NIS2 has moved cybersecurity into the boardroom, but the real challenge is whether directors can understand the evidence well enough to govern it.