·Consumer·Minds Team

Minds Study: NIS2 Liability Risks in the German Mittelstand

How do German managing directors react to personal liability under Section 38 BSIG? A Minds target audience simulation with 500 IT and business decision-makers.

Q1Scale010
How strongly does personal liability under Section 38 BSIG influence your purchasing decision for cybersecurity solutions?
  • 0
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
Average
6.9

The majority of Mittelstand decision-makers rate personal liability relevance as an absolutely critical factor when selecting new security vendors.

  • 15+ stats with cross-tabs by age, country, income
  • 5 downloadable charts
  • Raw response data (CSV)
  • Ask your own questions in this Study
Unlock the full study for free

Methodology

A representative simulation on the Minds platform with 500 simulated decision-makers from the German Mittelstand shows that the personal liability of managing directors under Section 38 BSIG has become the primary driver for cybersecurity investments in 2026, with results correlating closely with validation data from the Federal Statistical Office (Statistisches Bundesamt) on the structure of the German Mittelstand.

72%

Concern over personal liability with private assets

64%

Lack of documentation for the statutory approval obligation

31%

Skepticism toward purely technical IT reports lacking business context

Based on a simulated Audience of 500 respondent. Benchmark agreement varies by audience, question, grounding, and reference study.

Audience composition

Company size by employees
  • 1
    50-249 employees (Important entities)60%
  • 2
    250-499 employees (Essential entities)40%
Focus of NIS2 preparation
  • 1
    Focus on purely technical infrastructure68%
  • 2
    Focus on personal liability protection & governance32%
NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG) im Bundesgesetzblatt
BSI-Gesetz (BSIG) § 38 Haftung und Schulungspflichten der Geschäftsleitung

The introduction of the NIS2 Implementation Act (NIS2UmsuCG) on December 6, 2025, fundamentally changed the legal landscape for the German Mittelstand. While in the past, fines primarily targeted the company as a legal entity, the reformed Section 38 of the BSI Act (BSIG) establishes direct, non-delegable personal internal liability for board members and managing directors.

To understand how this legal tightening affects purchasing decisions and messaging resonance in the B2B sector, Minds conducted a precise target audience simulation. The simulated panel reflects the demographic and psychographic structure of 500 decision-makers in companies with 50 to 499 employees that fall under the categories of Important entities or Essential entities. The calibration of the behavioral models was based on established psychographic segmentation models and validated against real reference data from national statistical authorities and market observers such as Kantar.


Shifting Priorities: From the Server Room to the Liability Cabin

The simulation results highlight a massive discrepancy between the previous technical focus of cybersecurity projects and the actual concerns of executive management. While IT departments continue to discuss network architectures, endpoint security, and zero-trust models, CEOs and CFOs are increasingly focusing on legally safeguarding their own persons.

D
Dr. Andreas Neuhaus, 52, DüsseldorfManaging Director (CEO)

Technical security is one thing, but having to stand up personally with my private assets for documentation gaps under Section 38 BSIG keeps me awake at night. Our IT service providers only ever sell us firewalls, not legally compliant governance.

Under Section 38 BSIG, business leaders must not only actively approve the company's risk management measures, but also continuously monitor their implementation. Simple delegation to the CISO or an external Managed Service Provider (MSP) does not release management from personal liability with private assets in the event of damage. This legal reality is reflected in the Minds simulation: 72% of simulated managing directors express acute concern about this personal liability.

For cybersecurity vendors, this means a radical shift in the sales approach. Technical features and pure performance metrics lose relative weight as soon as they are not placed in the context of liability-exempting documentation. A product that fails to deliver audit-proof reports for the board is increasingly rejected in the decision-making process.


The Unresolved Documentation Gap in the Mittelstand

Although the law has been in force since the end of 2025 without a transition period, the simulation shows a significant backlog in the formal implementation of governance duties. 64% of simulated decision-makers stated that their companies lack sufficient, time-stamped documentation of the formal approval of security measures.

S
Sabine Lindner, 47, StuttgartCFO & Compliance Officer

We do have technical security measures in place, but we completely lack a formal management resolution approving our risk management measures. If the BSI audits us tomorrow, we are standing with one foot in liability risk.

The three core duties of management under Section 38 BSIG include:

  1. Formal approval: Risk management measures under Section 30 BSIG must be actively and verifiably approved by management. Informal consent is not sufficient.
  2. Continuous monitoring: Management must regularly monitor the actual implementation of the measures. In practice, management reviews are recommended at least quarterly.
  3. Personal training obligation: Managing directors must verifiably participate in regular training sessions to adequately assess information security risks.

Security vendors addressing this gap by offering automated compliance reports, audit trails, and easy-to-understand dashboards for non-technical users position themselves directly as liability relief partners for management.


The Changing Role of the CISO in the Purchasing Process

The simulation also shows that the dynamic between the IT level and executive management is intensifying. CISOs and IT directors are under considerable pressure to provide the board with understandable templates that can serve as proof of compliance with monitoring duties.

M
Markus Tegtmeier, 44, NürnbergCFO

My board is suddenly demanding proof of my training and wants to co-sign every security report quarterly. The purely technical CISO role is rapidly transforming into a legal safeguarding function.

Around 31% of simulated IT decision-makers complain that existing security reports are too technical to be used as a sound basis for decision-making at the board level. When a CISO proposes purchasing a new security solution, they must increasingly answer the question: How does this investment protect us from personal claims by the BSI or within the scope of internal liability?

Sales teams of software and service vendors must therefore urgently adapt their sales enablement content. Whitepapers, case studies, and pitch decks should not only emphasize the technical superiority of a solution, but also explicitly demonstrate how the software facilitates compliance with the obligations under Section 38 BSIG.


Strategic Implications for B2B Cybersecurity Vendors

The insights from this Minds simulation allow marketing and sales directors in the cybersecurity sector to precisely calibrate their go-to-market strategy for 2026. Since the target audience is in the bottom-of-funnel (bofu) phase and under acute pressure to act, the following adjustments promise the highest sales velocity:

  • Liability-oriented messaging: Shift the focus of your advertising messages from We protect your servers from ransomware to We secure your management against personal liability risks under Section 38 BSIG.
  • Audit-proof reporting features: Actively promote features such as automated audit logs, time-stamped approval processes, and clear executive summaries that can flow directly into management reviews.
  • Training bundles as door openers: Since personal training for management is legally mandated, vendors can gain a significant competitive advantage by bundling software licenses with certified executive training.

By using the Minds target audience simulation, vendors can test such messaging hypotheses in less than an hour on highly precise, GDPR-compliant segments before rolling out expensive campaigns in the physical market. Compared to classic market studies, this saves significant resources and eliminates the risk of mispositioning in the highly competitive cybersecurity market of the German Mittelstand.

If you want to find out how your specific product claims and sales arguments resonate with the liability concerns of German managing directors, we invite you to launch a customized simulation on our platform.

Secure your advantage in B2B sales now and schedule a personal meeting with our experts to experience a live demo of the Minds simulation for your target audience.

Book a demo now and learn about our methodology

Frequently asked questions

How high is the validity of Minds simulations for complex B2B topics like NIS2?

Minds achieves an average match of 85% to 95% with traditional physical panels. For highly specific questions and precisely anchored segments, such as Mittelstand managing directors in the DACH region, the match can even reach up to 100%.

How fast does Minds deliver results for niche target audiences in the German Mittelstand?

While classic market studies and panel surveys take several weeks, the Minds platform delivers deep, quantitative and qualitative insights in under an hour.

Are the simulated data and personas GDPR-compliant?

Yes, Minds is hosted entirely on servers within the European Union and is 100% GDPR-compliant. Since no actual personal data of real survey participants is processed, the typical legal risks of classic panels are eliminated.

How does this simulation help B2B cybersecurity vendors close deals?

The results reveal an extreme NIS2 compliance urgency at the board level. Vendors who shift their marketing and sales messaging from purely technical protection to personal liability relief under Section 38 BSIG hit the exact bofu purchase decision trigger of budget owners.

About Minds

Minds is an AI research lab building synthetic focus groups and studies. It helps go-to-market and product teams understand their target audiences in minutes, not months.