GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm
Threat Intelligence (TI) Requirements • TI must reflect real threat actors targeting an entity’s critical or important functions (CIFs). • Under TIBER‑EU, tests must simulate the tactics, techniques, and procedures (TTPs) of advanced real‑world attackers. Scenario Selection • Scenarios must be based on bespoke, entity‑spe - cific TI. • They must focus on CIFs and vulnerabilities across systems, processes, and people. • The DORA TLPT RTS aligns closely with TIBER‑EU scenario design requirements. Mandatory Documentation Timeline Following notification by supervisory authorities: Within 3 months: Submit initiation documents (project plan, control team lead details, communication plan). Within 6 months: Submit the detailed Scope Specification Document (CIFs, systems, test flags). Red Team Testers (RTTs) Requirements RTTs must: • be independent from the entity’s operations; • meet strengthened competence and ethical requirements introduced under TIBER‑EU (2025 update); and • demonstrate experience in advanced threat‑simu - lation techniques. Threat Intelligence Providers (TIPs) Requirements TIPs must: • produce high‑quality bespoke TI reports; • meet strict selection criteria aligned with the updated TIBER‑EU rules; and • be subject to supervisory restrictions if they lack sufficient qualifications.
stored, as well as the conditions under which these locations may change. This transparency enables both the financial entity and competent authorities to assess the risks associated with different jurisdictions. In parallel, supervisory expectations for outsourcing require that both the financial entity and the com - petent authorities retain full access, inspection, and audit rights. They also require that risks arising from third‑country involvement be specifically assessed. The EBA Guidelines on Outsourcing address these requirements explicitly, covering both access/con - trol obligations and risk management considerations related to third‑country arrangements. From a data protection perspective, Greece operates fully within the EU’s GDPR framework. When personal data is transferred outside the EEA, the transfer must rely on an appropriate GDPR mechanism. Following Schrems II, organisations must evaluate whether the chosen transfer tool functions effectively in practice and, where necessary, adopt additional technical and organisational measures in line with the EDPB’s guid - ance on “supplementary measures”. In practice, the combined effect of DORA, GDPR, and supervisory obligations often leads organisations to adopt operational strategies that resemble a form of soft data localisation. This typically results in a pref - erence for EU/EEA data regions, the use of technical measures that ensure encryption keys remain within the EU, and contingency planning that allows critical functions to continue or be recovered without reliance on a third country that poses regulatory or operational difficulties. 3.6 Threat-Led Penetration Testing Greece does not maintain its own national threat‑led penetration testing (TLPT) framework. Instead, TLPT obligations for Greek entities stem directly from DORA and the TIBER‑EU Framework, which functions as the official methodology for conducting TLPT under DORA. DORA TLPT adopts the TIBER‑EU intelligence‑led methodology.
176 CHAMBERS.COM
Powered by FlippingBook