Cybersecurity 2026

GREECE Trends and Developments Contributed by: Alexandros Choimes and Evangelos Katsaras, ALG Manousakis Law Firm

officials (such as police officers, prosecutors and judges) and updating policies and action plans for dealing with ransomware and deepfake-driven attacks. • Enhancing European and international co-oper - ation by establishing a Strategy for International Cooperation on Cybersecurity Issues, promoting the NCSA’s public and international presence and strengthening the co-operation in the context of shaping a European Cybersecurity Policy. • Establishing reliable mechanisms for exchange of information through the creation of a threat intel - ligence sharing platform. • Establishing procedures for mutual assistance through the enhancement of cyber resilience among Greek local authorities. Goal #3: Systemising cybersecurity governance This goal promotes the following. • The development of cybersecurity management frameworks by strengthening business continu - ity and disaster recovery mechanisms as well as developing a crisis management national plan. • Secure digital identities and trust in public digital services by upgrading the protection of govern - ment websites. • The establishment of a national cybersecurity risk assessment framework by preparing threat landscape reports, developing and maintaining a register to include hardware, software, and intan - gible information assets in critical sectors (public sector and critical infrastructure) and conducting a national cybersecurity risk assessment. • The improvement of national cybersecurity govern - ance by establishing a Cybersecurity Coordination Committee for Public Administration, developing and implementing a unified co-ordination frame - work for information security officers in Public Administration, formulating an operational frame - work for Organic Cybersecurity Units of Central Administration Bodies, adopting and implement - ing secondary legislation under Law 5160/2024, developing and publishing sectoral cybersecurity policies and standards, developing audit mecha - nisms on the implementation of cybersecurity requirements, building a cybersecurity governance manual for public bodies, creating of a training and

certification framework for cybersecurity inspectors as well as cyber insurance providers, and develop - ing a policy framework related to the security of submarine communications cables. • The implementation of cybersecurity risk manage - ment measures by implementing a comprehensive cybersecurity framework for 5G networks as well as a framework of measures and actions for AI, Cybersecurity and the Internet of Things (IoT), establishing secure design principles for new ICT systems in the public sector, developing a national framework for the secure transition of services to cloud computing, and conducting NCSA audits (eg, on essential and important entities under the NIS2 Directive). • The enhancement of cybersecurity incident report - ing mechanisms through the creation of a central mechanism for co-ordinated reporting of cyberse - curity incidents as well as a cyber hotline. Goal #4: Bolstering regulatory compliance / updating cybersecurity policies and procedures The last goal aims to achieve the following. • Balancing cybersecurity and the protection of privacy by developing a national framework on privacy and security by design, as well as a plan on cybersecurity and privacy compliance with both Data Protection Officers (DPOs) and Chief Informa - tion Security Officers (CISOs) as target audiences. • Bolstering cybersecurity in the supply chain by establishing a framework for secure ICT procure - ment as well as supply chain security. • Protecting and strengthening cyber resilience among critical sectors by creating and updating a dedicated list relating to critical infrastructure, developing specific system guidelines and security standards for particular categories such as ICS, SCADA and ΙIoT, adopting a sectoral strategy and action plan for cyber resilience in the field of civil aviation and strengthening the cyber resilience of the “.gr” and “.ελ” domain name registries. • Establishing a national policy to co-ordinate disclo - sure of vulnerabilities (CVD Policy) by developing a dedicated national mechanism as well as a national incentive framework for responsible vulnerability disclosure (Bug Bounty GR).

187 CHAMBERS.COM

Powered by