Board members in a meeting room reviewing cyber governance and risk data on a large digital display. NIS2 board governance.

Cybersecurity Just Became a Boardroom Job in Ireland

NIS2 Board Governance · Cyber Guidance for Ireland

What the NCSC’s new cyber governance guidance means for management boards in NIS2 entities.

Picture a ransomware attack landing on a Tuesday morning. Under NIS2, that is no longer just an IT problem to escalate up the chain, it is a problem the board is legally accountable for from the very first hour. Ireland’s National Cyber Security Centre (NCSC) has just made that accountability official, publishing dedicated cyber governance guidance to help boards understand exactly what is expected of them.

What the NCSC Just Announced

On 7 July 2026, the NCSC, part of the Department of Justice, Home Affairs and Migration, launched Guidance on Cyber Governance for Management Board Members in NIS2 Entities. The guidance is aimed squarely at Accounting Officers and Management Board members, including CEOs, Managing Directors, CIOs and CISOs, and is designed to help them understand and meet their cybersecurity responsibilities under the NIS2 Directive.

At the heart of the guidance sits the Cyber Fundamentals Framework, known as CyFun, which the NCSC recommends as the practical bridge between legal obligation and day-to-day action.

Why This Is a Board-Level Issue Now, Not Just an IT One

The NIS2 Directive, formally Directive (EU) 2022/2555, represents a genuine shift in how cybersecurity accountability is assigned in the EU. Rather than sitting with a technical team, responsibility now rests explicitly with the highest level of executive management. Under the Directive, management bodies of essential and important entities are required to approve and oversee their organisation’s cybersecurity risk management measures, and to complete cybersecurity training themselves, not simply mandate it for staff.

€10M
or 2% of global turnover: max fine for essential entities, whichever is greater
€7M
or 1.4% of global turnover: max fine for important entities, whichever is greater
18
critical and important sectors covered by NIS2 across the EU
Oct 2024
deadline for Member States to transpose the Directive into national law

Sources: Directive (EU) 2022/2555 (NIS2 Directive); NCSC Ireland.

This is not a compliance footnote

NIS2 carries some of the toughest penalties in EU cybersecurity law, and liability can extend to individual members of management, not just the organisation. That is precisely why the NCSC has now issued guidance written directly for boards rather than IT departments.

What Is CyFun, and Why Does the NCSC Keep Pointing to It?

CyFun, the Cyber Fundamentals Framework, is a practical, risk-based framework built on the internationally recognised NIST Cybersecurity Framework. The NCSC positions it as Ireland’s preferred national approach for organisations working to meet NIS2 obligations, because it gives boards a structured way to strengthen cybersecurity and demonstrate compliance, rather than treating regulation as a box-ticking exercise. The goal, as the NCSC frames it, is to help organisations move beyond minimum compliance and start managing cyber risk as a normal part of good governance.

What the Guidance Actually Gives Your Board

According to the NCSC, the guidance and the CyFun framework together give boards a clear, practical roadmap. Specifically, they are designed to help board members:

  • Understand the right questions to ask their security and IT leadership.
  • Identify and manage cybersecurity risk within the supply chain.
  • Build a culture where cyber risk is considered across the whole organisation, not just in IT.
  • Oversee cybersecurity effectively without needing deep technical expertise themselves.

That last point matters. The NCSC has been explicit that this guidance is built so boards can govern cyber risk without becoming technical experts. The expectation is oversight and informed decision-making, not hands-on remediation.

Frequently Asked Questions

What is the NCSC’s new cyber governance guidance?

It is a document published by Ireland’s National Cyber Security Centre on 7 July 2026, aimed at helping Accounting Officers and Management Board members in NIS2 entities understand and fulfil their cybersecurity governance responsibilities, built around the CyFun framework.

Which organisations in Ireland need to pay attention to NIS2 board governance requirements?

NIS2 applies to essential and important entities across 18 critical and important sectors in the EU, generally organisations at medium size or larger, with certain entity types such as trust service providers and DNS providers in scope regardless of size. If your organisation falls under NIS2, your management board carries direct legal responsibility for cybersecurity oversight.

What is CyFun?

CyFun, the Cyber Fundamentals Framework, is the NCSC’s preferred risk-based framework for helping organisations meet their NIS2 obligations. It is based on the NIST Cybersecurity Framework and gives organisations a practical, structured route to compliance.

Do board members need to become cybersecurity experts?

No. The NCSC guidance is specifically designed so boards can oversee cybersecurity risk effectively without detailed technical knowledge. The focus is on asking the right questions, understanding risk, and ensuring accountability, not on hands-on technical work.

What happens if a board does not meet its NIS2 obligations?

Non-compliance can lead to significant financial penalties for the organisation, up to €10 million or 2 percent of global turnover for essential entities, and can also carry personal liability implications for management, which is why board-level engagement is no longer optional.

If your board is navigating what NIS2 and this new guidance mean day to day, our cyber attack response plan for Irish SMEs covers the operational side of the same accountability the NCSC is now asking boards to own.

References

  • Department of Justice, Home Affairs and Migration / gov.ie, “NCSC Launches Cyber Governance Guidance for Management Boards in NIS2 Organisations,” 7 July 2026 — gov.ie
  • NCSC Ireland, Guidance on Cyber Governance for Management Board Members in NIS2 Entities (PDF) — ncsc.gov.ie
  • NCSC Ireland, Guidance Documents — ncsc.gov.ie/guidance
  • CyFun, Cyber Fundamentals Framework — cyfun.eu
  • EUR-Lex, Directive (EU) 2022/2555 (NIS2 Directive) — eur-lex.europa.eu
NEWTEC SERVICES · CYBERSECURITY GOVERNANCE

Not Sure Where Your Board Stands on This?

Reading the guidance is one thing. Turning CyFun into an actual routine your board follows is another. Let’s talk it through.

Talk to our team →
Shannon: (061) 708-820 · Dublin: (01) 531-3777 · Limerick: (061) 708-821