NIS2 in Malta: Management Responsibility and Personal Liability of Company Leadership

Published: · AIPOS OÜ · nis2europe.eu

Cybersecurity Is a Leadership Duty, Not Just an IT Task

One of the most misunderstood aspects of NIS2 is *who* is actually responsible. Many business leaders assume cybersecurity can be delegated entirely to the IT team or an external provider. Under the Maltese transposition of NIS2 — the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41) — that assumption is wrong.

Article 18 of S.L. 460.41 places the obligation squarely on the management bodies of essential and important entities. The management body must:

This mirrors Article 20(1) of Directive (EU) 2022/2555, which requires that management bodies approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements.

In practical terms, this means the board and senior leadership cannot simply sign off blindly. They are expected to understand, approve and monitor the measures — making cybersecurity a standing governance topic, not a purely technical one.

What the Management Body Must Approve and Oversee

The measures that leadership must approve and oversee are set out in article 19 of S.L. 460.41 (the equivalent of Article 21(2) of the NIS2 Directive). These are based on an all-hazards approach and include at least:

Under article 19(1)(c), the entity must also appoint a security liaison officer with the necessary expertise. However, appointing such an officer does not remove the management body's own duty to approve and oversee the measures under article 18.

The Training Duty for Directors and Staff

NIS2 in Malta introduces an explicit training obligation aimed directly at leadership. Under article 18(3) of S.L. 460.41:

> Members of the management bodies of essential and important entities are required to follow training in order to carry out their tasks.

This is not optional. Directors and senior officers must build enough knowledge to genuinely approve and oversee cybersecurity measures — you cannot meaningfully approve what you do not understand.

In addition, article 18(4) requires that essential and important entities offer similar training to their employees on a regular basis, so that staff gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided.

Together, these two obligations create a top-down culture of cyber awareness: leadership trains first, then ensures the wider workforce is trained too.

Personal and Management Liability Under Maltese NIS2

This is the dimension that changes the risk calculation for company leadership. Article 18(1) of S.L. 460.41 is explicit:

> The natural persons composing the management bodies may be held liable for infringements by the aforesaid entities of the said article in accordance with articles 31(10)(b) and 33.

In other words, individual members of the management body — not just the company as a legal entity — can face liability where the entity infringes its cybersecurity risk-management obligations.

This is aligned with Article 20(1) of the NIS2 Directive, which provides that management bodies "can be held liable for infringements by the entities" of the risk-management measures.

A note on public institutions: Under article 18(2), this liability provision is without prejudice to national law on the liability rules applicable to public institutions, as well as the liability of public servants and elected or appointed officials.

Administrative penalties on the entity. Beyond individual liability, the entity itself faces significant administrative penalties. Under article 32 of S.L. 460.41, when they infringe articles 19 or 20:

Entity typeMaximum administrative penalty
essential entity€10 000 000, or 2% of total worldwide annual turnover (whichever is higher)
important entity€7 000 000, or 1.4% of total worldwide annual turnover (whichever is higher)

These penalties are imposed by the Enforcement Committee on the basis of a request from the Critical Infrastructure Protection Department (CIP Department), in accordance with article 33. The exact scope and calculation of any liability directed at individual managers should be confirmed by a qualified adviser — [TÄPSUSTAB PARTNER-JURIST].

What Leadership Should Do Now

If your organisation may qualify as an essential entity or important entity under article 4 of S.L. 460.41, the management body should treat NIS2 as a board-level governance matter. Practical first steps include:

Unsure whether NIS2 applies to you and where your gaps are? Use our free scoping and gap tool to check your likely classification and identify the governance actions your leadership needs to prioritise.

Frequently asked questions

Is cybersecurity under NIS2 the responsibility of IT or of management?

It is a leadership duty. Under article 18 of S.L. 460.41, the management body of essential and important entities must approve the cybersecurity risk-management measures (article 19) and oversee their implementation. This cannot be fully delegated to IT, even though an entity must also appoint a security liaison officer.

Can directors be held personally liable under NIS2 in Malta?

Yes. Article 18(1) of S.L. 460.41 states that the natural persons composing the management bodies may be held liable for infringements by the entity, in accordance with articles 31(10)(b) and 33. This reflects Article 20(1) of the NIS2 Directive. The precise scope of individual liability should be confirmed by a qualified lawyer.

Do managers really have to attend cybersecurity training?

Yes. Article 18(3) of S.L. 460.41 requires members of the management bodies to follow training so they can carry out their tasks. Article 18(4) additionally requires entities to offer similar training to their employees on a regular basis.

What are the maximum penalties for breaching the risk-management or reporting rules?

Under article 32 of S.L. 460.41, for infringements of articles 19 or 20, essential entities face up to €10 000 000 or 2% of total worldwide annual turnover (whichever is higher), and important entities face up to €7 000 000 or 1.4% of turnover (whichever is higher). These are imposed by the Enforcement Committee following a request from the CIP Department.

Check your NIS2 compliance

Run the free gap analysis

Start the free scoping test Run the free surface scan

The complete NIS2 guide — Malta

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home