Skip to content
NIS 2: cybersecurity is no longer an IT department thing 🛡️

NIS 2: cybersecurity is no longer an IT department thing 🛡️

3 September 2026·Sandro Lain
Sandro Lain

NIS 2 and cybersecurity

The fastest way to tell whether a company is ready for the NIS Decree is one question: “who signed off your security measures?”

If the answer is “the IT manager” or “our consultants”, the problem is not technical — it’s governance. Legislative Decree 138/2024, which transposes the NIS 2 Directive in Italy, says something very precise: the management and executive bodies — the board and the C-level — are liable for the security measures. With their names on the line.

And it’s not a bureaucratic detail. It’s the first time information security stops being “an IT department thing” and becomes a personal responsibility of the people who run the company.

Want the full picture? Scope, registration, measures, deadlines and the compliance checklist are in the practical guide: NIS 2 — Cybersecurity: the Italian Practical Guide.

Why now? The lesson of systemic risks 🔥

The first NIS Directive (2016) was more a warning than an obligation: few sectors, a vague perimeter, sanctions designed not to hurt anyone in particular. Then came Colonial Pipeline, SolarWinds, Log4j: incidents where a single entry point — one password, an unprotected pipeline, an unpatched library — disrupted services that are infrastructure for everyone.

The conclusion European lawmakers drew is simple and uncomfortable: the cybersecurity of a private company is no longer its own business. When an essential service provider goes down, the effect ripples to suppliers, customers, citizens and the State. The risk is systemic. And systemic risk, by definition, is not left to the discretion of the IT department.

The signature: the political idea behind the Decree ✍️

The real novelty of NIS 2 is not the security measures — most are just good engineering practice — but the signature mechanism. The Decree isn’t asking you to be better: it’s asking you to be accountable.

No more blank delegation, no more “we handed it to the consultants”. Those with the power to decide have the duty to approve the measures, oversee their implementation and get trained. And art. 38 goes all the way: accountability covers any natural person who represents the company, decides on its behalf or exercises control over it.

The reasoning is the GDPR one: compliance is not a cost to optimise, it’s a precondition. Whoever signs can no longer say “I didn’t know”.

The impact on companies: a boardroom topic 🏛️

There’s a practical, underestimated consequence: security lands on the board’s agenda. Risks mapped in the corporate risk register, security budget as a line item, periodic briefings at the top. Many managers see it as an annoyance; anyone who knows how companies actually work sees it as the only way things actually happen.

And there’s the commercial side: if you’re in the supply chain of a NIS entity — banks, energy, transport, public administration — the security questionnaires, incident-reporting SLAs and audits are coming anyway. Better to drive them than to suffer them. Compliance is becoming your passport to be a supplier.

The impact on developers: no more silent patches ⌨️

For developers the change is cultural before it’s technical. A significant incident must be notified to CSIRT on a precise timeline — early warning, updates, final report: no more patching quietly on a Friday and telling no one. Transparency becomes an obligation, not a choice.

Then there’s documentation: vulnerability management, identity, authentication, cryptography. Implementing it is not enough — you have to prove it, with evidence and procedures. Security by design stops being a slogan and becomes a delivery requirement, as verifiable as a test.

The real cost is not the fine 💸

Fines make the news, but they’re the smallest part of the bill. The real cost of an incident is service disruption, contractual penalties, customers who walk away because you no longer look reliable. The fine is just the footnote that makes it readable.

NIS 2’s merit is making this risk visible to the people who can act on it: those at the top no longer have to trust a vendor’s report. They must answer for it — and therefore understand it. It’s a transfer of awareness, not just of accountability.

Conclusion: risk cannot be outsourced 🎯

The NIS Decree is, at its core, a statement about the nature of risk: it can be managed, measured, insured — but not delegated. The place of security has changed: no longer the server room, but the boardroom; the signature no longer the technician’s, but the decision-maker’s.

Take it as a provocation: the good news is that almost all the required measures are practices you should have adopted anyway. The bad news is that from now on, not having them comes with a price, a name and a signature.

Want the operational details — scope, registration, measures, deadlines? They’re in the practical guide: NIS 2 — Cybersecurity: the Italian Practical Guide.

Last updated on