German, Executives

German Executives Face Personal Liability Under New EU Cyber Security Laws

Published on 07/26/2026 at 23:41 | Redaktion boerse-global.de

From 2026, nearly 30,000 German companies face strict EU cyber rules with personal liability for top management, third-party risks, and GDPR-compliant logging.

Germany's NIS2 & DORA: New IT Security Rules for 30,000 Firms by 2026
German Executives Face Personal Liability Under New EU Cyber Security Laws Illustration mit AI erstellt übermittelt durch boerse-global.de

Nearly 30,000 German companies will face sweeping new IT security obligations from 2026, with top management personally on the hook for compliance failures. The rules, stemming from the EU's NIS2 directive and the Digital Operational Resilience Act (DORA), mark a significant escalation in corporate accountability for cyber risks.

Who Must Comply

The German NIS2 implementation act, based on a September 2025 draft, spells out detailed requirements in sections 30 and 43 ff. of the revised BSIG (Federal Office for Information Security Act). Any company with at least 50 employees or €10 million in annual revenue operating in critical sectors such as energy, transport, banking or healthcare must comply. That covers roughly 29,500 businesses.

Section 38 of the new BSIG makes clear: company directors bear personal responsibility for implementation. Mandatory management training on cyber security obligations is no longer optional — it is a legal requirement.

Lessons from the Financial Sector

DORA, already in force for financial institutions, offers a preview of what is coming. More than 50 percent of reportable security incidents occur at third-party ICT service providers, not within the companies themselves. The message is clear: cyber security cannot stop at the corporate firewall.

Experts warn against treating NIS2 as a purely technical IT project. It is fundamentally a governance challenge. Key steps include:
- Mapping critical dependencies on external partners
- Actively monitoring and auditing third-party providers
- Building audit-proof documentation trails for all security-relevant processes

Both DORA and NIS2 also mandate systematic personnel screening. Operators of critical infrastructure (KRITIS) and financial institutions must now conduct automated background checks that include financial records and criminal register searches.

The Privacy Trap in Log Files

A frequently overlooked complication: personal data embedded in security logs. IP addresses, usernames and email addresses captured in audit trails fall under GDPR restrictions on purpose limitation and data minimisation. Specialists recommend extending existing ISO 27001 certifications to include ISO 27701, the privacy information management standard.

The rules are particularly strict for companies using artificial intelligence tools. Any KRITIS operator employing AI programming assistants — for example at municipal utilities — must prove to auditors that source code is processed within the EU, that complete audit trails of model usage exist, and that telemetry data flows to non-EU countries are disabled.

The risks are not theoretical. In mid-July 2026, a configuration error in a US software vendor's office suite expansion exposed unredacted file contents — including sensitive environment variables — to public cloud storage. The vendor disabled the affected functions on July 13 and 14.

Ransomware on the Rise

The urgency of the new rules is underscored by the current threat landscape. In North Rhine-Westphalia, ransomware attacks are increasing. Nationwide, cyber attacks caused approximately €202 billion in damage in 2025.

Security experts are particularly concerned about the "Anubis" ransomware strain. In early July, it claimed roughly 90 victims. The malware includes a mode that permanently deletes files and can bypass multi-factor authentication through vulnerabilities. Separately, on July 26, a local privilege escalation vulnerability in the Linux kernel was disclosed (CVE-2026-53274). A patch is not yet available.

What 2027 Brings

Companies must also prepare for the EU Machinery Regulation (2023/1230), which takes effect in January 2027. It imposes new cyber security and documentation requirements for software embedded in machinery. Under current rules, existing machines do not need to be retrofitted.

Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.

en | boerse | 69881463 |