NIS2 in Malta: Management Responsibility and Personal Liability of Company Leadership
Cybersecurity Is a Leadership Duty, Not Just an IT Task
One of the most misunderstood aspects of NIS2 is *who* is actually responsible. Many business leaders assume cybersecurity can be delegated entirely to the IT team or an external provider. Under the Maltese transposition of NIS2 — the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41) — that assumption is wrong.
Article 18 of S.L. 460.41 places the obligation squarely on the management bodies of essential and important entities. The management body must:
- Approve the cybersecurity risk-management measures taken by the entity in accordance with article 19; and
- Oversee the implementation of those measures.
This mirrors Article 20(1) of Directive (EU) 2022/2555, which requires that management bodies approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements.
In practical terms, this means the board and senior leadership cannot simply sign off blindly. They are expected to understand, approve and monitor the measures — making cybersecurity a standing governance topic, not a purely technical one.
What the Management Body Must Approve and Oversee
The measures that leadership must approve and oversee are set out in article 19 of S.L. 460.41 (the equivalent of Article 21(2) of the NIS2 Directive). These are based on an all-hazards approach and include at least:
- Policies on risk analysis and information system security;
- Incident handling;
- Business continuity, such as backup management and disaster recovery, and crisis management;
- Supply chain security, including security aspects concerning direct suppliers and service providers;
- Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
- Policies and procedures to assess the effectiveness of cybersecurity risk-management measures;
- Basic cyber hygiene practices and cybersecurity training;
- Policies and procedures regarding the use of cryptography and, where appropriate, encryption;
- Human resources security, insider risk management, access control policies and asset management;
- The use of multi-factor authentication or continuous authentication solutions, secured communications and secured emergency communication systems, where appropriate;
- Logging and traceability of network and information systems.
Under article 19(1)(c), the entity must also appoint a security liaison officer with the necessary expertise. However, appointing such an officer does not remove the management body's own duty to approve and oversee the measures under article 18.
The Training Duty for Directors and Staff
NIS2 in Malta introduces an explicit training obligation aimed directly at leadership. Under article 18(3) of S.L. 460.41:
> Members of the management bodies of essential and important entities are required to follow training in order to carry out their tasks.
This is not optional. Directors and senior officers must build enough knowledge to genuinely approve and oversee cybersecurity measures — you cannot meaningfully approve what you do not understand.
In addition, article 18(4) requires that essential and important entities offer similar training to their employees on a regular basis, so that staff gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided.
Together, these two obligations create a top-down culture of cyber awareness: leadership trains first, then ensures the wider workforce is trained too.
Personal and Management Liability Under Maltese NIS2
This is the dimension that changes the risk calculation for company leadership. Article 18(1) of S.L. 460.41 is explicit:
> The natural persons composing the management bodies may be held liable for infringements by the aforesaid entities of the said article in accordance with articles 31(10)(b) and 33.
In other words, individual members of the management body — not just the company as a legal entity — can face liability where the entity infringes its cybersecurity risk-management obligations.
This is aligned with Article 20(1) of the NIS2 Directive, which provides that management bodies "can be held liable for infringements by the entities" of the risk-management measures.
A note on public institutions: Under article 18(2), this liability provision is without prejudice to national law on the liability rules applicable to public institutions, as well as the liability of public servants and elected or appointed officials.
Administrative penalties on the entity. Beyond individual liability, the entity itself faces significant administrative penalties. Under article 32 of S.L. 460.41, when they infringe articles 19 or 20:
| Entity type | Maximum administrative penalty |
|---|---|
| essential entity | €10 000 000, or 2% of total worldwide annual turnover (whichever is higher) |
| important entity | €7 000 000, or 1.4% of total worldwide annual turnover (whichever is higher) |
These penalties are imposed by the Enforcement Committee on the basis of a request from the Critical Infrastructure Protection Department (CIP Department), in accordance with article 33. The exact scope and calculation of any liability directed at individual managers should be confirmed by a qualified adviser — [TÄPSUSTAB PARTNER-JURIST].
What Leadership Should Do Now
If your organisation may qualify as an essential entity or important entity under article 4 of S.L. 460.41, the management body should treat NIS2 as a board-level governance matter. Practical first steps include:
- Confirm your classification — essential entity or important entity — as this determines the level of supervision and the penalty ceilings.
- Put cybersecurity on the board agenda so that the management body can genuinely approve and oversee the article 19 measures.
- Arrange training for management body members (article 18(3)) and set up regular staff training (article 18(4)).
- Document approvals and oversight, since supervision by the CIP Department (under articles 29 and 30) may involve requests for evidence and audits.
Unsure whether NIS2 applies to you and where your gaps are? Use our free scoping and gap tool to check your likely classification and identify the governance actions your leadership needs to prioritise.
Frequently asked questions
Is cybersecurity under NIS2 the responsibility of IT or of management?
It is a leadership duty. Under article 18 of S.L. 460.41, the management body of essential and important entities must approve the cybersecurity risk-management measures (article 19) and oversee their implementation. This cannot be fully delegated to IT, even though an entity must also appoint a security liaison officer.
Can directors be held personally liable under NIS2 in Malta?
Yes. Article 18(1) of S.L. 460.41 states that the natural persons composing the management bodies may be held liable for infringements by the entity, in accordance with articles 31(10)(b) and 33. This reflects Article 20(1) of the NIS2 Directive. The precise scope of individual liability should be confirmed by a qualified lawyer.
Do managers really have to attend cybersecurity training?
Yes. Article 18(3) of S.L. 460.41 requires members of the management bodies to follow training so they can carry out their tasks. Article 18(4) additionally requires entities to offer similar training to their employees on a regular basis.
What are the maximum penalties for breaching the risk-management or reporting rules?
Under article 32 of S.L. 460.41, for infringements of articles 19 or 20, essential entities face up to €10 000 000 or 2% of total worldwide annual turnover (whichever is higher), and important entities face up to €7 000 000 or 1.4% of turnover (whichever is higher). These are imposed by the Enforcement Committee following a request from the CIP Department.
Check your NIS2 compliance
The complete NIS2 guide — Malta →
This article is general information, not legal advice. A partner lawyer confirms your specific situation.