Skip to content

Cybersecurity is becoming the personal responsibility of executive directors

Cybersecurity is no longer only an IT issue – for directors it is becoming part of corporate governance and proper managerial care. Management must know whether the company falls within regulation and ensure appropriate measures, resources, training and supplier oversight. The article explains directors’ personal responsibility and how to build a system that can withstand both regulatory scrutiny and a security incident.

Executive discussing personal responsibility in cybersecurity at a conference table.

Key takeaways

The new Act on Cybersecurity will enter into force no later than 1 November 2025. This legislation, transposing the NIS2 Directive, has been approved by the Chamber of Deputies and is awaiting debate in the Senate and the President's signature, fundamentally changing the rules of cybersecurity.
Cybersecurity is becoming the personal responsibility of executive directors. Members of statutory bodies will bear direct responsibility for complying with the new legal requirements and will be required to ensure sufficient resources and supervision of these measures as part of their duty of due managerial care.
You must perform a self-identification to determine if the Act applies to you. Businesses must assess their size and sector of activity according to the criteria set out in the Act and its accompanying decrees. If they fall under the regulation, they are obliged to notify the NÚKIB of the provision of a regulated service.
Implement technical and organisational measures to protect data. Core obligations include technical security, access and password management, including multi-factor authentication and the principle of least privilege for users.

ARE YOU FACING NEW PERSONAL LIABILITY FOR CYBERSECURITY?

Contact us; we will be happy to assist you with ensuring legal compliance.

ARROWS law firm

New Cybersecurity Obligations for Company Management

The new Cybersecurity Act places a much greater emphasis on the involvement of top management in ensuring cybersecurity. Executive directors and members of the board of directors will bear direct responsibility for their company's compliance with the new requirements of this regulation. In practice, this means that if your company falls under the regulation, you must ensure the implementation of all necessary measures, oversee their compliance, and allocate sufficient human and financial resources to cybersecurity.

Regardless of technical knowledge, the law requires active supervision by the statutory body, not just a formal delegation of responsibility. As a result of the new legislation, cybersecurity is becoming another component of the duty of due managerial care, which members of statutory bodies are obliged to observe in the performance of their duties.

Even before a company begins to implement specific security measures, it must assess whether the law applies to it. This is done through a process of so-called self-identification, in which the company briefly assesses its size, field of activity, and other criteria set by the law and accompanying decrees. If it finds that it falls under the regulation, it is obliged to report the provision of a regulated service to the National Cyber and Information Security Agency (NÚKIB).

Subsequently, it is necessary to implement technical and organisational measures, which, in the lower-obligation regime, include in particular:

1. Technical Security, Access and Password Management

Implementing technical measures to protect networks, systems, and data, including managing access rights and identities. This also includes rules for creating and managing strong passwords, multi-factor authentication, and controlling access permissions according to the principle of least privilege.

2. Training and Human Resources Management

Regular training for employees and management on security threats and proper conduct. It also includes vetting individuals in key positions and providing thorough information about the duties and responsibilities of individuals.

3. Strategic Security Management

The foundation is the appointment of responsible persons, the creation of a security policy, and maintaining an overview of the measures taken. Top management is responsible for approving and continuously monitoring the functionality of the entire security management system.

4. Attack Detection, Incident Management, and Recovery Plan

The organisation must be able to detect cyber incidents in a timely manner, respond to them correctly, report them to NÚKIB, and subsequently restore secure operations. An incident response plan and a plan for restoring critical systems are essential.

5. Security in Contractual Relationships with Suppliers

Contracts with suppliers must include security requirements, such as confidentiality obligations, the level of technical measures, response times, and potentially the right to audit. The supply chain is often the weakest link.

All adopted measures must not only be implemented but also effectively documented, regularly updated, and audited. During an inspection by the supervisory authority, it will not be enough to point to internal directives – the key will be to prove that the cybersecurity system actually works in practice. The authorities will require evidence that the established rules are known, applied, and continuously verified.

Frequently Asked Questions about Management's Obligations and Self-Identification

1. How can a company determine if the new Cybersecurity Act applies to it?

  • This is done through a process of so-called self-identification. The company must assess the sector in which it operates, its size (number of employees and turnover), and the type of services it provides according to the criteria of the law and accompanying decrees. If it falls under the regulation, it has a legal obligation to actively report this to NÚKIB.

2. Can an executive director transfer all responsibility for cybersecurity to the IT department or an external supplier?

  • No. While the law allows for the delegation of specific tasks to IT specialists, the professional and legal responsibility remains with the statutory body. Active supervision, approval of security policies, and budget allocation are part of the duty of due managerial care.

3. What are the basic organisational and technical measures a company must implement?

  1. The main pillars include access management and strong passwords (including multi-factor authentication), regular employee training, setting up crisis plans for incident detection and recovery, appointing responsible persons, and verifying security in supplier contracts.

ARROWS law firm

Risks and Sanctions for Non-Compliance

The new regulation gives cybersecurity a similar weight to, for example, financial accounting – and the sanctions correspond to this. Failure to comply with obligations can have very tangible consequences for both the company and its management. Regulated companies can face fines of up to 2% of their total annual turnover (for entities in the higher-obligation regime) or 1.4% for other entities.

For large enterprises, this can mean sanctions in the order of tens or hundreds of millions of Czech crowns. In addition to these financial penalties, the new law also introduces non-financial sanctions – authorities can, for example, suspend the validity of European security certifications (e.g., ISO 27001, NIST, TISAX, etc.), which can cause significant difficulties in meeting contractual obligations.

An even more significant innovation, however, is the direct personal liability of statutory bodies. If a company violates its cybersecurity obligations, its executive directors or members of the board of directors can be directly penalised. They face personal liability for damages caused (including non-pecuniary damage) – for example, if sensitive data of business partners is leaked due to underestimated security, the injured parties can claim compensation from them.

Furthermore, they may be liable to creditors for the company's debts if the company becomes insolvent due to a security incident. The draft Cybersecurity Act anticipates that NÚKIB will be able to impose a fine of up to CZK 20 million on a member of a statutory body in serious cases. For repeated or serious breaches of duty, the authority can also decide to ban them from holding office for a period of at least 6 months. In exceptional situations where there has been gross negligence, a potential assessment of liability under criminal law cannot be ruled out.

These sanctions are not just theoretical threats. Personal penalties for senior executives would have serious reputational impacts for both the managers concerned and the entire company – few companies can afford to have their executive director publicly fined or temporarily removed from management. The investigation or sanction proceedings alone can paralyse the company's internal operations and damage client trust.

This is why the new regulation aims to motivate company management not to underestimate cybersecurity. This modern "accountability" approach from the EU is intended to draw companies into active protection: when management knows they have skin in the game, they will pay due attention to the area.

The fact that this works is shown by the example from Slovakia – a similar law (also based on NIS2) is already in force there, and companies are not leaving anything to chance. During the self-identification process in Slovakia, 60% more companies registered under the regulation than expected (over 15,000 instead of the originally estimated 9,000). This trend clearly shows that businesses and their management are aware of the risks of non-compliance – and Czech executive directors should do the same before the first inspections or incidents occur.

How to Prepare and Protect Yourself (Practical Recommendations)

The good news is that you are not alone in meeting the new obligations, and with timely preparation, many risks can be avoided.

Below are a few practical steps on how to prepare for the new regulation as an executive director or manager and thus protect both yourself and your company:

DO YOU NEED LEGAL HELP?

Get in touch — we're happy to help.

ARROWS law firm
  • Find out if the regulation applies to you: Go through the self-identification process – assess your sector of activity and the size of your business according to the criteria of the law. If you are unsure about the process, our specialised lawyers will be happy to help you.

  • Do not underestimate planning and resources: Integrate cybersecurity into your company's strategies and allocate an adequate budget and personnel for it. Appoint or hire a qualified person responsible for cybersecurity or create a specialised team to handle the agenda. Remember that implementing a functional system can take months or even years – the sooner you start, the better. If you plan to cooperate with external specialists, bear in mind that their capacity is often limited – so secure it in time.

  • Implement the necessary measures step by step: Create a plan for implementing security measures according to the requirements of the law. Map existing weaknesses and gradually introduce the mentioned elements: risk analysis and management, security policies, incident detection systems, data backup, access control (e.g., multi-factor authentication), etc. Document each step as you go.

  • Delegate, but maintain an overview: Divide the cybersecurity agenda among competent individuals – IT managers, security specialists, lawyers, and external consultants. Delegating tasks is necessary, but it does not relieve you of responsibility. Therefore, set up reporting mechanisms to the management level: regular reports on the state of security, incidents, and the implementation of measures. An executive director or board member should have an up-to-date overview of the company's cybersecurity status at all times.

  • Educate yourself and others: Complete the mandatory training and continue to actively educate yourself in cybersecurity – follow threat trends, learn from incidents at other companies. At the same time, introduce regular training for employees focused on security principles (e.g., password management, phishing recognition, incident response). Promote a security culture in the company – when employees understand the risks, you significantly reduce the likelihood of human error.

  • Develop a crisis scenario: Despite all prevention, incidents cannot be 100% avoided. Therefore, prepare an Incident Response Plan – who will do what in the event of a system attack, whom to contact (NÚKIB, police, lawyers, PR), how to restore operations. Regularly test this plan with simulations. This will demonstrate that you are fulfilling your duty not only in prevention but also in responding to crisis situations.

  • Consult on legal aspects: The new regulation is complex and is continuously being specified by implementing regulations. Cooperate with lawyers who will help you correctly interpret specific obligations and set up internal processes in accordance with the law. A legal readiness audit can reveal gaps that the authority would focus on during an inspection.

  • Insurance and other protective measures: Consider taking out cyber risk insurance, which can mitigate the financial impact of a potential attack or data breach. Although insurance does not replace the need to comply with cybersecurity measures, it can provide the means to quickly manage a crisis situation (e.g., covering the costs of experts to restore the system, PR communication, legal expenses, or ransom for data recovery).

It is important to properly record and archive all the above steps – from risk analyses and training records to reports for management. This documentation will serve both for internal monitoring of progress and as evidence in a potential inspection that management acted proactively and with due care. An executive director who can prove that they did not underestimate security and took reasonable measures faces a much lower risk of personal sanctions. Conversely, ignoring obligations or relying on "it will definitely miss us" would be very dangerous in today's situation.

Risk and Potential Problems

How ARROWS Helps

Personal fines and disqualification from office for executive directors

We will set up a security management system that legally protects statutory bodies, demonstrates proper supervision, and minimises the risk of personal penalties.

Incorrect self-identification and fines of up to 2% of turnover

We will conduct a legal and industry-specific self-identification of your company, assess your obligations, and guide you safely through the notification process with NÚKIB.

Non-functional internal policies and risks in supplier contracts

We will draft and review complete security documentation and supplier contracts (SLAs, confidentiality, audits) in accordance with the law and NÚKIB requirements.

Cyber attack, data breach, and claims for damages

We will prepare a crisis Incident Response Plan from a legal perspective, ensure mandatory communication with NÚKIB and the Office for Personal Data Protection, and represent you in resolving damages and disputes.

ARROWS law firm

Conclusion: Start Today

A new age of cyber responsibility is dawning for company management in the Czech Republic. Executive directors can no longer consider cybersecurity a marginal technical issue that can simply be left to IT specialists. The new Cybersecurity Act clearly states that if a company falls within its scope, top management must act proactively – and is personally responsible for the process of implementing technical and organisational measures.

The sanctions and risks outlined above are a compelling reason to address this topic with the utmost seriousness. At the same time, however, those who prepare in time can pass through this sieve unscathed and even gain a competitive advantage (companies with a reputation as secure partners will be more attractive to clients).

It does not pay to wait for the first inspections or incidents. On the contrary, starting preparations now is a strategic move that will protect both your company and yourself. If you are not sure where to start or whether you are meeting all the necessary requirements, do not hesitate to seek professional help. Our Prague-based law firm has extensive experience with cybersecurity regulation and we will be happy to help you – from the initial analysis of the law's impact, through setting up internal processes and documentation, to management training or handling security incidents.

Cybersecurity is a new challenge for executive directors – face it head-on and make sure your company meets all the requirements. By doing so, you will protect not only your company's data and reputation, but also yourself from personal legal liability.

Frequently Asked Questions about Sanctions, Executive Director's Personal Liability, and Defence

1. What fines does the company itself face for violating cybersecurity rules?

  • Regulated companies face fines of up to 2% of their total annual turnover (in the higher-obligation regime), or 1.4% for other entities. In addition to financial sanctions, non-financial penalties are also possible, such as the revocation or suspension of security certifications (ISO 27001, etc.).

2. What specific personal penalties do executive directors and board members face?

  • In serious cases, NÚKIB can impose a personal fine of up to CZK 20 million on a member of a statutory body and issue a ban on holding office for a period of at least 6 months. In addition, management is liable with their entire personal assets for damages caused to the company or creditors as a result of neglecting the duty of due managerial care.

3. Can cyber risk insurance fully protect the company and its management?

  • Not fully. Insurance helps cover the financial impacts of a crisis situation (e.g., data recovery costs, legal fees, or PR communication), but it will not protect a statutory body from a personal ban on holding office or a fine from NÚKIB for knowingly ignoring legal obligations.

4. What is the best way to prove to the Authority (NÚKIB) that management acted with due managerial care?

  • Detailed and continuous documentation is key. It is necessary to have archived risk analyses, records of completed training, minutes of management meetings regarding the approval of security budgets, audit reports, and tested crisis incident response plans.

5. What must a secure contract with an IT supplier contain from the perspective of the new law?

Supplier contracts must contain clearly defined security requirements, non-disclosure agreements (NDAs), guaranteed response times in a crisis incident (SLAs), rules for data handling, and the customer's right to conduct a security audit of the supplier.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

 


Disclaimer:

The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.