NIS2 Directive: The 20% Is 80% of the Point
- Jonathan Main

- 23 hours ago
- 3 min read
Why the smallest layer of a NIS2 programme carries most of the Directive's intent
Most NIS2 programmes allocate their effort in proportion to the work in front of them. The technical build absorbs the majority of it. The executive layer absorbs a fraction. That allocation is reasonable, and it is also where the exposure concentrates: the layer that carries the least effort carries most of what the Directive was written to change.
Two Splits That Point in Opposite Directions
A NIS2 programme contains two allocations, and they run against each other.
The first is the effort split. Roughly four-fifths of the work goes into the technical build: the risk-management measures, the ISMS, detection, response. The remaining fifth touches the management body directly: approval, oversight, training, demonstrable leadership. The technical work is larger in scope, and most organisations that reach this point have resourced it well.
The second is the intent split, and it runs the other way. The share of effort spent on the executive layer is small. The share of the Directive's purpose that sits there is large. These are separate questions, and the answer to one has been mistaken for the answer to the other.
What the Effort Split Gets Right
The effort allocation is sound on its own terms.
Technical controls, detection, and response require sustained resourcing, specialist skill, and continuous maintenance. An organisation that under-resources this layer is exposed in an immediate and visible way. The weight the technical build receives is proportionate to the work it demands.
The effort split describes where the work sits. It is a reliable guide to that, and to little else. In particular, it describes where the labour concentrates, while remaining silent on where the consequence concentrates.
What the Intent Split Reveals
NIS2 did not introduce the expectation that organisations should hold strong cybersecurity. That expectation predates the Directive in several forms. What NIS2 introduces distinctly is personal accountability for the people who lead the organisation.
That accountability is the genuinely new exposure. In ISOMETRI's assessment, it is the primary mechanism by which the Directive expects to change behaviour: through making the people who set organisational priorities personally answerable for whether cybersecurity was resourced, followed, and acted upon.
Read this way, the layer most programmes treat as secondary carries close to the whole of the Directive's actual point. The 20% of the effort is 80% of the intent.
Why the NIS2 Directive Leans on People, Not Only Controls
Controls can be documented, delegated, and maintained by a technical function. Accountability behaves differently. It sits with named individuals, and it is discharged by them through decision and oversight, or it is left undischarged.
This is the reason the executive layer resists the treatment applied to the technical layer. It can be surfaced, escalated, and evidenced, and it remains the management body's to hold throughout. It closes out through demonstrated approval and continuous oversight, on the record, exercised by the body the Directive names. The technical layer produces systems. The executive layer produces decisions, and decisions require a decision-maker who can be identified after the fact.
NIS2 as a Current Example of a Recurring Pattern
This imbalance is characteristic of assurance work in general. The layer carrying the least effort tends to carry the most consequence, and it is the layer most often left unexamined, because it is harder to delegate and easier to defer. It is the same principle set out in The Responsibility Threshold: what governs the need for oversight is the responsibility carried, not the volume of activity that surrounds it.
NIS2 is the current, visible, time-pressured instance of that pattern for organisations in scope of the Directive today. The same imbalance — effort weighted toward the technical, consequence weighted toward the accountable — appears wherever assurance is treated as a technical exercise. It is the same shift from operational performance toward demonstrable oversight examined in NIS2 Director Accountability, applied to the internal structure of a single programme.
Where This Leaves Most Programmes
Most organisations are not behind on the technical work. It is, in the majority of cases, already well advanced, owned, and resourced.
What has rarely happened is an independent check on the executive layer, and the reason is structural: it was never separated out as a distinct thing to check. It sits inside the programme as a single line, easy to read as complete because the technical rows around it are progressing. This is the threshold examined in When Governance Becomes Critical: the point at which what an organisation carries has outrun what its existing oversight can quietly absorb. The layer that carries most of the Directive's intent is the one most likely to pass unexamined, precisely because it demands the least effort to record and the most authority to discharge.


Comments