising organisations, government agencies and multinational companies on information security, cyber resilience and data protection.
He is the founder of Ireland's first Computer Emergency Response Team (CERT), a special adviser to Europol's European Cybercrime Centre (EC3), and a regular speaker at major international cybersecurity conferences. Brian is also a published author and frequent contributor to industry publications on cybersecurity and governance.