Section 38 BSIG: German Managers Must Train on Cyber Risk

Thomas Eriksson··5 min read
Executives in a boardroom discussing the management cybersecurity training duty under Section 38 BSIG

For German managing directors, cybersecurity has stopped being something that can be fully handed to the CISO. Section 38 of the amended BSIG, the law implementing NIS2 in Germany, makes cybersecurity training a personal duty of the Geschaeftsleitung and pairs it with personal liability for failures of oversight. The BSI has now published an official information package spelling out what that training must cover. Taken together, these developments turn management training from a goodwill gesture into a documented legal expectation with the manager's own assets behind it.

A Duty the Board Cannot Delegate

Section 38(3) BSIG obliges the management of important and particularly important entities to regularly attend cybersecurity training. Legal commentators are unambiguous on the decisive point: the duty is non-delegable. A managing director cannot satisfy it by ensuring the IT team is well trained, by appointing a qualified security officer, or by sending a deputy to the sessions. The obligation attaches to the members of the management body personally, and each of them has to attend.

The population affected is large. According to German trade coverage, roughly 29,500 entities fall under the regime, which has been in force since December 2025 with no transition period. For every one of those organizations, the management training duty is not a future compliance milestone. It applies now.

What the BSI Says the Training Must Cover

Boards no longer need to guess what adequate training looks like. The BSI has published an official information package, NIS-2-Geschaeftsleitungsschulung, which specifies the competence fields management training should build:

  • Identifying risks. Managers must be able to recognize the cybersecurity risks their entity actually faces, from ransomware and social engineering to supply-chain compromise.
  • Assessing risk-management measures. The training must equip managers to evaluate whether the measures their organization has implemented are appropriate to those risks.
  • Judging the impact on services. Managers should be able to assess what the measures, and the risks they address, mean for the services the entity delivers.

The BSI recommends annual training. That combination of defined competence fields and a recommended cadence sets a clear benchmark: a generic thirty-minute e-learning module that never touches the entity's own risk picture will struggle to demonstrate that these specific competences were built, let alone maintained year over year.

The competence fields also hint at format. All three are judgment skills rather than recall skills, which points toward scenario-based content: walking the management body through a realistic incident affecting its own services, asking whether the current measures would have held, and forcing an explicit assessment of the trade-offs. Training built that way produces exactly the competences the BSI names, and it is far easier to defend than a certificate of attendance for an off-the-shelf course. Organizations should also plan for turnover: a director who joins mid-year inherits the duty on day one, so onboarding into the training cadence belongs in the appointment checklist alongside the commercial-register filing.

Approval, Supervision, and Personal Liability

The training duty does not stand alone, and its logic only becomes clear next to the rest of Section 38. Under Section 38(1) and (2), the management body must approve the entity's risk-management measures under Section 30 and supervise their implementation. The sanction is what makes this bite: a culpable breach of these duties leads to personal liability of the managers toward the entity. If the company suffers damage because the management body neglected its approval and oversight obligations, the managers can be held to account for it personally.

Seen through that lens, Section 38(3) is not a box-ticking add-on. Managers cannot meaningfully approve risk-management measures they do not understand, and they cannot supervise implementation they cannot assess. The training duty exists to make the approval and oversight duties real, and the liability rule exists to make all three unavoidable. A director who skipped the training will find it considerably harder to argue, after an incident, that their oversight of the Section 30 measures met the required standard of care.

Building a Defensible Training Record

Because the consequences are personal, the evidence should be too. A defensible record under Section 38 has a few practical components: dated attendance records for each member of the management body, not a single collective entry; a curriculum mapped explicitly to the BSI's competence fields, so the content can be shown to match the official expectation; an annual cadence with refreshed material, reflecting the BSI's recommendation; and board minutes that document when risk-management measures were reviewed and approved, connecting the training to the oversight duties it supports.

Management training is also only one layer of the law's people requirements. Section 30 BSIG expects risk-management measures that include cyber hygiene and security awareness training at staff level, so an entity whose board is trained but whose workforce is not remains exposed on a core duty. Running both layers through one platform, with completion records and phishing simulation results as compliance evidence, keeps the whole human dimension auditable, which is exactly the pattern empowsec is designed to support. For what the underlying directive expects from staff-level programs, see our guide to NIS2 security awareness training requirements.

What This Means for Your Organization

  • The duty is personal and non-delegable. Section 38(3) BSIG requires the management of important and particularly important entities to regularly attend cybersecurity training themselves.
  • The BSI has defined the bar. Its NIS-2-Geschaeftsleitungsschulung package names the competence fields, identifying risks, assessing risk-management measures, and judging their impact on services, and recommends annual training.
  • Liability is the enforcement mechanism. Culpable breaches of the approval and oversight duties in Section 38(1) and (2) expose managers to personal liability toward their own entity.
  • Evidence per person, per year. Keep dated attendance records for each director, a curriculum mapped to the BSI fields, and minutes showing measures were approved and supervised.
  • Do not stop at the board. Section 30 expects staff-level cyber hygiene and awareness training too, and both layers should produce records you can hand to a supervisor.
Share: