{"id":3921,"date":"2026-06-23T09:10:00","date_gmt":"2026-06-23T07:10:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/where-should-the-board-begin-preparing-for-nis2\/"},"modified":"2026-10-03T20:25:43","modified_gmt":"2026-10-03T18:25:43","slug":"where-should-the-board-begin-preparing-for-nis2","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/","title":{"rendered":"Where should the board begin preparing for NIS2?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for the board and management \u2022 published June 23, 2026 \u2022 updated September 27, 2026 \u2022 8 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"krotka-odpowiedz\" class=\"wp-block-heading\">Short answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With two decisions that the board itself must make. These are who in the organization is the entity manager within the meaning of the KSC Act, and whether the entity&#8217;s qualification has been determined and documented. Only after these does a gap analysis, implementation plan, and budget make sense\u2014without them, the organization finances work whose scope no one can justify. The Act does not allow the entity manager&#8217;s responsibility to be transferred to the IT department or to a vendor, so the first decision is a board decision, not a task to be delegated.  <\/p>\n<\/div>\n\n\n\n<h2 id=\"dlaczego\" class=\"wp-block-heading\">Why this question arises at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Preparation for NIS2 is sometimes initiated from the middle. The board learns that the organization is subject to new regulations, assigns the matter to the IT or compliance department, and after a few weeks receives a list of missing procedures and a quote for tools. The question of sequence returns only when an expenditure must be approved that no one can link to a specific obligation.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The source of this confusion is the structure of the regulations. Directive (EU) 2022\/2555 itself binds the Member State, not the business\u2014an organization&#8217;s obligations arise from the Act on the National Cybersecurity System (KSC) as amended by the amendment of January 23, 2026, which entered into force on April 3, 2026. The Act changes something that was not so clear in the previous legal state. It places responsibility for performing cybersecurity obligations on the entity manager (Article 8c), imposes on them an obligation to undergo documented training once per calendar year (Article 8e), and provides for a separate financial penalty for that person\u2014up to 300% of the remuneration they receive (calculated under the rules for determining cash in lieu of annual leave) and as a rule up to 100% in a public entity (Article 73a(4) and (5))\u2014independent of the penalty imposed on the entity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity therefore ceases to be a matter that the board can simply acknowledge. It becomes an area in which the board makes decisions and must be able to show the basis on which it made them. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second reason is the calendar. Entry in the KSC Register for entities registering on application falls within the period until October 3, 2026, the adaptation period ends on April 3, 2027, and the twenty-four-month deadline for the first audit of essential entities expires on April 3, 2028. After that date financial penalties may also be imposed for the first time (Article 35 of the amending act). The only penalty outside this deferral is the penalty of up to PLN 100 million under Article 73(5). The registration schedule itself does not follow from the Act but from the communication of the Minister of Digitization of April 8, 2026. The minister may amend it only where technical or organisational reasons make it impossible to make entries and start using the S46 system within the scheduled timeframe (Article 34(5) of the amending act). The date of October 3, 2026 applies to entities that met the criteria on April 3, 2026. An organization that meets them later has six months from that moment to submit the application\u2014for entry ex officio, the deadline runs from service of the summons. These dates are not an argument for haste. However, they determine which work must be completed this year and which has until April 3, 2027.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-board is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 id=\"zarzad\" class=\"wp-block-heading\">What should the board know?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Responsibility for performing obligations under the KSC Act rests with the entity manager and cannot be transferred by contract or resolution\u2014tasks can be delegated, not responsibility. The entity manager has an obligation to undergo documented cybersecurity training, and the Act provides for a separate financial penalty for them, in addition to the penalty for the entity. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Entity qualification is, as a rule, based on self-assessment. The authority writes to an entity entered ex officio (a notice) or designated by decision. The legal basis is Articles 7a(2) and 7b(1), 7j, 7l and 7m of the Act and Article 34(2) of the amending act. The result of the assessment\u2014including a negative one\u2014should be documented. The scope of implementation depends on the entity&#8217;s category and what the organization already has, so a budget set before a gap analysis is a guessed budget. Deadlines divide the work into two stages. The first is registration in 2026, the second is implementation and connection to the S46 system by April 3, 2027.  <\/p>\n<\/div>\n\n\n\n<h2 id=\"co-ustalic\" class=\"wp-block-heading\">What must be determined before the decision<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Who is the entity manager and what the Act requires of them<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This question sounds formal but determines everything else. In organizations with a multi-member board, responsibility applies to the body, but practice requires identifying a person who leads the matter, reports it to the board, and is responsible for the completeness of decision-making materials. In capital groups, qualification and status are determined separately for each entity, so there are as many entity managers as there are companies covered by the Act\u2014a common group project does not replace this.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From this determination, three things follow that the board should ask at the first meeting devoted to this matter. These are who is responsible by name, what training they have completed or will complete, and by what procedure they receive information about incidents. The third question is most often omitted, yet it determines the ability to report a serious incident within the required timeframe\u2014early warning within 24 hours of detecting a serious incident and notification within 72 hours, also counted from detection and not from the early warning. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Whether qualification is determined and documented<\/h3>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Qualification is not a formality opening the project, but its foundation.<\/p>\n\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">It determines whether the organization is an essential or important entity, and from that\u2014whether it must plan an audit cycle and under what supervisory regime it will operate. The criteria and method of self-assessment are set out in <a href=\"https:\/\/www.lablogic.pl\/en\/does-every-organization-fall-under-nis2\/\">Does every organization fall under NIS2?<\/a>. What the board should receive from that assessment is a concrete result.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A useful qualification result is not the sentence &#8220;we are subject.&#8221; It is a brief document. It records which lines of business were assigned to sectors from the annexes of the Act, how the entity&#8217;s size was calculated taking into account related and partner enterprises, what category was adopted, and who approved this conclusion. Without this record, the board has no way to demonstrate that the decision was informed\u2014and with a negative qualification result, this document is the only trace that it was conducted at all.  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What the organization already has<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Preparation for NIS2 rarely starts from scratch. Organizations with a certified information security management system, with implemented GDPR, with a functioning incident response procedure, or with obligations arising from the DORA regulation already have some of the required elements\u2014usually in a different arrangement and under a different name. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Establishing the starting point is the step that most strongly affects cost. A board that orders &#8220;NIS2 implementation&#8221; without this inventory usually pays for duplication of already existing procedures and for documentation describing processes that the organization does not conduct. Documentation should show how the organization actually operates; if it describes an invented state, during an audit it works against it.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical scope of this review is finite. It covers risk analysis and its currency, access and authorization management, backups with recovery testing, event logging, incident reporting and response procedure, business continuity plan, requirements for suppliers in existing contracts, and verification of the criminal record of persons performing tasks related to the information security management system and to incident handling\u2014information from the National Criminal Register on the absence of convictions for offences against the protection of information, whereby a valid security clearance at the &#8220;confidential&#8221; level or higher replaces this requirement.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who is responsible for what on the operational side<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The entity manager&#8217;s responsibility does not eliminate the need to assign tasks. The Act requires, among other things, the designation of at least two persons responsible for contacts with entities of the national cybersecurity system; one person is sufficient only for a micro or small enterprise and for an important entity that is a public entity. In practice, process owners and risk owners are also needed\u2014that is, people who can say what will happen to a specific service when a specific system is unavailable. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A common organizational arrangement looks like this. Security formally belongs to IT, but decisions about priorities are made in business lines, and no one has a mandate to resolve disputes between them. In such an arrangement, implementation stops at the risk analysis stage, because assessing the consequences of process interruption requires input from the business, and the business does not feel it owns the matter. Resolving this issue is a management decision, not a technical one.  <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What board decisions determine the pace<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Three decisions actually condition the progress of work, and none of them can be made at a lower level. The first is the level of risk that the organization accepts\u2014without it, risk analysis ends with a list of threats without a conclusion. The second is the financial and human resources assigned to tasks, along with a determination of what the organization does independently and what it entrusts to a security service provider. The third concerns suppliers. Supply chain oversight requires changes in contracts and in the procurement process, and these go beyond the competence of the IT department.   <\/p>\n\n\n\n<div class=\"wp-block-group ll-art-note is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">A separate element not worth closing at this stage is long-term hardware commitments related to provisions on high-risk suppliers. The President signed the amendment and referred to the Constitutional Tribunal a motion concerning the provisions on designating a supplier as a high-risk supplier, the effects of such a decision and its review by the administrative court (case K 19\/26). The motion did not suspend the Act&#8217;s validity, but this fragment of regulation may change. As of September 27, 2026, no hearing had been held and no ruling issued in the case.   <\/p>\n<\/div>\n\n\n\n<h2 id=\"checklista\" class=\"wp-block-heading\">Checklist of initial decisions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Things to check off before the first budget decision.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-check is-layout-constrained wp-block-group-is-layout-constrained\">\n<ul class=\"wp-block-list\">\n<li>The entity manager and the person leading the matter have been identified by name, and the determination has been recorded in minutes or a resolution.<\/li>\n\n\n\n<li>Entity qualification is determined, has an assigned category and written justification; in a capital group\u2014separately for each company.<\/li>\n\n\n\n<li>The application for entry in the KSC Register has been submitted, or the date of its submission before October 3, 2026 has been set\u2014the deadline from the communication of the Minister of Digitization applies to entities that met the criteria on April 3, 2026; if the criteria are met later, six months run from that moment.<\/li>\n\n\n\n<li>At least two persons responsible for contacts with entities of the national cybersecurity system have been designated (one person only for a micro or small enterprise, or for an important entity that is a public entity).<\/li>\n\n\n\n<li>An inventory has been prepared of what the organization already has. It covers risk analysis, access management, backups, logs, incident procedure, business continuity, requirements for suppliers.<\/li>\n\n\n\n<li>It has been determined by what route and within what timeframe information about a serious incident reaches the entity manager.<\/li>\n\n\n\n<li>Training for the entity manager and the method of its documentation have been planned.<\/li>\n\n\n\n<li>A deadline has been set by which the board will receive a gap analysis with a proposal of priorities.<\/li>\n<\/ul>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Only after this list does the conversation about budget have a foundation, because the scope of work results from the difference between the required state and the actual state, not from the catalog of vendor offers.<\/p>\n\n\n\n<h2 id=\"wnioski\" class=\"wp-block-heading\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Preparation for NIS2 begins with a decision about responsibility, not with implementation. A board that first names the entity manager, confirms qualification in writing, and inventories the starting point buys itself something more than order. It buys the ability to justify each subsequent expenditure with a specific statutory obligation. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A sensible sequence for the coming months looks like this. By autumn 2026, close qualification, self-assessment documentation, and entry in the KSC Register\u2014these are formal tasks, but without them nothing further will proceed. In parallel, commission an inventory of the current state and gap analysis so that the board can adopt scope, priorities, and budget at one meeting. Complete the implementation of the information security management system and the connection to the S46 system by April 3, 2027. After that date what remains is consolidating processes and preparing for the first audit, which falls due by April 3, 2028.   <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The measure of progress is not the number of documents. It is the answer to the question of whether the organization can indicate who is responsible, how it learns of an incident, what it does in the first day, and what it can use to demonstrate that this is how it actually operates. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-data-breach-need-to-be-reported\/\">Does every data breach need to be reported?<\/a><\/strong>  \u2014 decision on reporting and distinguishing a security event from a personal data breach; a related thread for organizations that are simultaneously subject to GDPR. <\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-often-should-employees-be-trained-on-personal-data-protection\/\">How often should employees be trained on personal data protection?<\/a><\/strong>  \u2014 training obligation versus good practice, including with regard to management. <\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/how-and-when-to-apply-for-entry-in-the-ksc-register\/\">When and how to apply for entry in the register of essential and important entities<\/a><\/strong> \u2014 deadlines, the data required and the declaration of the head of the entity.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-to-do-after-the-ksc-register-deadline-has-passed\/\">What to do after 3 October 2026, once the deadline for entry in the KSC register has passed?<\/a><\/strong> \u2014 registration duties after the schedule closes, including ex officio entries<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/nis2-documentation\/\">What NIS2 documentation must an essential or important entity keep?<\/a><\/strong> \u2014 the composition of documentation under Article 10 of the KSC Act, its retention periods and the decisions that fall to the head of the entity.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n<li>Act of July 5, 2018 on the National Cybersecurity System, consolidated text \u2014 ISAP: <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180001560\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Directive (EU) 2022\/2555 of the European Parliament and of the Council of December 14, 2022 (NIS2) \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A32022L2555\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> <\/li>\n\n\n\n<li>Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) \u2014 Journal of Laws: <a href=\"https:\/\/dziennikustaw.gov.pl\/D2026000025201.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">dziennikustaw.gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Communication of the Minister of Digitization of April 8, 2026 on deadlines under the amendment to the KSC Act (Official Journal of the Minister of Digitization, item 7) \u2014 Ministry of Digitization: <a href=\"https:\/\/www.gov.pl\/web\/cyfryzacja\/du-mc-poz-7\" target=\"_blank\" rel=\"noreferrer noopener\">gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Amendment to the KSC Act \u2014 obligations of essential and important entities \u2014 Ministry of Digitization: <a href=\"https:\/\/www.gov.pl\/web\/cyfryzacja\/nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa-ksc---obowiazki-podmiotow-kluczowych-i-waznych\" target=\"_blank\" rel=\"noreferrer noopener\">gov.pl<\/a> (in Polish)<\/li>\n\n\n\n<li>Motion of the President of the Republic of Poland for review of the constitutionality of the Act on the National Cybersecurity System, case K 19\/26 \u2014 Constitutional Tribunal: <a href=\"https:\/\/trybunal.gov.pl\/s\/k-19-26\" target=\"_blank\" rel=\"noreferrer noopener\">trybunal.gov.pl<\/a> (in Polish)<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading ll-nietoc\">Let&#8217;s determine the first step for your organization<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If qualification is already determined and the open question is the scope and sequence of work, it is worth starting with a gap analysis\u2014it shows how many of the requirements the organization meets today and what is actually missing. Support in preparing for NIS2 and KSC includes determining the scope of obligations, gap analysis, and an action plan that can be maintained and demonstrated during an audit. <\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/\">Support in preparing for NIS2 and KSC<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>With two board decisions. Who is the entity manager within the meaning of the KSC Act, and whether the qualification has been documented. Only after these does a gap analysis, implementation plan, and budget make sense.<\/p>\n","protected":false},"author":2,"featured_media":5576,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"August 2026","footnotes":""},"categories":[74],"tags":[78],"class_list":["post-3921","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nis2","tag-for-management"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<meta name=\"keywords\" content=\"for-management\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"NIS2 starts with responsibility\" \/>\n\t\t<meta property=\"og:description\" content=\"Boards start with qualification and responsibility, not implementation.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"NIS2 and KSC\" \/>\n\t\t<meta property=\"article:tag\" content=\"nis2\" \/>\n\t\t<meta property=\"article:tag\" content=\"ksc\" \/>\n\t\t<meta property=\"article:tag\" content=\"board\" \/>\n\t\t<meta property=\"article:tag\" content=\"compliance\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-23T07:10:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-03T18:25:43+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"NIS2 starts with responsibility\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Boards start with qualification and responsibility, not implementation.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#article\",\"name\":\"Preparing for NIS2 \\u2014 two board decisions come first\",\"headline\":\"Where should the board begin preparing for NIS2?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Where should the board start with NIS2? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-06-23T09:10:00+02:00\",\"dateModified\":\"2026-10-03T20:25:43+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#webpage\"},\"articleSection\":\"NIS2 and KSC\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"name\":\"NIS2 and KSC\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"position\":2,\"name\":\"NIS2 and KSC\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#listItem\",\"name\":\"Where should the board begin preparing for NIS2?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#listItem\",\"position\":3,\"name\":\"Where should the board begin preparing for NIS2?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"name\":\"NIS2 and KSC\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski-portret\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp\",\"width\":864,\"height\":1080,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/\",\"name\":\"Preparing for NIS2 \\u2014 two board decisions come first\",\"description\":\"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#michal-rutkowski\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"Where should the board start with NIS2? \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/where-should-the-board-begin-preparing-for-nis2\\\/#mainImage\"},\"datePublished\":\"2026-06-23T09:10:00+02:00\",\"dateModified\":\"2026-10-03T20:25:43+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Preparing for NIS2 \u2014 two board decisions come first","description":"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.","canonical_url":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/","robots":"max-image-preview:large","keywords":"for-management","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#article","name":"Preparing for NIS2 \u2014 two board decisions come first","headline":"Where should the board begin preparing for NIS2?","author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg","width":1200,"height":630,"caption":"Where should the board start with NIS2? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-06-23T09:10:00+02:00","dateModified":"2026-10-03T20:25:43+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#webpage"},"articleSection":"NIS2 and KSC"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","name":"NIS2 and KSC"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","position":2,"name":"NIS2 and KSC","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#listItem","name":"Where should the board begin preparing for NIS2?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#listItem","position":3,"name":"Where should the board begin preparing for NIS2?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","name":"NIS2 and KSC"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski","url":"https:\/\/www.lablogic.pl\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski-portret","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/michal-rutkowski-iod-dpo-rodo-nis2-lablogic.webp","width":864,"height":1080,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/","name":"Preparing for NIS2 \u2014 two board decisions come first","description":"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"creator":{"@id":"https:\/\/www.lablogic.pl\/#michal-rutkowski"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg","@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#mainImage","width":1200,"height":630,"caption":"Where should the board start with NIS2? \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/#mainImage"},"datePublished":"2026-06-23T09:10:00+02:00","dateModified":"2026-10-03T20:25:43+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"NIS2 starts with responsibility","og:description":"Boards start with qualification and responsibility, not implementation.","og:url":"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg","og:image:width":1200,"og:image:height":630,"article:section":"NIS2 and KSC","article:tag":["nis2","ksc","board","compliance"],"article:published_time":"2026-06-23T07:10:00+00:00","article:modified_time":"2026-10-03T18:25:43+00:00","twitter:card":"summary_large_image","twitter:title":"NIS2 starts with responsibility","twitter:description":"Boards start with qualification and responsibility, not implementation.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg"},"aioseo_meta_data":{"post_id":"3921","title":"Preparing for NIS2 \u2014 two board decisions come first","description":"Boards start NIS2 with responsibility and qualification, not implementation. The order of decisions, the KSC Act deadlines and a first-decisions checklist.","keywords":null,"keyphrases":{"focus":{"keyphrase":"preparing for NIS2","score":0},"additional":[{"keyphrase":"NIS2 board responsibilities","score":0},{"keyphrase":"NIS2 implementation steps","score":0},{"keyphrase":"Polish KSC Act obligations","score":0},{"keyphrase":"where to start with NIS2","score":0}]},"primary_term":null,"canonical_url":null,"og_title":"NIS2 starts with responsibility","og_description":"Boards start with qualification and responsibility, not implementation.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"NIS2 and KSC","og_article_tags":[{"label":"NIS2","value":"NIS2"},{"label":"KSC","value":"KSC"},{"label":"board","value":"board"},{"label":"compliance","value":"compliance"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":0,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-18 09:57:45","updated":"2026-10-03 18:26:53","seo_analyzer_scan_date":null,"focus_keyword":"preparing for NIS2","additional_keywords":[{"word":"NIS2 board responsibilities","score":0},{"word":"NIS2 implementation steps","score":0},{"word":"Polish KSC Act obligations","score":0},{"word":"where to start with NIS2","score":0}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-where-should-the-board-begin-preparing-for-nis2-en-1.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=3921"}],"version-history":[{"count":6,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3921\/revisions"}],"predecessor-version":[{"id":5800,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/3921\/revisions\/5800"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5576"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=3921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=3921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=3921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}