The rise of digital liability for directors

Cyber Security Colleagues
Cyber attacks, phishing and data breaches were long regarded as operational or IT risks. However, regulations such as the GDPR, NIS2, DORA, the EU Cybersecurity Act, the AI Act, the Digital Services Act (DSA) and the Data Act, combined with an increasingly challenging cyber threat landscape, have turned digital security into a board-level issue.  

Digital resilience is more and more recognised as an essential element of good governance and is therefore becoming a key consideration in directors’ liability. More broadly, it is also a shared responsibility of management and the wider leadership team that reports to the board.  

Digital Risks are a board responsibility 

Under Belgian law, directors are expected to act with the level of care and diligence that a reasonably prudent director would exercise in comparable circumstances. This duty of care evolves alongside the risks faced by organisations.  

A director may face personal liability where their actions, or failure to act, clearly fall outside the range of decisions on which a reasonably prudent director could differ. In certain situations, this liability may arise both internally and towards third parties (art. 2:56-2:58 NWVV). 

Boards have long been expected to oversee financial, tax and compliance risks. Today, the same applies to digital security. This requires more than technical safeguards alone. Boards must provide strategic direction for cyber security, operational IT risks, data governance and AI within an increasingly complex regulatory environment. They are responsible for establishing policies that support digital security, assigning responsibilities and encouraging employees to follow the rules.  

Digital security as a governance issue

Most cyber incidents do not begin with a sophisticated attack. They start with a simple phishing email and a human error. The consequences, however, can be significant: financial fraud, operational disruption, data breaches, reputational damage and statutory notification obligations.  

Shadow AI, meaning the use of unauthorised AI applications outside the organisation’s oversight, also creates tangible security risks. These may include the sharing of confidential information with AI providers and their subcontractors, uncontrolled access to data, and dependence on unknown or insecure suppliers.  

While shadow AI can never be eliminated entirely, it is often a symptom of policies that are unclear or impractical to implement. Boards should ensure that policies not only provide protection but are also workable in practice and encourage compliance. Ideally, this is achieved not through punishment, but by making the secure option the easiest option.  

Where an incident reveals that known risks were ignored, recommendations were not followed up, or digital security was never discussed at board level, questions regarding directors’ liability may quickly arise. 

Not every incident leads to liability

Naturally, a director does not become liable simply because a cyber incident occurs. As with other business risks, the assessment will primarily focus on the adequacy of the organisation’s governance and decision-making. The key question will be whether the board can demonstrate that it: 

  • Identified the relevant digital risks, 
  • Sought and relied on appropriate expertise, 
  • Implemented suitable measures, 
  • Oversaw their execution, and 
  • Properly documented its decisions.  

If so, the occurrence of an incident alone will generally not be sufficient to establish liability. As noted above, similar considerations may also extend to members of management, with potential consequences within the boundaries of employment law and internal policies.  

Direct claims by third parties

The growing focus on directors’ liability is further reinforced by the abolition of the quasi-immunity previously granted to auxiliary agents under Book 6 of the Belgian Civil Code. In exceptional circumstances, this may allow a company’s contractual counterparties to bring a direct claim against a director for a personal fault committed in the performance of their duties. One example could be a leak of commercially sensitive information relating to a supplier, causing reputational damage or direct financial loss to that supplier. See: Book 6 Civil Code and vicarious liability - BDO Legal.

Conclusion

Current legislation on digital security does not create a new regime of directors’ liability. What it does make clear is that digital security, encompassing cyber security, operational resilience, data protection and the safe use of AI, forms part of a director’s governance responsibilities.  

Boards are not expected to manage every technical detail. They are, however, expected to determine risk appetite, set security priorities, allocate responsibilities and establish effective oversight. Robust digital security governance also builds trust and promotes compliance throughout the organisation.  

For directors, digital resilience is becoming what ESG became several years ago: not a technical side issue, but a core component of good governance. Failure to take digital risks into account when making board-level decisions may expose an organisation not only to operational harm, but also to scrutiny of the directors’ own duty of care.