Cybersecurity 2026

GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm

the NCSA (and potentially the EU CSIRT Network) promptly. • Within 72 hours, the entity must submit a more detailed incident report. This report should include an initial assessment of the nature of the incident, its severity and observable impact, and whether the incident appears to be under control or ongo - ing. The NCSA may also request interim updates or additional information as the situation develops, and Law 5160/2024 allows it to require progress reports while the incident is being resolved. • No later than one month after the initial notification, the entity must submit a final report to the NCSA. This report should include a comprehensive analy - sis of the incident, its root cause, the full extent of its impact, and the remedial measures taken. If the incident is still ongoing after one month, additional progress reports may be required beyond this deadline. Failure to comply with reporting deadlines may itself lead to penalties, as timely reporting is a legal obliga - tion. All notifications are submitted to the NCSA’s National CSIRT, but relevant sectoral authorities may also be involved. • Public administration and national security sec - tors: incidents require co-ordination with the government CSIRT. Law 5160/2024 requires public sector entities to notify the Cyber Security Incident Response Team of the National Intelligence Service (EYP), alongside simultaneous notification to the NCSA. • Telecommunications sector: significant incidents must be reported both to ADAE and the NCSA. ADAE then shares relevant information with the NCSA and EETT as needed. • Financial sector: under DORA, institutions report significant ICT incidents to their financial regulator (the Bank of Greece or the Hellenic Capital Mar - ket Commission). If the incident also falls under NIS2, these regulators are expected to co-ordinate with the NCSA. The Greek framework (via Law 5236/2025 and cross-sector Memoranda of Coop - eration) seeks to avoid duplicate reporting – for example, a bank may report to the Bank of Greece,

which then informs the NCSA, or vice versa – although this mechanism is still maturing. Certain incidents trigger multiple regulatory notifica - tions. For example, a personal data breach in a hos - pital qualifies both as a NIS2 incident and a GDPR breach. In such cases, the hospital must notify the NCSA (under NIS2) and the Greek Data Protection Authority within 72 hours (under the GDPR). As there is currently no one‑stop‑shop mechanism, organisa - tions must comply with each law’s separate proce - dure. The Greek authorities encourage reporting stream - lining to prevent multiple entities from reporting the same incident separately. For instance, if a telecom - munications provider submits a report to ADAE, ADAE forwards it to the NCSA so the provider does not need to report twice (supported by a Memorandum of Cooperation between ADAE and the NCSA). Simi - larly, at the European level, the NCSA – acting as the national single point of contact – shares information with the EU CSIRT Network and, for large‑scale inci - dents, with the European Cyber Crisis Liaison Organi - sation Network (EU‑CyCLONE). Entities do not need to report directly to EU bodies, although they may be asked for further details via the NCSA. Early warnings are used for immediate alerts and support and are treated as confidential. The NCSA must protect the security, commercial interests, and confidentiality of the information, though it may issue anonymised warnings to other entities. The final report and interim updates form part of the formal post‑inci - dent obligations, and the NCSA may request a correc - tive action plan, follow‑up meeting, or audit. Beyond regulatory notifications, entities may also be required to inform service recipients/users if service provision is affected, and the NCSA may issue public notices where necessary to mitigate risks or protect the public interest. 2.4 State Responsibilities and Obligations The state, through the NCSA, develops the National Cybersecurity Strategy, which outlines the protection of critical sectors, skills development, and investment in secure technologies. The strategy is reviewed every five years, while progress is assessed every two years,

170 CHAMBERS.COM

Powered by