Cybersecurity 2026

GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm

Third‑party risk management (TPRM) requirements include:

• Interim report – within 72 hours of the initial notifi - cation. • Final report – within one month of the interim report, providing full root-cause analysis and cor - rective measures. Additional updates are required when the situation materially changes or when requested by the author - ity. The reports must enable supervisors to understand what happened, the areas affected, and how the inci - dent is being managed. Initial notifications should pro - vide essential information, followed by more detailed impact assessments and status updates, and finally a comprehensive root‑cause analysis, damage assess - ment, remediation plan, and preventive actions. Third‑Party Providers and Cross‑Regime Considerations DORA brings third‑party ICT providers into the same operational framework. If an incident occurs at an ICT provider (eg, cloud or outsourcing provider), the finan - cial entity must report it as its own major incident and co-ordinate with the provider based on contractual obligations for co-operation and information sharing. Providers designated as CTPPs (Critical Third‑Party Providers) fall under a dedicated EU‑level oversight regime. This does not limit national obligations for Greek financial institutions regarding TPRM, testing, and full incident reporting. Financial entities may also report significant cyber threats, even before they develop into incidents, and may participate in threat‑information‑sharing arrange - ments consistent with the framework’s safeguards. For entities also subject to NIS2, DORA incident reporting to financial sector supervisors exists along - side NIS2 reporting obligations to the NCSA. 3.4 Operational Resilience Enforcement DORA establishes a new EU‑level oversight frame - work under which designated ICT providers (eg, cloud service providers, software vendors) are subject to direct supervisory monitoring by the European Super - visory Authorities (ESAs – EBA, ESMA and EIOPA). At

• a TPRM strategy; • risk assessments;

• a register of all third‑party arrangements; and • contractual clauses covering access, audit and information rights, sub‑outsourcing, exit, and data reversibility. Incident Management and Reporting Entities must maintain an end‑to‑end incident man - agement process covering detection, triage, contain - ment, eradication, recovery, and post‑incident review. Incidents must be classified using defined criteria such as service downtime, number and criticality of users affected, data loss, geographic spread, eco - nomic impact, and other material indicators. DORA delegates specific thresholds and evidence requirements to the Regulatory Technical Standards (RTS). Classification of an incident as “major” is based primarily on its scale and criticality – for example, disruption to critical services, high user impact, long duration, significant data loss, or systemic implica - tions. Materiality is assessed based on factors such as: • impact on critical functions; • number of affected customers or users and extent of disruption; • duration and severity of availability degradation; • geographical spread; • impact on the confidentiality, integrity, or availabil - ity of data; • operational or financial damage; and • potential systemic or chain‑reaction effects. Reporting Timelines Major ICT‑related incidents must be reported to the competent financial authority (Bank of Greece or HCMC). Reporting follows a staged model. • Initial notification – within 4 hours of classification as “major”, and no later than 24 hours after detec - tion.

174 CHAMBERS.COM

Powered by