NIS2 Executive Liability: Why Email Security Is Now a C-Level Matter
Since December 6, 2025, a new era of cybersecurity has been in effect in Germany. Under the NIS2 Implementation Act, management is for the first time personally liable for the implementation of cybersecurity measures. Email security is at the very top of the agenda – because over 90% of all cyberattacks begin with an email.
§38 BSIG: Personal Liability of Management
The revised BSI Act is unambiguous on this point:
Management must approve the risk management measures under §30 and oversee their implementation. If management fails to fulfill this duty, it is personally liable.
This specifically means:
- Approval: Management must be aware of the measures and formally approve them
- Oversight: It is not sufficient to simply task the IT department – implementation must be demonstrably monitored
- Personal liability: In case of breach of duty, executives are liable with their personal assets
What Happens in the Event of an Email Security Incident?
Consider the following scenario: An employee opens a phishing email, ransomware encrypts critical systems, and customer data is exfiltrated.
Without NIS2-compliant measures, the consequences include:
- Reporting obligation: 24-hour early warning to the BSI, 72 hours for the full report
- Fine: Up to EUR 10 million or 2% of global annual revenue
- Personal liability: Management is held accountable
- Reputational damage: Public disclosure of the incident
The Fine Structure Under NIS2
| Category | Maximum Fine |
|---|---|
| Essential entities | EUR 10 million or 2% of global annual revenue |
| Important entities | EUR 7 million or 1.4% of global annual revenue |
Calculation basis is whichever amount is higher. For a company with EUR 600 million in revenue, this could amount to up to EUR 12 million in fines.
The Most Common Email Risks for Executives
1. Business Email Compromise (BEC)
Attackers impersonate the CEO or CFO and authorize wire transfers. Average damage: EUR 130,000 per incident.
2. Phishing & Spear Phishing
Targeted fraudulent emails with malware attachments or credential harvesting links. AI is making these attacks harder to detect than ever in 2026.
3. Data Exfiltration via Email
Sensitive data leaves the company unencrypted – whether intentionally or accidentally. Without DLP measures, this often goes unnoticed.
4. Lack of Encryption in the Supply Chain
Unencrypted emails to partners and suppliers are an open vulnerability – and a direct violation of §30 No. 5 and No. 8 BSIG.
3 Measures Every Executive Must Implement NOW
Measure 1: Implement Email Encryption
§30 No. 8 BSIG requires cryptography concepts. This means:
- Automatic S/MIME or PGP encryption for sensitive emails
- TLS enforcement for all email connections
- Documented key management
Implementation with Conbool: SecureMail automates encryption directly in the mail flow. No manual effort required from employees.
Measure 2: Activate Threat Protection
§30 No. 2 BSIG requires incident management. This means:
- AI-based detection of phishing and malware
- Quarantine for suspicious emails
- Complete audit trail for incident analysis
Implementation with Conbool: MailGuard detects and neutralizes threats in real time – before they reach the inbox.
Measure 3: Ensure Audit Capability
Management must be able to demonstrate implementation. This means:
- Tamper-proof audit logs
- Email tracing for every incident
- Exportable compliance reports
Implementation with Conbool: Integrated tracing and audit logging provide complete evidence – exportable at the push of a button.
How Conbool Minimizes Risk for Executives
Conbool makes email security transparent and verifiable for management:
- Automated Compliance: Encryption, protection, and auditing run automatically
- Compliance Dashboard: Real-time overview of security status
- Audit-Ready: Complete evidence for BSI audits
- Made in Germany: ISO 27001 data centers in Frankfurt and Berlin
Setup takes just a few minutes. Personal liability ends as soon as you have demonstrably implemented all measures.
Further reading:


