Cybersecurity is becoming the personal responsibility of executive directors
Cybersecurity is no longer only an IT issue – for directors it is becoming part of corporate governance and proper managerial care. Management must know whether the company falls within regulation and ensure appropriate measures, resources, training and supplier oversight. The article explains directors’ personal responsibility and how to build a system that can withstand both regulatory scrutiny and a security incident.

Key takeaways
New Cybersecurity Obligations for Company Management
The new Cybersecurity Act places a much greater emphasis on the involvement of top management in ensuring cybersecurity. Executive directors and members of the board of directors will bear direct responsibility for their company's compliance with the new requirements of this regulation. In practice, this means that if your company falls under the regulation, you must ensure the implementation of all necessary measures, oversee their compliance, and allocate sufficient human and financial resources to cybersecurity.
Regardless of technical knowledge, the law requires active supervision by the statutory body, not just a formal delegation of responsibility. As a result of the new legislation, cybersecurity is becoming another component of the duty of due managerial care, which members of statutory bodies are obliged to observe in the performance of their duties.
Even before a company begins to implement specific security measures, it must assess whether the law applies to it. This is done through a process of so-called self-identification, in which the company briefly assesses its size, field of activity, and other criteria set by the law and accompanying decrees. If it finds that it falls under the regulation, it is obliged to report the provision of a regulated service to the National Cyber and Information Security Agency (NÚKIB).
Subsequently, it is necessary to implement technical and organisational measures, which, in the lower-obligation regime, include in particular:
1. Technical Security, Access and Password Management
Implementing technical measures to protect networks, systems, and data, including managing access rights and identities. This also includes rules for creating and managing strong passwords, multi-factor authentication, and controlling access permissions according to the principle of least privilege.
2. Training and Human Resources Management
Regular training for employees and management on security threats and proper conduct. It also includes vetting individuals in key positions and providing thorough information about the duties and responsibilities of individuals.
3. Strategic Security Management
The foundation is the appointment of responsible persons, the creation of a security policy, and maintaining an overview of the measures taken. Top management is responsible for approving and continuously monitoring the functionality of the entire security management system.
4. Attack Detection, Incident Management, and Recovery Plan
The organisation must be able to detect cyber incidents in a timely manner, respond to them correctly, report them to NÚKIB, and subsequently restore secure operations. An incident response plan and a plan for restoring critical systems are essential.
5. Security in Contractual Relationships with Suppliers
Contracts with suppliers must include security requirements, such as confidentiality obligations, the level of technical measures, response times, and potentially the right to audit. The supply chain is often the weakest link.
All adopted measures must not only be implemented but also effectively documented, regularly updated, and audited. During an inspection by the supervisory authority, it will not be enough to point to internal directives – the key will be to prove that the cybersecurity system actually works in practice. The authorities will require evidence that the established rules are known, applied, and continuously verified.
Risks and Sanctions for Non-Compliance
The new regulation gives cybersecurity a similar weight to, for example, financial accounting – and the sanctions correspond to this. Failure to comply with obligations can have very tangible consequences for both the company and its management. Regulated companies can face fines of up to 2% of their total annual turnover (for entities in the higher-obligation regime) or 1.4% for other entities.
For large enterprises, this can mean sanctions in the order of tens or hundreds of millions of Czech crowns. In addition to these financial penalties, the new law also introduces non-financial sanctions – authorities can, for example, suspend the validity of European security certifications (e.g., ISO 27001, NIST, TISAX, etc.), which can cause significant difficulties in meeting contractual obligations.
An even more significant innovation, however, is the direct personal liability of statutory bodies. If a company violates its cybersecurity obligations, its executive directors or members of the board of directors can be directly penalised. They face personal liability for damages caused (including non-pecuniary damage) – for example, if sensitive data of business partners is leaked due to underestimated security, the injured parties can claim compensation from them.
Furthermore, they may be liable to creditors for the company's debts if the company becomes insolvent due to a security incident. The draft Cybersecurity Act anticipates that NÚKIB will be able to impose a fine of up to CZK 20 million on a member of a statutory body in serious cases. For repeated or serious breaches of duty, the authority can also decide to ban them from holding office for a period of at least 6 months. In exceptional situations where there has been gross negligence, a potential assessment of liability under criminal law cannot be ruled out.
These sanctions are not just theoretical threats. Personal penalties for senior executives would have serious reputational impacts for both the managers concerned and the entire company – few companies can afford to have their executive director publicly fined or temporarily removed from management. The investigation or sanction proceedings alone can paralyse the company's internal operations and damage client trust.
This is why the new regulation aims to motivate company management not to underestimate cybersecurity. This modern "accountability" approach from the EU is intended to draw companies into active protection: when management knows they have skin in the game, they will pay due attention to the area.
The fact that this works is shown by the example from Slovakia – a similar law (also based on NIS2) is already in force there, and companies are not leaving anything to chance. During the self-identification process in Slovakia, 60% more companies registered under the regulation than expected (over 15,000 instead of the originally estimated 9,000). This trend clearly shows that businesses and their management are aware of the risks of non-compliance – and Czech executive directors should do the same before the first inspections or incidents occur.
How to Prepare and Protect Yourself (Practical Recommendations)
The good news is that you are not alone in meeting the new obligations, and with timely preparation, many risks can be avoided.
Below are a few practical steps on how to prepare for the new regulation as an executive director or manager and thus protect both yourself and your company:
Find out if the regulation applies to you: Go through the self-identification process – assess your sector of activity and the size of your business according to the criteria of the law. If you are unsure about the process, our specialised lawyers will be happy to help you.
Do not underestimate planning and resources: Integrate cybersecurity into your company's strategies and allocate an adequate budget and personnel for it. Appoint or hire a qualified person responsible for cybersecurity or create a specialised team to handle the agenda. Remember that implementing a functional system can take months or even years – the sooner you start, the better. If you plan to cooperate with external specialists, bear in mind that their capacity is often limited – so secure it in time.
Implement the necessary measures step by step: Create a plan for implementing security measures according to the requirements of the law. Map existing weaknesses and gradually introduce the mentioned elements: risk analysis and management, security policies, incident detection systems, data backup, access control (e.g., multi-factor authentication), etc. Document each step as you go.
Delegate, but maintain an overview: Divide the cybersecurity agenda among competent individuals – IT managers, security specialists, lawyers, and external consultants. Delegating tasks is necessary, but it does not relieve you of responsibility. Therefore, set up reporting mechanisms to the management level: regular reports on the state of security, incidents, and the implementation of measures. An executive director or board member should have an up-to-date overview of the company's cybersecurity status at all times.
Educate yourself and others: Complete the mandatory training and continue to actively educate yourself in cybersecurity – follow threat trends, learn from incidents at other companies. At the same time, introduce regular training for employees focused on security principles (e.g., password management, phishing recognition, incident response). Promote a security culture in the company – when employees understand the risks, you significantly reduce the likelihood of human error.
Develop a crisis scenario: Despite all prevention, incidents cannot be 100% avoided. Therefore, prepare an Incident Response Plan – who will do what in the event of a system attack, whom to contact (NÚKIB, police, lawyers, PR), how to restore operations. Regularly test this plan with simulations. This will demonstrate that you are fulfilling your duty not only in prevention but also in responding to crisis situations.
Consult on legal aspects: The new regulation is complex and is continuously being specified by implementing regulations. Cooperate with lawyers who will help you correctly interpret specific obligations and set up internal processes in accordance with the law. A legal readiness audit can reveal gaps that the authority would focus on during an inspection.
Insurance and other protective measures: Consider taking out cyber risk insurance, which can mitigate the financial impact of a potential attack or data breach. Although insurance does not replace the need to comply with cybersecurity measures, it can provide the means to quickly manage a crisis situation (e.g., covering the costs of experts to restore the system, PR communication, legal expenses, or ransom for data recovery).
It is important to properly record and archive all the above steps – from risk analyses and training records to reports for management. This documentation will serve both for internal monitoring of progress and as evidence in a potential inspection that management acted proactively and with due care. An executive director who can prove that they did not underestimate security and took reasonable measures faces a much lower risk of personal sanctions. Conversely, ignoring obligations or relying on "it will definitely miss us" would be very dangerous in today's situation.
Risk and Potential Problems | How ARROWS Helps |
Personal fines and disqualification from office for executive directors | We will set up a security management system that legally protects statutory bodies, demonstrates proper supervision, and minimises the risk of personal penalties. |
Incorrect self-identification and fines of up to 2% of turnover | We will conduct a legal and industry-specific self-identification of your company, assess your obligations, and guide you safely through the notification process with NÚKIB. |
Non-functional internal policies and risks in supplier contracts | We will draft and review complete security documentation and supplier contracts (SLAs, confidentiality, audits) in accordance with the law and NÚKIB requirements. |
Cyber attack, data breach, and claims for damages | We will prepare a crisis Incident Response Plan from a legal perspective, ensure mandatory communication with NÚKIB and the Office for Personal Data Protection, and represent you in resolving damages and disputes. |
Conclusion: Start Today
A new age of cyber responsibility is dawning for company management in the Czech Republic. Executive directors can no longer consider cybersecurity a marginal technical issue that can simply be left to IT specialists. The new Cybersecurity Act clearly states that if a company falls within its scope, top management must act proactively – and is personally responsible for the process of implementing technical and organisational measures.
The sanctions and risks outlined above are a compelling reason to address this topic with the utmost seriousness. At the same time, however, those who prepare in time can pass through this sieve unscathed and even gain a competitive advantage (companies with a reputation as secure partners will be more attractive to clients).
It does not pay to wait for the first inspections or incidents. On the contrary, starting preparations now is a strategic move that will protect both your company and yourself. If you are not sure where to start or whether you are meeting all the necessary requirements, do not hesitate to seek professional help. Our Prague-based law firm has extensive experience with cybersecurity regulation and we will be happy to help you – from the initial analysis of the law's impact, through setting up internal processes and documentation, to management training or handling security incidents.
Cybersecurity is a new challenge for executive directors – face it head-on and make sure your company meets all the requirements. By doing so, you will protect not only your company's data and reputation, but also yourself from personal legal liability.
About the author
Read also:
- Digital Inspections and AI in 2026: New EU Compliance Duties for Firms
- Czech Healthcare Providers in 2026: NIS2, Digitalisation and Compliance
- AML/CFT Compliance for Online Marketplace Operators Under Czech and EU Law
- Czech Business Judgment Rule: Protecting Executive Directors from Liability
- Preparing for Labour Inspections in the Czech Republic: Training and Fines
- Czech Lobbying Act: Mandatory Register, Obligations and How to Comply
- Client cleared of criminal charges thanks to ARROWS's meticulous defense
- Precise defense by ARROWS halted criminal proceedings for alleged misuse of know-how
- Mgr. Petr Hanzel, LL.M.
- IT AND SOFTWARE LAW, CYBERSECURITY
Disclaimer:
The information contained in this article is for general informational purposes only and serves as a basic guide to the issue as of 2026. Although we strive for maximum accuracy, laws and their interpretation evolve over time. We are ARROWS Law Firm, a member of the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we are insured for professional liability with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact ARROWS Law Firm directly (consultation@arws.cz). We are not liable for any damages arising from the independent use of the information in this article without prior individual legal consultation.
