Ignorance Is No Defense: Why Cyber Risk Training for Boards Is No Longer Optional — or Enough
For centuries, ignorantia juris non excusat,meaning ignorance of the law excuses no one, has been one of the quieter foundations of legal accountability. Nobody escapes liability by claiming they never read the statute. Three pieces of EU legislation have now applied that same principle, explicitly, to the boardroom: NIS2, DORA and the AI Act each make a director's or executive's ignorance of cyber and AI risk a matter of personal legal exposure, not merely a governance gap.
That is a significant shift. Cybersecurity has traditionally been something the board received briefings on. Under this new generation of EU regulation, it is something board members are individually required to understand.

What the regulators now require
NIS2 (Directive (EU) 2022/2555), in force for essential and important entities since October 2024, does two things in the same article. Article 20(1) requires management bodies to approve the entity's cyber risk-management measures and to oversee their implementation, and it allows them to be held liable for the entity's non-compliance. Article 20(2) then closes the obvious loophole: management body members must themselves follow regular training so they have sufficient knowledge and skill to identify risks and assess the adequacy of the measures they are approving. You cannot discharge an oversight duty over something you do not understand, so the regulation now mandates the understanding as a precondition of the oversight.
DORA (Regulation (EU) 2022/2554), which applies across the financial sector, goes further in one respect: the obligation in Article 5(4) is explicitly individual, not collective. Each member of the management body must actively keep their own knowledge of ICT risk current, through training proportionate to the ICT risk the entity carries. Article5(2)(g) additionally requires the board to approve and periodically review the budget for that training, turning “did we fund this properly” into its own governance question.
The AI Act (Regulation (EU) 2024/1689) extends the same logic beyond cyber into AI governance. Article 4, in force since February 2025, requires providers and deployers to ensure a sufficient level of AI literacy among staff and anyone else operating AI systems on their behalf, calibrated to each person's role and the context of use. For executives who approve AI-enabled products, sign off on high-risk use cases, or use AI-generated analysis to assist their decision-making, there is an obligation to have a level of AI literacy that is appropriate to their role.
Across all three, the pattern is the same: attendance is necessary but the standard being set is comprehension, and comprehension sits with the individual, not the institution.
Where most training programs stop short of the standard
Here is the uncomfortable part. A great deal of executive cyber training satisfies the letter of these obligations: a session was held, attendance was logged, a certificate was issued, without moving the needle on what the requirement actually cares about: whether that executive can now identify a risk and assess whether the measures in front of them are adequate. Being informed and being able to exercise judgment are not the same thing, and regulators, auditors and, eventually, courts will be testing for the latter.
Nowhere does this gap show up more clearly than in how boards consume the numbers their CISO puts in front of them.
A number is not an understanding
Most boards now receive some form of quantified cyber risk reporting: a risk score, a maturity percentage, an estimate of annual loss exposure, a probability of a material breach. This is progress: it is far better than a red-amber-green heatmap with no defensible basis. But a number, on its own, discharges neither the NIS2 duty to assess nor the DORA duty to understand.
If a CISO reports that “annual loss exposure has increased from €2M to €3.5M,” an executive with active oversight will be able to ask informed questions to understand:
● Where did this number come from? Internal incident data, industry benchmarks, expert judgment calibrated against a model: each carries a different level of confidence, and a defensible figure should be able to say which.
● What does the range around it hide, or reveal? A single point estimate implies a precision that cyber risk rarely has. The most likely outcome and the tail (the low-probability, high-severity scenario) call for different responses, mitigation versus insurance or reserved capital, so aboard that only sees one number cannot make that distinction.
● What changed, and why? An increase driven by a genuinely worsening threat landscape calls for a different response than one driven by better data collection revealing a risk that was always there.
● What decision is this number meant to support? A metric presented without a linked decision is a status update, not risk management.
An executive who nods at “7.2 out of 10” or“€3.5M” without being able to ask these questions has attended training, but has not met the standard NIS2 Article 20(2) and DORA Article 5(4) actually describe. The regulatory bar is not “the board was told a number.” It is “the board understood enough to challenge it.”
The practical implication
Cyber risk training for executives and board members needs to do more than transfer awareness of threats and terminology. It needs to build the specific, durable capability to interrogate quantitative risk reporting: to ask about provenance, to read a range rather than a point estimate, and to connect a figure to the decision it is meant to inform. Anything short of that leaves the organization compliant on paper but exposed in substance, which is precisely the gap NIS2, DORA and the AI Act were written to close.
This is precisely the gap C-Risk's Meeting your oversight obligations under NIS2, DORA and the EU AI Act is designed to close. Rather than transferring awareness of threats and terminology, the program builds the specific capability regulators are testing for: the ability to interrogate a CISO's quantified risk reporting, question its assumptions and provenance, and connect a figure to the decision it is meant to inform, so that executives and board members can demonstrate, not merely assert, the standard of understanding required under NIS2 Article 20(2), DORA Article 5(4) and AI Act Article 4.
Ignorance was never a defense. Under EU regulation, it is now explicitly a liability.
How should executives be trained to meet their obligations under NIS2, DORA and the AI Act?
Training must go beyond regulatory awareness: NIS2, DORA and the AI Act all require executives to demonstrate the judgment to assess risk, not just attend a session. C-Risk's Defensible Cyber Risk Governance for Executives program builds exactly this capability, teaching boards to interrogate their CISO's risk reporting and make defensible, informed decisions.
Who is liable if a company fails to comply with NIS2, DORA or the AI Act?
Individual board members and executives, not just the organization. NIS2 Article 20, DORA Article 5 and AI Act Article 4 each make personal ignorance of cyber and AI risk a matter of direct legal exposure. C-Risk helps management bodies close this gap and demonstrate genuine oversight, not just compliance on paper.
Why train company executives in risk governance?
Because untrained oversight is indefensible: a board that cannot question a risk figure hasn't met itsregulatory duty, whatever training it has attended. C-Risk equips executives with the quantitative risk expertise to challenge reporting, ask the right questions and make sound governance decisions, turning compliance into genuine risk management.
Related articles
Read more on cyber risk, ransomware attacks, regulatory compliance and cybersecurity.

