By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
HellenicHellenic
  • Media
  • Travel
  • Property
  • Business
  • History
  • News
  • Food
  • Technology
Search
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Reading: What the new cyber security regulation provides – Which agencies and businesses will have to comply
Share
Sign In
Notification Show More
Aa
HellenicHellenic
Aa
  • Media
  • Travel
  • Property
  • Business
  • History
  • News
  • Food
  • Technology
Search
  • Media
  • Travel
  • Property
  • Business
  • History
  • News
  • Food
  • Technology
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Hellenic > Blog > Technology > What the new cyber security regulation provides – Which agencies and businesses will have to comply
Technology

What the new cyber security regulation provides – Which agencies and businesses will have to comply

Hellenic
Last updated: 2024/11/02 at 11:11 AM
Hellenic
Share
8 Min Read
Greece has the lowest percentage of businesses with maximum internet speed in the EU
SHARE

The new European Union Directive should be implemented within 2025

More than 2,000 public and private sector entities will be required by 2025 to comply with the regulations brought by the implementation of NIS 2, the European Union’s latest cybersecurity directive.

Contents
The new European Union Directive should be implemented within 2025Related Tags

Otherwise, as the commander of the National Cybersecurity Authority (NCA), Michalis Bletsas, pointed out in an informal briefing yesterday, sanctions can be imposed, such as administrative fines to private sector entities, administrative fines to public administration bodies, temporary suspension of certification that concerns part or all of the relevant services, a temporary ban on any natural person responsible for the exercise of managerial duties.

As he explained, the new directive that Greece incorporates into its national law, adopts the obligation to report cyber security incidents. The obligation of the first report must be made by businesses and agencies within 24 hours of detecting the case, but now the responsibility for digital security is transferred to the highest levels. “Until now, the responsibility rested with the security managers of the information systems. Now, this responsibility is transferred to the management of a company”, explained officials of the National Cybersecurity Authority in an informal information meeting. “Cybersecurity is a team sport and requires the cooperation of all stakeholders. The planning includes the cooperation with the GRETHA and the EYP for the creation of a national incident response team, which is expected to be ready in 2025″, stressed Bletsas.

It should be mentioned that the relevant bill is in the phase of public consultation and is expected to be passed by the end of the year, although it will take some time until the decisions regarding the specifications for the cyber security systems of companies are formed, which will be determined according to the particularities of the branches concerned by the specific directive.

The new directive

Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022, known as the NIS 2 Directive (Network and Information Security Directive) is the revised version of the original NIS Directive, which was enacted in 2016 with the aim of strengthening of cybersecurity in the European Union. NIS 2, adopted in 2022, is about protecting critical networks and IT systems against cyber threats and ensures a coherent approach to cybersecurity across the EU.

Which organizations does it concern?

The list of organizations, agencies and businesses that are required to comply is quite long as, as it was pointed out, it includes all those whose shutdown would create a problem in society.

In particular, the list includes all companies, which employ between 50 and 250 employees and have a turnover of between 10 and 250 million euros, or even large companies active in sectors such as:

• Public Administration

• ICT Service Management (Information and Communication Technologies)

• Space

• Sewage

• Postal services

• Waste management

• Food

• Chemical products (preparation, production, distribution)

• Construction sector

Basic obligations

Regarding obligations, public sector organizations and private sector companies will have:

1. Obligations to take cyber security measures

Public sector organizations and private sector enterprises take detailed risk management measures based on a holistic approach to risk and aim to protect network and information systems and the physical environment of these systems from incidents.

2. Obligations to report cyber security incidents to EAK

Agencies must report cyber security incidents to EAK ensuring timely communication and response to threats

We should mention that these incidents will be made public

What are the penalties for non-compliance?

An effective and dissuasive sanctioning mechanism is established, which ensures the implementation of the relevant regulations. The sanctions are effective and fully respect the principle of proportionality. Mr. Bletsas said that the point that the EAK will focus on will be the reporting of cyber security incidents, as only in this way will there be a complete picture of the cyber attacks that occur in Greece and it will be possible to take measures to deal with them. Failure to report may result in penalties in the form of fines provided for in the bill, which can reach €10 million or 2% of a company’s global turnover.

As highlighted, the legislation will strengthen control mechanisms and ensure that organizations comply with security standards, reducing the risk of cyber-attacks and safeguarding the rights of citizens and the security of businesses.

The measures to be taken by agencies and businesses

Indicative:

a. Policies and procedures for risk analysis and information systems security

b. Incident management

c. Business continuity, such as backup and disaster recovery management, as well as cyber incident management

d. Supply chain security to adequately manage the risks arising from the relationships between each entity and its direct suppliers or service providers

e. Security in the acquisition, development and maintenance of network and information systems, including the handling and disclosure of vulnerabilities

f. Policies and procedures for evaluating the effectiveness of cybersecurity risk management measures.

Related Tags

cyber security

You Might Also Like

Apple plans to “open” its AI models to third parties for software development

New Building Regulation: In Parliament the amendment of RIS – what is foreseen, the environmental balance and who will pay for it

Two new services have been announced by Rakuten Viber in Greece

Tiktok’s reaction to Commission’s research on ads on the platform

Karagounis: Recruitment through mobile application – what is changing for businesses and employees with ERGANI II

TAGGED: agencies, BUSINESSES, comply, Cyber, cyber security, regulation, security

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Hellenic November 2, 2024 November 2, 2024
Share This Article
Facebook Twitter Copy Link Print
Share
Previous Article Markoulakis: "He fainted in front of me and I told them I'm the doctor, I'm not" Markoulakis: “He fainted in front of me and I told them I’m the doctor, I’m not”
Next Article Clear with a slight drop in temperature today Thursday – Where will it rain Clear with a slight drop in temperature today Thursday – Where will it rain
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

235.3k Followers Like
69.1k Followers Follow
11.6k Followers Pin
56.4k Followers Follow
136k Subscribers Subscribe
4.4k Followers Follow
- Advertisement -
Ad imageAd image

Latest News

Another impressive trailer for the movie "F1" with Brad Pitt
Another impressive trailer for the movie “F1” with Brad Pitt
Media May 28, 2025
Major Fire Fire: On June 3 the decision of the Court of Appeal
Major Fire Fire: On June 3 the decision of the Court of Appeal
News May 28, 2025
Eurovision 2025: Tonight the first semifinal with the participation of Cyprus
Eurovision 2025: Tonight the first semifinal with the participation of Cyprus
Media May 28, 2025
Youth Pass: Over 147,000 applications for new beneficiaries aged 18-19
Youth Pass: Over 147,000 applications for new beneficiaries aged 18-19
Business May 27, 2025
//

Welcome to Hellenic, your premier source for the latest Greek news and information, all delivered in English.

Quick Link

  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Company

  • About Us
  • Contact Us
  • Advertise with Us

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

HellenicHellenic
Follow US
Copyright ©️ 2023 Hellenic | All rights reserved.
Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.
Welcome Back!

Sign in to your account

Lost your password?