The duty of care is a board-level control question
Executive directors approve risk-management measures and supervise implementation. They need enough information to understand why measures are appropriate, which residual risks remain and whether the controls operate effectively.
Supervisory boards use the same risk and evidence picture to assess direction, progress and exceptions within their oversight role.
Ten measure areas as a governance framework
The NIS2 measure areas cover risk analysis and policy, incident handling, continuity and crisis management, supply-chain security, secure acquisition and maintenance, effectiveness assessment, cyber hygiene and training, cryptography, personnel and access security, asset management and strong authentication and communication.
The board does not operate each control, but should understand coverage, ownership, proportionality and evidence.
Use an all-hazards risk analysis
Assess cyber, physical, technical, human and supplier causes that can affect network and information systems or critical services. Scenarios help connect the measure areas and reveal shared dependencies and recovery priorities.
Begin with the interests that require protection
These interests help the board compare impact and explain why one measure or scenario receives priority.
- continuity of critical services;
- safety of people, products and operations;
- financial position and contractual commitments;
- reputation and stakeholder trust;
- personal data, confidential information and system integrity.
What should be demonstrably organised?
Maintain the risk assessment, decisions, owners, policies, operational evidence, tests, incidents, supplier reviews, exceptions and improvement actions. Management reporting should show whether the complete control cycle works and where intervention is needed.
Frequently asked questions
What is the NIS2 duty of care?
It is the obligation to manage cybersecurity risk through appropriate and proportionate measures across the required areas.
Must the board approve every individual control?
The board approves the risk-management measures and direction at an appropriate level and supervises implementation; operational details can be delegated within clear governance.
How can effectiveness be demonstrated?
Through tests, exercises, audits, reviews, metrics, incidents, corrective actions and other evidence relevant to the control and risk.
Review the duty of care through a board lens
Use the Masterclass to discuss risk, proportionality, evidence, effectiveness and the information that boards need for oversight.
Discuss the appropriate training route