Cybersecurity 2026

GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm

with ENISA support available when required. In par - allel, the state establishes the regulatory framework and, through the NCSA, issues binding technical and organisational requirements as well as guidelines. The NCSA also serves as the National Cybersecurity Certification Authority under the EU Cybersecurity Act, overseeing the implementation of certification schemes for ICT services. The state is responsible for maintaining national pre - vention, detection, and response capabilities. The NCSA hosts the national CSIRT, and in cases of large- scale incidents, national cyber crisis management procedures and European co-ordination mechanisms (eg, EU-CyCLONE) are activated. In the area of Cyber Threat Intelligence (CTI), the framework encourages and protects the voluntary exchange of information – such as indicators of compromise, vulnerabilities, and incidents – and supports the establishment of Infor - mation Sharing and Analysis Center (ISAC) structures. The NCSA facilitates information exchange, issues anonymous warnings to the market when necessary, and participates in EU-level networks (such as the EU CSIRT Network) and international collaborations. The strategy adopts a public–private partnership model. The state seeks co-operation with the private sector by forming sectoral working groups or ISACs in areas including finance, energy, and telecommunica - tions. It regularly convenes critical infrastructure oper - ators in dedicated forums to discuss emerging threats and jointly develop mitigation measures. Furthermore, the state invests in capacity building and operates a National Coordination Centre within the EU cyberse - curity capabilities network (Regulation (EU) 2021/887). Financial incentives for cybersecurity investments and certifications are also under consideration. In serious cases, the state may mobilise additional resources, including technical assistance from NCSA experts, and involve law enforcement authorities to provide investigative support. Similarly, the develop - ment of sectoral ISACs highlights the state’s role as convenor and the industry’s role as the primary chan - nel for day-to-day information exchange. In summary, the Greek state plays the roles of organ - iser, regulator, information provider, and supporter in

the field of cybersecurity. It sets strategic direction and regulatory requirements (so private entities under - stand their obligations), ensures national response capabilities (so the state can intervene during major threats), actively shares threat information (so no organisation confronts risks alone), and builds strong connections with the private sector and international partners (because cybersecurity resilience is a col - lective effort). 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation DORA applies directly in Greece without requiring national transposition and serves as the primary operational resilience framework for financial entities and critical ICT third‑party providers. The following organisations fall within the scope of DORA. A broad range of financial sector entities, including: • credit institutions, payment institutions and e‑mon - ey institutions; • investment firms, insurers and reinsurers; • central securities depositories (CSDs), CCPs and trading venues; • crypto‑asset service providers (CASPs); and • pension funds, credit rating agencies and trade repositories. Critical Third‑Party ICT Providers, meaning ICT ser - vice providers that deliver critical or important ser - vices to financial institutions, such as: • cloud computing service providers; • data analytics or software providers; and • other ICT outsourcing firms. DORA is structured around five core operational pil - lars: 1. ICT Risk Management Requirements

171 CHAMBERS.COM

Powered by