Cybersecurity 2026

GREECE Trends and Developments Contributed by: Alexandros Choimes and Evangelos Katsaras, ALG Manousakis Law Firm

almost all connected hardware and software, from IoT devices and embedded systems to firmware, oper - ating systems, standalone applications and cloud- supported digital components. Although, the CRA became legally binding on 10 December 2024, its obli - gations are intentionally phased in. Starting from Sep - tember 2026, manufacturers selling PDEs into Greece must begin reporting actively exploited vulnerabilities and severe incidents to national CSIRTs/ENISA. The digital landscape In relation to the emergence of these technologies, the digital environment of Greece has been marked by the following trends and observations. Rapid development of technologies using AI The relationship between AI and cybersecurity is quite tight considering that the rise in cyber threats is becoming increasingly associated with the capabili - ties of AI systems such as Large Language Models (LLMs), which, while becoming popular for day-to-day as well as commercial uses, may also serve the pur - poses of cybercrime groups (eg, for cyber-espionage or for financial gains). AI-enhanced malicious activi - ties are also significant for malware attacks, which are quite common in Greece compared to other EU member states, particularly due to the country’s geo - graphical location. Rise of cyber threats In 2025, the most significant types of cyber-attacks related to cybercrime activities such as DDoS (distrib - uted denial of service attack) and ransomware, espe - cially impacting public administration bodies, digital providers as well as entities operating in the health sector. Research suggests that the evolution of cyber - crime in Greece shows distinctive national character - istics, primarily in cases of fraud (predominantly in the form of ransomware and business email compromise) as well as AI-enhanced attacks, although systematic annual monitoring and available datasets for cyber - crime activities (as compiled by the Cyber Crime Divi - sion of the Hellenic Police) remain fragmented. Nev - ertheless, the nature of these threats considering the divergence in national statistics compared to global trends showcase the vulnerability of Greece’s SME- heavy economy and the lower digital maturity among local businesses. Based on recent data, Greece ranks

6th worldwide for malware detected in incoming email and 1st in Southern Europe for attacks on industrial systems of high criticality. Lack of preparedness and online safety Greek small and medium-sized enterprises (SMEs) remain underprepared for cyber threats, given their limited access to security expertise or infrastructure. Specifically, although Greek SMEs make up 99.9% of all businesses, they have emerged as the weakest link in the European Union with regards to cybersecurity, ranking last in terms of protective measures and com - prehensive policies against cyber-attacks. In addition, Greece is among the most dangerous online environ - ments, with ransomware and malware attacks surging more than tenfold in 2024 alone, targeting more than The cybersecurity market in Greece is expected to gain more than 50% and to exceed USD270 mil - lion in total value by 2031. Such gains are foreseen due to a number of factors, primarily regarding the increased interest of the Greek private sector in the protection of their digital infrastructure (considering their vulnerability against cyber threats, as described above), rising investments from the EU Recovery and Resilience Facility, as well as foreign investments, such as the USD1 billion investment from Microsoft for the creation and activation of three data centres on Greek territory by 2028. Such continuing digitali - sation, which will affect both the private and public sectors, is expected to have a significant impact on the implementation of the NCSA’s action plan and to place cybersecurity among Greece’s top national pri - one in five Greeks at least once (22%). Increase in cybersecurity investments In parallel to the enactment of the laws mentioned in “The regulatory landscape” above, the NCSA recently published its updated National Strategy on Cyberse - curity (2026–2030) in December 2025 by virtue of the Ministerial Decision No 2563/16-12-2025 (the “Strat - egy”). The updated Strategy came to replace the pre - viously adopted National Strategy (2020–2025) which had been established in light of the older NIS Direc - tive and its transposing Law 4577/2018, stressing the need for institutional changes in response to the orities moving forward. The strategic landscape

185 CHAMBERS.COM

Powered by