> It's fine + obligation to fix, and daily fine until fixed, and higher fine if you do it again.
The important proviso is that the penalties need to (on some non-geological timescale) get high enough that the offender is no longer capable of operating. That could mean the fines reach $500 billion, or it could mean the company is barred from operating in the EU, or it could mean people get arrested and assets are seized. But unless the penalties become crippling, it won't matter. It needs to reach a point where the downsides of noncompliance are actually greater than the benefits.
NIS2 allows for the arrest of managers in case of cybersecurity incidents resulting from negligence. I think it's a step in the right direction, but we'll have to see how it plays out.
The important proviso is that the penalties need to (on some non-geological timescale) get high enough that the offender is no longer capable of operating. That could mean the fines reach $500 billion, or it could mean the company is barred from operating in the EU, or it could mean people get arrested and assets are seized. But unless the penalties become crippling, it won't matter. It needs to reach a point where the downsides of noncompliance are actually greater than the benefits.