GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm
2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation Pursuant to Law 5160/2024, entities classified as “essential” or “important” are required to implement specific cybersecurity risk‑management measures, incident‑reporting obligations, governance process - es, and to comply with supervisory and enforcement mechanisms. The criteria used to classify entities into these two categories are based on the nature and sector of their activity as well as their size. The sectors covered by the regulatory framework include: • energy; • transport; • banking; • financial markets; • health; • drinking water and wastewater management; and • digital infrastructure. The framework also encompasses digital providers such as online marketplaces, search engines, and social networking services. In addition, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) fall within the scope of Law 5160/2024 when they provide ICT or security services on a large scale and are con - sidered part of the digital infrastructure or ICT services category. This effectively extends compliance require - ments across the broader services market. Law 5160/2024 applies to all medium‑sized or large organisations within the above sectors (indicative - ly, those with more than 50 employees or turnover exceeding EUR10 million). Smaller entities may also be included when they are the sole providers of an essential service or when the disruption of their opera - tions is considered to have a significant social impact. Furthermore, public administrations that provide critical public services or state functions are explicitly covered – even if they do not meet the size criteria
– with the aim of protecting critical government infor - mation systems. However, several aspects of the law remain open to interpretation or are still awaiting further guidance. • Definition of “digital infrastructure” – although the law applies to digital infrastructure providers, it does not clearly define which modern digital services qualify as infrastructure as opposed to “online services” or “digital platforms”. • The “significant impact” exception – neither NIS2 nor Law 5160/2024 sets quantitative thresholds for determining what constitutes a “significant impact”. • Scope of managed service providers – the law does not clarify which MSP business models are automatically included within its scope. 2.2 Critical Infrastructure Cybersecurity Requirements Law 5160/2024 establishes requirements for imple - menting appropriate technical and organisational measures to manage cybersecurity risks. These obligations are further specified in Greece’s National Cybersecurity Requirements Framework, set out in JMD 1689/2025, which provides a detailed checklist for essential and important entities. The main areas of focus are as follows. Governance and Accountability A cyber governance plan is required, ensuring that risk oversight is carried out at senior management level and that specific responsible officers are appointed. Notably, organisations must designate an Informa - tion and Communications Systems Security Officer (ICSSO – equivalent to a CISO) by name, who must also report to the NCSA. Senior management bears responsibility for compliance, as the legislation explic - itly holds CEOs and directors accountable if they fail to ensure adequate measures or proper incident handling. Organisations must maintain an informa - tion security policy covering the entire organisation, supported by individual policies, with clearly defined roles and responsibilities. Regular updates to senior management are required, along with submission of an annual cybersecurity report to the NCSA.
168 CHAMBERS.COM
Powered by FlippingBook