GREECE Trends and Developments Contributed by: Alexandros Choimes and Evangelos Katsaras, ALG Manousakis Law Firm
• Promoting active protection in cyberspace by cre - ating a framework of requirements for the develop - ment of a register of recommended cybersecurity service providers, upgrading and operationalising the National Cybersecurity Certification Authority, establishing an institutional certification framework in line with Regulation (EU) 2019/881 (“EU Cyber - security Act”) and strengthening of cyber preven - tion capabilities in the national defence sector. Practical considerations Drawing together the regulatory, digital and strategic landscapes above, the following focus areas can help organisations operating in Greece calibrate their 2026 plans. A. Prepare for deep NIS2 supervision • Treat NIS2 registration as the start of ongoing regu - latory engagement rather than a formal require - ment. • Conduct internal or third-party audits to verify readiness. • Maintain up-to-date documentation and records to support potential desk-based audits or on-site inspections. • Implement mandatory secondary measures, includ - ing comprehensive policies, asset inventories, sup - plier oversight programmes, and staff training. B. Monitor CER designation of critical entities • Identify whether or not the organisation falls within CER’s scope and track the official designation process. • Re-assess NIS2 applicability immediately after CER designation to ensure full regulatory compli - ance. • Integrate CER and NIS2 requirements into internal compliance monitoring frameworks. C. Accelerate CRA readiness • Establish CRA compliance workstreams ahead of 2026 obligations. • Prepare to provide CRA-aligned product security evidence for procurement processes. • Ensure market access readiness by implementing CRA-aligned practices before 2027 deadlines.
D. Strengthen defences against AI-enabled and hybrid cyber threats • Deploy detection capabilities to identify AI-generat - ed threats and abnormal behavioural patterns. • Upgrade endpoint, identity, and email security con - trols to mitigate advanced attacks. • Implement technical and procedural measures to prevent deepfake-driven fraud and hybrid cyber incidents. E. Address SME weakness in the supply chain • Conduct comprehensive vendor risk assessments and define minimum-security baselines for suppli - ers. • Perform periodic verification of supplier compli - ance with cybersecurity standards. • Provide SMEs with practical support, including templates, awareness training, and secure configu - ration guidance. • Request all critical suppliers to comply with NIS2- aligned security provisions. F. Invest in cyber skills, training, and governance • Recruit cybersecurity professionals proactively to address talent shortages. • Develop and upskill existing employees through targeted training programmes. • Strengthen internal governance by clearly defining cybersecurity roles, responsibilities, and escalation procedures. G. Enhance incident response capabilities across multiple regulatory regimes • Map all relevant reporting channels and timelines across NIS2, GDPR, CRA, CER, and sector-specif - ic frameworks. • Develop unified incident response playbooks to ensure consistent handling of multi-regime obliga - tions. • Establish a central incident response function to triage, manage, and report incidents efficiently across all applicable regulations.
188 CHAMBERS.COM
Powered by FlippingBook