GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm
Risk Assessment and Asset Management Organisations must maintain an up‑to‑date inven - tory of assets (hardware, software, data and network assets), prioritised according to criticality and risk. Periodic risk assessments must identify threats and vulnerabilities affecting critical processes, applying controls based on a recognised risk management methodology (often aligned with ISO 27005 or similar standards). These assessments must also address supply‑chain risks, including those associated with suppliers and service providers. Basic Technical and Organisational Measures The National Framework outlines a set of core meas - ures aligned with international best practices. These measures include the following. • Access controls and identity management – ensur - ing system access only for authorised users. • Asset and configuration security – implementing secure configurations, maintaining current software versions, and applying network security controls, including continuous monitoring of network traffic and logs for anomalies. • Vulnerability management and code updates – establishing procedures for timely remediation of vulnerabilities and co-ordinated vulnerability disclo - sure. • Training and awareness – conducting regular secu - rity training and awareness activities. Incident Detection, Response and Recovery Organisations must maintain an incident response plan with procedures for incident classification, con - tainment, eradication, recovery and reporting – both internally and to the authorities. Periodic testing of these procedures is required. Business Continuity and Disaster Recovery (BCP/ DR) BCP/DR planning and testing must be carried out to ensure that key services can be maintained or quickly restored following a cyber disruption. Requirements include backup policies and regular recovery testing, particularly to protect against ransomware and data corruption.
Third‑Party Due Diligence and Management Organisations must ensure that third‑party con - tracts include appropriate cybersecurity controls and clauses, such as security obligations, audit rights or independent assessment reports, breach notifica - tion requirements, and data‑location provisions when applicable. There is also an obligation to oversee sub - contractors, maintain an exit strategy (including data portability, relocation support and transition periods), and manage concentration risks, supported by contin - gency plans for the failure of a critical supplier. The National Framework effectively transforms estab - lished best practices into mandatory requirements. Compliance is monitored through submissions and audits, and non‑compliance may result in enforce - ment actions, such as fines or corrective orders. 2.3 Incident Response and Notification Obligations The established incident response and reporting obli - gations aim to ensure the timely management of inci - dents and the proper notification of authorities. Under Law 5160/2024, an incident must be report - ed if it is classified as a “significant incident”. This includes any security incident that has, or could have, a substantial impact on the provision of an operator’s services or that affects other individuals or entities, causing significant material or non-material damage. In practice, the assessment considers factors such as the number of users affected, the duration of the disruption, the geographical spread, and the severity of the impact (including financial losses or risks to life or health). At EU level, quantitative thresholds have been set (for example, incidents affecting more than 100,000 users or lasting several hours may automati - cally qualify as significant), and Greece follows these criteria as established in the Commission’s imple - menting regulation on incident reporting. The incident reporting process takes place in stages. • Within 24 hours of becoming aware that a signifi - cant incident has occurred, the entity must submit an initial notification (“early warning”) to the author - ities. This notification must be provided even if full details are not yet known, as its purpose is to alert
169 CHAMBERS.COM
Powered by FlippingBook