Skip to content

Governance & Accountability

Personal liability of management under Section 38 BSIG

Section 38 BSIG requires management to personally implement and oversee cybersecurity measures. Failure to comply creates internal liability toward the entity itself. This article explains the liability mechanism, the documentation that protects, and the most common misconceptions.

15 min read · Published 20 February 2026

§ 38 BSIG is the provision that managing directors most frequently misunderstand. It stipulates that management bodies of essential and important entities must personally implement and oversee the risk management measures required under § 30 BSIG. Failure to comply exposes them to internal liability (Innenhaftung) toward their own entity, meaning recourse claims against their personal assets. This article explains what § 38 BSIG actually requires, where the most common misconceptions lie, and what documentation you as an IT manager or CISO should prepare to ensure your management is properly protected.

What § 38 BSIG Actually Requires

The legislature deliberately elevated responsibility for cybersecurity to the executive level. § 38 BSIG contains three separate obligations that apply cumulatively.

§ 38 (1) BSIG: Implement and Oversee

"Geschäftsleitungen besonders wichtiger Einrichtungen und wichtiger Einrichtungen sind verpflichtet, die von diesen Einrichtungen nach § 30 zu ergreifenden Risikomanagementmaßnahmen umzusetzen und ihre Umsetzung zu überwachen." – § 38 (1) BSIG

Two verbs are key: "umsetzen" (implement) and "überwachen" (oversee). Both are explained in detail below. Note that the German transposition law deliberately uses the stronger term "umsetzen" (implement) rather than the "approve" used in Art. 20 of the NIS2 Directive. Management must not merely approve the measures but actively ensure they are carried out.

§ 38 (2) BSIG: Internal Liability Toward the Entity

"Geschäftsleitungen, die ihre Pflichten nach Absatz 1 verletzen, haften ihrer Einrichtung für einen schuldhaft verursachten Schaden nach den auf die Rechtsform der Einrichtung anwendbaren Regeln des Gesellschaftsrechts." – § 38 (2) BSIG

The crucial point: this constitutes internal liability (Innenhaftung). Management is liable toward its own entity, not directly toward the BSI or any other authority. Fines under § 65 BSIG are imposed on the entity as a legal person. The entity can then seek recourse against the managing director under the applicable corporate law rules. This is how personal assets become exposed – indirectly.

§ 38 (3) BSIG: Mandatory Training

The management body must participate in training on cybersecurity risks and their impact on the entity. It must also ensure that employees are given the opportunity to attend training. In its NIS-2 management training guidance (October 2025), the BSI recommends approximately 4 hours of training with a refresher at least every 3 years. These figures are recommendations, not binding minimum requirements. The law itself refers to "regular" training and "sufficient knowledge and skills." The training obligation applies regardless of whether a security incident has occurred.

Art. 20 NIS2 Directive: The European Framework

Art. 20 of the NIS2 Directive requires all EU member states to establish comparable rules on management body accountability. The specific requirements depend on each country's national transposition law. Notably, while Art. 20 NIS2 Directive uses the wording "approve and oversee," the German legislature goes further with "implement and oversee" in § 38 BSIG. Organizations operating subsidiaries in other EU countries should review the respective national transposition separately.

What "Implement" Really Means

§ 38 (1) BSIG uses the verb "umsetzen" (implement), not the "approve" found in Art. 20 of the NIS2 Directive. The difference carries legal significance.

"Approve" (Art. 20 NIS2 Directive) means: making a formal, documented approval decision based on sufficient information. Management approves the proposed measures.

"Implement" (§ 38 (1) BSIG) goes further: management must actively ensure that the risk management measures under § 30 BSIG are actually carried out. This includes:

  • Commissioning the risk analysis under § 30 BSIG and formally acknowledging its results
  • Approving and enacting the information security policy framework
  • Allocating sufficient resources (personnel, budget, infrastructure)
  • Signing off on the treatment plan for identified risks
  • Approving the emergency and incident response plan and ensuring it is operational

The KaitoSec NIS2 Guide maps out this process in a structured way in Chapter 5 (Governance). The Template Library contains templates for management resolutions and policy documents.

What "Oversee" Really Means

"Oversee" is a continuous obligation. It is not enough to acknowledge the risk analysis once and consider the matter closed.

In practice, overseeing means:

  • Regular (at least quarterly) reporting to the management body on the entity's security posture
  • Documented acknowledgment of these reports by the management body
  • IT security as a standing agenda item in management board meetings
  • Real-time escalation of significant security incidents to the management body
  • Tracking the implementation status of outstanding security measures

The standard: "Knew or should have known." If management cannot demonstrate during a serious incident that it was adequately informed and actively exercised oversight, the entity's recourse claim will be difficult to defend against.

Delegation – What Works and What Does Not

The most common misconception: "We have a CISO, NIS2 responsibility lies with them."

The obligation to implement and oversee cannot be delegated. The management body may delegate the operational execution to a CISO or Information Security Officer (ISO). However, it cannot delegate the implementation and oversight obligation itself. Management remains responsible for ensuring that:

  1. the delegated person is sufficiently qualified and equipped with resources,
  2. a functioning reporting line from the CISO/ISO to the management body exists,
  3. the management body actually acknowledges the reports and documents this,
  4. identified issues are acted upon.

The CISO does not protect the managing director from § 38 BSIG. The CISO is the mechanism through which the managing director fulfills their obligation. The KaitoSec Pre-Check helps you systematically assess the current state of your security measures and identify gaps.

How Personal Assets Actually Become Exposed

Liability of management under § 38 BSIG works differently than many assume. There is no direct fine issued against the managing director personally. The path runs through two stages.

Fines Against the Entity (§ 65 BSIG)

Violations of the obligations under § 30 BSIG are sanctioned under § 65 BSIG. Fines are imposed on the entity as a legal person:

  • Essential entities: Up to 10 million euros
  • Important entities: Up to 7 million euros

The percentage-based caps (2% and 1.4% of global annual revenue, respectively) only apply to entities with total revenue exceeding 500 million euros (§ 65 (6) and (7) BSIG). For most SMEs – the target audience of KaitoSec – the fixed euro amounts represent the relevant upper limit.

Recourse: How the Company Reaches the Managing Director

If the entity pays a fine because management failed to fulfill its obligations under § 38 (1) BSIG, the entity can seek recourse against the managing director. This is a civil law claim under the rules of the applicable corporate law (e.g., § 43 (2) GmbHG for GmbH managing directors, § 93 (2) AktG for board members of stock corporations).

This is how personal assets become exposed. The GmbH's limited liability protects shareholders from creditor claims, not the managing director from recourse claims by their own company.

D&O Insurance – No Automatic Protection

Directors & Officers (D&O) insurance policies are often cited as a safety net. Two critical limitations:

  • Intent and gross negligence: D&O policies typically do not cover intentional violations. If management has systematically failed to meet its obligations, the insurer may deny coverage.
  • Regulatory fines: Many D&O policies explicitly exclude fines imposed by regulatory authorities. Review your policy. Simply having D&O insurance does not constitute NIS2 protection.

Activity Ban as a Last Resort (§ 61 (9) BSIG)

In cases of particularly severe, repeated violations, the competent supervisory authority may temporarily prohibit natural persons performing management functions in essential entities from exercising those functions. Three qualifications are important: First, the activity ban applies only to essential entities, not to important entities. Second, it is not imposed directly by the BSI but by the competent supervisory authority following a referral by the BSI. Third, it is a last resort after prior, unsuccessful enforcement orders.

What Does This Mean in Practice?

These obligations can be translated into concrete, documentable measures. The following list is not a substitute for legal advice, but it shows what documentation makes the difference when it matters.

What Management Must Do

  • Formally acknowledge and approve the risk analysis: The risk analysis under § 30 BSIG is presented to the management body and formally approved with signature and date. This document must be producible in an emergency.
  • Enact security policies: The information security policy framework (overarching policy, password policy, access control, incident response plan) is formally approved and signed by the management body.
  • Receive quarterly security reports: The CISO/ISO reports at least quarterly on open risks, incident status, and progress on measures. The management body confirms acknowledgment in writing.
  • Include IT security in board meetings: IT security is a standing agenda item in regular management meetings. The minutes document what was discussed and decided.
  • Formally appoint an ISO/CISO: A written appointment document with a clear mandate, resource commitment, and reporting line to the management body.
  • Complete training (§ 38 (3) BSIG): The BSI recommends approximately 4 hours of cybersecurity training within 3 years. Retain proof of attendance. Details on this topic are covered in the separate article A-15.
  • Receive real-time notification of significant incidents: The incident response process must ensure that the management body is informed without delay when significant security incidents occur.

What Does NOT Reduce Liability

  • Having a CISO without equipping them with resources, mandate, and a reporting line
  • Receiving security reports but never formally acknowledging or acting on them
  • Delegating everything to the IT department and never engaging with security topics at the management level
  • Relying on D&O insurance without having reviewed the policy for NIS2 relevance

The Documentation Strategy

In the event of a BSI audit or liability proceedings, you must be able to demonstrate that the management body fulfilled its obligations under § 38 BSIG. The following documents form the core framework:

  • Board meeting minutes: With the standing agenda item "IT Security / NIS2 Compliance" and documented resolutions. At least quarterly.
  • Signed approvals: Risk analysis, risk treatment plan, information security policy – all with date and signature of the management body.
  • Acknowledged reports: Written confirmations that the ISO/CISO quarterly report was received and acknowledged. Document date and recipient.
  • ISO/CISO appointment letter: Formal document with mandate, resource framework, reporting line, and date of appointment.
  • Training certificates: Proof of attendance for all members of the management body. Format: certificate, attendance list, or e-learning completion record.
  • Incident escalation documentation: Evidence that the management body was informed during significant incidents (timestamp, channel, content of the initial notification).

For formalizing the management body's resolution on NIS2 measures, the KaitoSec Template Library includes a "Management Resolution for NIS2 Implementation" template. It covers all relevant compliance points and is aligned with the requirements of § 38 BSIG.

Common Misconceptions – Clarified

  • "Our IT department handles security, that's not my job as managing director." Wrong. § 38 BSIG is non-delegable. Operational execution may rest with IT. The implementation and oversight obligation remains with the management body.
  • "We're a GmbH, the managing director is protected by the corporate veil." Not against the company itself. § 38 (2) BSIG establishes an internal liability claim. The entity can seek recourse against the managing director.
  • "We have D&O insurance, we're covered." Review your policy. Regulatory fines and gross negligence are frequently excluded.
  • "We're an 'important entity,' not 'essential' – so the rules are softer." The implementation and oversight obligation under § 38 (1) BSIG applies to both categories. The difference lies in the fine ceiling (10 million vs. 7 million euros) and the activity ban, which is only possible for essential entities.
  • "The BSI can personally fine me." No. Fines under § 65 BSIG are imposed on the entity. Personal assets become exposed through the entity's internal liability recourse against the managing director.
  • "Approving once is enough." No. The oversight obligation is continuous. A one-time approval of the risk analysis without ongoing supervision does not satisfy § 38 (1) BSIG.

Connection to Other NIS2 Topics

Article A-09 does not stand in isolation. The personal liability of management forms the umbrella over the entire NIS2 compliance program:

  • B-03 (Risk Analysis): The results of the risk analysis must be formally approved by the management body. Without this approval, B-03 is incomplete from a liability perspective.
  • A-03 (What a Risk Analysis Means): Management must understand what it is approving. Article A-03 provides the conceptual foundation.
  • A-15 (Mandatory Management Training): The training obligation under § 38 (3) BSIG is covered there in detail: content, formats, and record-keeping.
  • NIS2 Guide Chapter 5 (Governance): The KaitoSec NIS2 Guide maps out steps 5-2 (documenting the management resolution) and 5-3 (establishing the reporting framework) in a structured way.

The next step for management: Download the management resolution template from the KaitoSec Template Library, complete it, and formally adopt it at the next board meeting. The KaitoSec Pre-Check shows you in advance where the biggest gaps lie.

This article is for general informational purposes and does not constitute legal advice. For questions about the specific legal assessment of your situation, consult a lawyer specializing in IT law.

This article is orientation, not legal advice. Verify scope, deadlines and notification routes against the rules in force for your organisation.

Back to the Knowledge Hub