The National Cyber Security Centre (NCSC) has released a crucial piece of guidance for management board members of organizations subject to the EU's NIS2 directive on cybersecurity. This directive mandates that these management bodies not only approve but also oversee cybersecurity risk management measures and ensure their personnel undergo comprehensive cybersecurity training. The NCSC's guidance is a vital resource for accounting officers and senior managers, helping them navigate their cybersecurity responsibilities under the directive. At the heart of this guidance is the NCSC's Cyber Fundamentals Framework (CyFun), a risk-based approach designed to assist organizations in translating their legal obligations into practical actions. The NCSC views NIS2 as a significant milestone in the legislative landscape, marking a shift in accountability for cybersecurity risk management to the highest levels of executive management. This shift is a recognition of the evolving nature of cybersecurity, which has moved beyond being a technical issue confined to server rooms to becoming a critical priority at the boardroom level. Minister for Justice Jim O'Callaghan emphasized the importance of this development, stating that Ireland's economic prosperity and social well-being are deeply intertwined with the resilience of its digital infrastructure. The CyFun framework is a cornerstone of the NCSC's strategy, providing a structured approach to cybersecurity risk management. It is designed to be adaptable, allowing organizations to tailor their cybersecurity practices to their specific needs and contexts. By adopting CyFun, management boards can ensure that their organizations are not only compliant with the NIS2 directive but also proactively prepared for the evolving cybersecurity landscape. The NCSC's guidance and the CyFun framework are essential tools for organizations to navigate the complexities of cybersecurity risk management. They empower management boards to take a proactive approach, ensuring that cybersecurity is not just a technical concern but a strategic priority that is integrated into the organization's core operations. This shift in perspective is crucial for the future of cybersecurity, as it emphasizes the need for leadership at all levels to take ownership of cybersecurity risks and ensure the resilience of digital infrastructure.