Published: September 21, 2026
The implementation of the EU NIS2 Directive into Polish law through the amendment of the Act on the National Cybersecurity System (UKSC) brings a fundamental change in the approach to digital risk management. Cybersecurity is no longer solely the domain of technical departments; it has become a key area of legal and financial responsibility for senior management.
The new rules break with the former practice of treating fines as an ordinary cost of doing business borne by the company. Polish law introduces personal financial and managerial sanctions directly against decision-makers.
1. Management Board liability: up to 300% of salary and suspension from office
The UKSC amendment identifies the Head of the entity — defined through Article 8c UKSC together with the Accounting Act — as the person directly bearing legal responsibility.
In commercial companies (limited liability companies, joint-stock companies and simple joint-stock companies), Management Board members are treated as the Head of the entity. The statutory personal sanctions depend on the legal form and sector:
- Private sector: a personal fine of up to 300% of a Management Board member's monthly salary.
- Public sector: a fine of up to 100% of monthly salary for local-government leaders and heads of budgetary units.
The competent supervisory authority imposes the fine, and the proceeds go to the state budget.
Suspension from performing the function
For essential entities that persistently fail to remedy infringements, the supervisory authority may temporarily suspend a Management Board member until the deficiencies are corrected.
What is the Management Board responsible for?
A penalty is not imposed merely because the organisation falls victim to a sophisticated cyberattack. It may result from organisational omissions and inadequate supervision, including:
- failure to implement an Information Security Management System (ISMS) or continuously assess risk,
- failure to complete the required annual cybersecurity training,
- failure to register the entity or update its data on time,
- failure to implement post-inspection recommendations and orders.
2. The role and liability of the CISO
A CISO outside the Management Board
If the CISO is not a Management Board member, UKSC does not impose direct administrative penalties on that person — neither the fine of up to 300% of salary nor suspension from office. Statutory responsibility remains with the governing body even when tasks are delegated to another person or entity.
What liability does the CISO bear?
The absence of direct supervisory penalties does not remove the CISO's liability towards the company:
- Employment contract: liability under the Labour Code, generally capped at three months' salary for improper performance, except in cases of intentional damage.
- B2B or civil-law contract: liability under the Civil Code; the company may seek compensation if it suffers losses due to the CISO's fault.
3. Can the company pay a Management Board member's fine?
Having the company pay or reimburse a fine imposed personally on a Management Board member carries serious legal and tax risks.
- The personal nature of the penalty: the sanction is intended to punish an individual for inadequate supervision.
- Risk of acting to the company's detriment: paying a private fine from company assets may give rise to criminal and civil liability.
- Tax consequences: the payment may be treated as income for the Management Board member and may not be tax-deductible for the company.
What about D&O insurance?
Standard Directors & Officers policies generally do not cover administrative fines imposed directly by public authorities. They may, however, cover legal defence costs or certain compensation claims brought by the company against its directors.
4. Multi-member Management Boards: who is liable?
If no specific person is designated within a multi-member Management Board, all members bear personal responsibility. The law allows one member to be formally appointed to supervise cybersecurity.
Arguments against designation
- A lightning rod for the rest of the board: proceedings and any fine will be directed at the designated person.
- Continuous verification: the role requires ongoing competence development and genuine oversight of IT and OT budgets.
Arguments in favour
- Protection for other members: their direct exposure is reduced, provided the designated person receives adequate resources.
- Real budgetary and strategic authority: a strong mandate to enforce necessary cybersecurity investment.
- Avoiding collective responsibility: without designation, the authority may penalise every Management Board member separately.
Summary
The Act on the National Cybersecurity System definitively ends the era in which cybersecurity could be pushed to the margins of Management Board work.
The conclusion for Management Boards: the best protection against a personal fine is an effective ISMS, regular training and genuine oversight of company procedures. Delegating operational tasks to a CISO is essential, but it does not release company management from legal responsibility for their proper execution.
Consulting sp. z o.o.
