The case, explained
Cybersecurity and Directors' Liability: Failure to Oversee Technological Risks
6 min read · Updated August 2026 · Editorial oversight: Avv. Federico Papa
The landscape of directors' liability underwent a radical transformation in the 2023-2024 period, driven by the definitive integration of corporate governance and information security. According to press reports, recent jurisprudential developments have clarified that the duty to establish adequate organizational structures can no longer ignore robust data protection, turning cybersecurity from a technical cost into a pillar of director liability. In this article, we will analyze how the omission of technological protocols constitutes a direct breach of legal obligations, narrowing the protective scope of the Business Judgment Rule. Through our usual twin case, we will explore the civil and governance consequences for those who ignore digital red flags.

In brief
The article examines directors' liability for failing to implement cybersecurity measures. Analyzing Articles 2086 and 2381 of the Italian Civil Code, it highlights how the lack of technological structures constitutes a breach of a procedural duty not protected by the Business Judgment Rule. The piece explores the impact of Legislative Decree 138/2024 (NIS 2) and the Milan Court's position on liability actions filed following ransomware attacks and cyber fraud.
The facts
According to reports by outlets such as BeBeez and Milano Finanza, there has been a significant increase in liability actions against corporate boards that suffered massive losses due to ransomware attacks or so-called CEO Fraud schemes. The cases, which saw several rulings on the merits by the Milan Business Court, involve directors accused of failing to implement even basic digital defense measures.
Many of these cases are currently pending in first instance, where bankruptcy trustees or new shareholders challenge not the failure of a technical choice, but the total absence of IT governance. Specifically, recent orders have highlighted how the failure to oversee information flows and the lack of incident response protocols exposed companies to unreasonable risks, leading to the removal of corporate officers and claims for millions in damages due to business interruptions.

The rules at play
The regulatory framework revolves around three fundamental pillars:
- Art. 2086, paragraph 2, c.c., which imposes the duty to establish an organizational setup adequate to the nature and size of the business, now permanently incorporating the digital component;
- Art. 2381 c.c., specifying the duty of delegated bodies to setup and maintain such arrangements and of the board to assess their adequacy based on information flows;
- Legislative Decree 138/2024, transposing the NIS 2 Directive, which introduces direct personal liability for governing bodies for failing to approve and oversee cyber risk management measures. A breach of these provisions entails joint and several liability under Art. 2392 c.c. for damages caused to the company and to creditors.
What the case law says
Case law on the merits has clarified a fundamental distinction: the Business Judgment Rule protects management discretion, but not the omission of procedural duties. Judges have affirmed that establishing an adequate organizational setup is not an unreviewable business choice, but a pre-decisional legal duty.
According to established case law, a director is liable when ignoring red flags or failing to activate the necessary information flows. In the technological sphere, the lack of a disaster recovery plan or the absence of staff training are not considered unfortunate business decisions, but rather professional negligence for failing to exercise the diligence required by the nature of the office. Higher court jurisprudence in related fields has specified that risk monitoring must be continuous and documented, making digital inertia a ground for liability when damage is foreseeable.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
- Constantly monitor the recording in the minutes of information flows between the IT department and the Board to prove compliance with the duty to act in an informed manner.
- Advise clients to adopt certified minimum protocols (e.g., ISO 27001) in order to raise the defense of having implemented abstractly adequate setups.
- Verify that D&O (Directors & Officers) policies do not contain specific exclusions for cybersecurity damages stemming from gross organizational negligence.
References: Art. 2086 c.c.Art. 2381 c.c.Art. 2392 c.c.D.Lgs. 138/2024Direttiva NIS 2
Related cases

Frequently asked questions
Is a director liable even if the attack is technically highly sophisticated?
The director is liable not for the hacker's skill, but for the potential absence of protocols that could have mitigated the risk or facilitated data recovery.
Does the Business Judgment Rule protect the decision not to invest in cybersecurity due to budget constraints?
No, if such a choice leads to the total absence of basic organizational structures; the adequacy of setups is a statutory duty outside non-reviewable discretion.
What criminal risks does a director face in the event of a cyberattack?
Beyond civil liability, if the attack causes the company's collapse, charges of simple bankruptcy may arise due to the failure to adopt necessary precautions.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free