Cybersecurity 2026

GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm

• Asset identification, protection and detection measures, as well as incident response, recovery and backup policies. 2. ICT Incident Reporting Rules • Classification of ICT incidents and mandatory reporting of major incidents. 3. Digital Operational Resilience Testing • Regular scenario‑based testing and Threat‑Led Penetration Testing (TLPT). 4. ICT Third‑Party Risk Management • Contractual obligations, oversight requirements, concentration‑risk assessment and exit strategies. 5. Oversight of Critical Third‑Party ICT Providers • ESA‑level monitoring and supervisory powers over designated critical ICT providers. DORA also has significant extraterritorial reach, cover - ing the following. • Financial entities operating in Greece but head - quartered elsewhere – if an institution provides regulated services in any EU Member State, includ - ing Greece, DORA applies regardless of where its headquarters are located. • Non‑EU ICT third‑party providers serving Greek financial institutions – at the national level, Greece has complemented DORA with Law 5193/2025, which assigns supervisory and enforcement pow - ers. The Bank of Greece supervises banks, insur - ance companies and payment providers, while the Hellenic Capital Market Commission oversees investment firms, fund managers and related enti - ties. These authorities have the power to impose administrative fines of up to 10% of turnover, in accordance with national law. 3.2 ICT Service Provider Contractual Requirements DORA defines ICT services as encompassing “a broad range of offerings, extending beyond traditional out -

sourced IT services”. This includes third‑party service providers, cloud and software vendors, and fintech providers. Under DORA, entities qualify as ICT service providers when they supply any of the following to financial institutions: • digital or data services; • data processing; • software; • data centre services; • cloud computing services; or • any outsourced ICT‑related function. ICT service providers may be designated as critical based on several criteria: • the provider’s systemic importance; • the scale and complexity of services offered to the financial sector; • the potential impact on the stability, continuity, and quality of financial services in the event of disrup - tion; and • the degree of concentration within the provider’s market segment. This designation is carried out by the European Super - visory Authorities (ESAs), not by national authorities. Financial institutions must embed binding contractual and supervisory requirements into their agreements with all ICT service providers. In particular, contracts must address the following areas. Full description of services: A clear and comprehensive description of all services and the provider’s obligations. Subcontracting: Explicit provisions governing subcontracting, includ - ing notification and approval requirements, as well as the obligation to ensure that subcontractors receive equivalent security, control, and co-operation commit - ments (“chain outsourcing”).

172 CHAMBERS.COM

Powered by