NIS2 Board Liability Simulator for Irish Directors

Free calculator: NIS2 personal-liability exposure for Irish directors. Fines, personal liability, board bans, criminal prosecution risk — in under 3 minutes.

Free interactive tool for Irish SME directors and board members. Under Ireland's forthcoming National Cyber Security Bill, directors and senior managers can be held personally liable for cybersecurity failures — fines up to €10 million, board bans, and criminal prosecution. Calculate your exposure in 3 minutes with an instant personalised report.

What the Simulator Assesses

  • Sector — NIS2 covers 18 sectors across Annex I (high criticality: energy, transport, banking, healthcare, digital infrastructure, and more) and Annex II (other critical sectors: food, manufacturing, digital providers, and more)
  • Company size — NIS2 generally applies to medium-sized enterprises and above (50+ employees or €10M+ turnover); these thresholds determine entity classification and maximum fine
  • Your role — under Head 28 of Ireland's General Scheme, the management board includes anyone with authority for oversight, direction, and control of the entity
  • Supply chain exposure — dependency on third-party IT suppliers, cloud services, and managed service providers (Article 21(2)(d))
  • Current security measures — the key measures NIS2 requires; having them in place can significantly reduce personal liability exposure

The Six Security Measures Checked

  • Incident response plan — a documented plan for handling cybersecurity incidents (Article 21(2)(b))
  • Board cybersecurity training — regular education for management body members (Article 20(2))
  • Formal risk assessment process (Article 21(2)(a))
  • Supply chain security due diligence on third-party suppliers (Article 21(2)(d))
  • Incident reporting process — notification within 24 hours (early warning) and 72 hours (full report) (Article 23)
  • CyFUN framework adopted or certified — NCSC Ireland's recommended compliance framework

How Scoring Works

The simulator determines whether your organisation is in scope, classifies it as an Essential or Important entity, and calculates a personal risk score from 0 to 100. Aggravating factors (entity classification, supply chain exposure, missing NIS2 measures, a director or CEO role) raise the score; each measure in place lowers it; the result is weighted by role. Scores of 65+ mean high personal liability risk, 40-64 medium, below 40 lower.

Your report shows the maximum organisational fine, your personal liability rating, board ban risk (temporary suspension under Article 32(5)(b)), criminal liability risk, mitigating and aggravating factors, prioritised recommendations, and the legal basis, with a downloadable PDF. Documented evidence of due diligence is your strongest defence against personal liability claims.

Sources and Disclaimer

Based on official sources: the EU NIS2 Directive (2022/2555), Ireland's General Scheme of the National Cyber Security Bill (Heads 28, 41, 43), NCSC Ireland NIS2 guidance, and the CyFUN framework.

The simulator provides an indicative assessment, not legal advice. The final legislation may differ from the General Scheme; for definitive guidance, consult a qualified solicitor.

Frequently Asked Questions

Can Irish directors be personally liable under NIS2?

Yes. Under Head 43 of Ireland's General Scheme, where a corporate infringement is committed with the consent, connivance, or wilful neglect of a director, manager, secretary, or officer, that individual may be held personally liable. Head 28 also provides for liability where gross negligence is found after a cybersecurity incident.

What are the maximum NIS2 fines for Irish businesses?

Essential entities face fines of up to €10 million or 2% of worldwide annual turnover (whichever is higher); Important entities up to €7 million or 1.4%. These are set out in Head 41 of Ireland's General Scheme.

Can a director be banned from serving on a board under NIS2?

Yes. NIS2 Article 32(5)(b) allows authorities to request a temporary ban on persons with management duties at CEO or legal representative level in an Essential Entity that persistently fails to comply.

What is the CyFUN framework and does it help with NIS2 compliance?

CyFUN (Cyber Fundamentals) is NCSC Ireland's recommended cybersecurity framework, publicly described as the preferred method to demonstrate NIS2 compliance. Adopting it provides structured evidence of due diligence that can mitigate personal liability risk.