Alessandro AleddaInsider Threat and Risk

ITER/GRGreece

What the record establishes for Greece: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.

Recipients
4 of 4
Reporting address
None recorded
NIS2
Date not read
Terms moved
No
Sources cited
5
Last read
3 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Hellenic Data Protection Authority reportededpb members
CSIRT or competent authorityNIS2, article 23The Εθνική Αρχή Κυβερνοασφάλειας, the National Cybersecurity Authority, to which paragraph 4 owes the submissions reported

Not set by the law, and there is no portal for it. The Authority publishes two forms, both dated 9 December 2025: a simple one for the twenty-four hour early warning, an analytical one for the seventy-two hour and the final report: and takes them by electronic mail at incident@cyber.gov.gr. Its page also links to the Hellenic CSIRT's own incident report page, which is a different team and is not recorded here as discharging this duty.

gr nomos 5160 2024 · cyber gov gr anafora
Financial supervisorDORA, article 19Bank of Greece reportedeba competent authorities
Market authorityMAR, article 17Επιτροπή Κεφαλαιαγοράς (HCMC) reportedesma mar nca

Transposition of NIS2 binding

ActΝόμος 5160/2024, ΦΕΚ Α΄ 195 of 27 November 2024
In forcenot established in the text read
RecipientThe Εθνική Αρχή Κυβερνοασφάλειας, the National Cybersecurity Authority, to which paragraph 4 owes the submissions
Moves a termNo. None. The cascade is the Directive's, and the numbers are spelled out: a warning «εντός είκοσι τεσσάρων (24) ωρών από τη στιγμή που αντιλήφθηκαν το σημαντικό περιστατικό», the incident notification «εντός εβδομήντα δύο (72) ωρών» on the same anchor, an interim report at the Authority's request, and «τελική έκθεση το αργότερο εντός ενός (1) μηνός μετά από την υποβολή της κοινοποίησης περιστατικού». Where the incident is still running at that point, a progress report then and a final report within one month of the entity's handling of it. Trust service providers have their own derogation.
StandingRead in the law as published in the Government Gazette. One thing is national rather than the Directive's default: the submissions are owed to the National Cybersecurity Authority itself, not to a CSIRT. This entry also settles something about the Cypriot one: the six hours in the Cypriot authority's guide are not a Greek-language convention. Greece, writing in the same language, says twenty-four.
Sourcegr nomos 5160 2024

An event in Greece

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.