Back to glossaryLaw & regulation

Fiduciary duty in cybersecurity

The obligation imposed on members of the management body to approve, oversee and receive training on cybersecurity measures, on pain of engaging their personal liability.

Definition

Fiduciary duty in cybersecurity refers to the obligation, enshrined in Article 20 of the NIS2 Directive, which elevates cybersecurity into a duty of care of the management body itself, rather than merely of the technical management. Members of the management body, whether the board of directors, the supervisory board or any equivalent organ, must approve cybersecurity risk-management measures, oversee their implementation and undergo appropriate training. A breach may engage their personal liability, independently of the company's. This evolution marks a fundamental shift, moving cybersecurity from the operational sphere of the information security officer to the fiduciary governance of the board, on the same footing as accounting or internal control obligations. National transpositions have amplified this principle: Germany provides for personal fines of up to five hundred thousand euros, and the directive authorizes a temporary ban on exercising management functions for essential entities. This new liability has direct consequences for the D&O insurance market, whose scope is extended to losses of cyber origin revealing a governance failure, creating an unprecedented convergence with the company's cyber policy.

Example

The chief executive of a French pharmaceutical company, an essential entity under NIS2, failed to attend mandatory training sessions and did not approve the plan for updating critical systems. Following a ransomware attack exploiting an unpatched vulnerability, ANSSI documents the breach of Article 20 obligations. The company's D&O policy covers the executive's defense costs, but the authorities are considering a personal fine of two hundred thousand euros. The D&O insurer verifies whether the policy excludes deliberate regulatory breaches and opens a shared liability investigation with the company's cyber insurer.

Related terms
Related articles
Also known as

devoir de diligence cyber, responsabilité dirigeants cybersécurité, cyber governance duty, duty of care cyber