Should the Management Board representative for NIS2 implementation and maintenance be a member of the IT department?
ANSWER
The Management Board representative for NIS2 implementation and maintenance does not necessarily need to be a member of the IT department. Whilst IT professionals possess specialist technical knowledge, the representative should above all have project management skills, an understanding of business processes, and awareness of the legal regulations governing cybersecurity.
The optimal solution is to appoint a person with a broad perspective, who may come from the IT department but also has experience in risk and project management as well as legal knowledge relating to NIS2. Alternatively, a dedicated team may be established in which an IT professional works alongside a person responsible for oversight and regulatory compliance.


