NIS2 for the board: what decision-makers need to know
Turning a directive into decisions the board can actually take.

NIS2 raises the bar on governance, risk management and incident reporting. For boards, the shift is not technical — it is accountability.
Three questions a board should ask
Are we in scope, and as what? Where do our gaps concentrate against the directive? And can we report an incident within the deadlines, on the day it matters?
The first question sounds trivial and is not: scope depends on sector and size, but also on your role in the supply chain. Many companies find they are in scope not because they are “essential”, but because they supply someone who is. The second — where the gaps are — needs evidence, not opinion: leadership-approved risk management, management-body governance, oversight of critical ICT suppliers, a reporting capability. The third is proven, not asserted: an incident-reporting process that has never been rehearsed is a hypothesis, and the deadlines (24-hour early warning, 72-hour notification) leave no room for improvisation.
Proportionate, not performative
The directive rewards substance over paperwork. A prioritised, costed roadmap that the board approves beats a binder no one reads.
“Proportionate” does not mean doing the minimum: it means matching effort to real risk, and being able to explain it. A board that approves a programme should be able to summarise it in a few sentences — what we protect, from what, in what priority and at what cost. If no one can explain it, it is not a programme; it is a shopping list.
Start with a fixed-price assessment, so the cost is known before you begin — and the output is a plan you own.



