In 2024, the NIS2 Directive came into effect in Europe introducing specific measures, reporting obligations and personal liabilities to mitigate risks for societal digital disruption. We conducted an inductive study and interviewed 29 CISO’s and IT or C-level executives from large, NIS2 affected, organizations in The Netherlands and validated the outcomes with 300+ cybersecurity professionals through various workshops.