Note. This guide is informational material based on current legislation, international standards and published scientific research. It does not constitute legal advice. For binding guidance, consult the competent authorities and legal counsel.

1. The role of the Security Officer

The appointment of an Information and Systems Security Officer (in Greece: «ΥΑΣΠΕ») is required by the national framework implementing the NIS2 Directive — Law 5160/2024 and the delegated acts of the National Cybersecurity Authority (for the health sector, see also Joint Ministerial Decision 1689/2025). The Security Officer coordinates the implementation of security measures, advises management, monitors incidents and communicates with the authorities. Two principles define the role:

  • Liability is not transferred to the Security Officer. Under Article 20 of NIS2, the measures are approved and overseen by the management body, which can be held liable for infringements. The Security Officer proposes and implements — they do not replace management.
  • Distinct from the DPO. The Security Officer (systems security, NIS2) and the Data Protection Officer (GDPR Article 37) are separate roles with different missions and, especially in healthcare, should not be conflated — nor held by the same person where avoidable.

2. The non-negotiable deadlines

In a significant incident, the law moves faster than the technical investigation. The clock starts the moment the organisation becomes aware of the incident:

≤ 24 hours
Early warning → National Cybersecurity Authority

First notification (NIS2 Article 23, Law 5160/2024). Report what you know — completeness comes later.

≤ 72 hours
Incident notification → NCA

Update with severity assessment, impact and indicators of compromise (IoCs).

≤ 1 month
Final report → NCA

Root cause, overall impact, measures taken and lessons learned.

In parallel, if the incident involves personal data (in healthcare, almost always), an independent obligation is triggered: notification of the Hellenic DPA within 72 hours (GDPR Article 33) and, where there is high risk to individuals, communication to the patients themselves (Article 34). One report does not cover the other — these are two different authorities with two different forms.

In practice. Reports to the National Cybersecurity Authority are submitted via incident@cyber.gov.gr and to the Hellenic DPA via eservices.dpa.gr. Prepare pre-filled templates in advance — the Tools on this site generate both drafts automatically, with deadline calculation.

3. The 10 measures of Article 21 — what they mean in practice

Article 21(2) of NIS2 sets the minimum risk-management measures. The table translates them into practical actions and maps them to implementation standards:

Measure (Art. 21(2))What it means for a hospitalReference standard
(a) Risk analysis and security policiesApproved security policy, methodology and a risk register that is kept up to dateISO/IEC 27001:2022, ISO/IEC 27005:2022
(b) Incident handlingIncident response plan (IRP), designated team, event detection and loggingISO/IEC 27035, NIST CSF 2.0 (Respond)
(c) Business continuityBCP with impact analysis, 3-2-1 backups with test restores, manual downtime proceduresISO 22301:2019, ISO/IEC 27031
(d) Supply chain securityRegister of critical suppliers, contractual security clauses, risk assessment of medical devices (IoMT)ISO/IEC 27036, MDR 2017/745
(e) Secure acquisition and vulnerability handlingPatch management, secure configuration, retirement of legacy systemsISO/IEC 27002:2022
(f) Effectiveness assessmentKPIs, internal audits, penetration testing, continuous improvementISO 27001 §9, NIST CSF 2.0 (Identify)
(g) Cyber hygiene and trainingAwareness programme for all staff with role-targeted frequency (see §6)ENISA Cyber Hygiene (2025)
(h) CryptographyEncryption at rest and in transit, key managementISO/IEC 27002 §8.24
(i) Personnel security and access controlRole-based access, least privilege, asset inventoryISO/IEC 27002 §5–§8
(j) MFA and secure communicationsMulti-factor authentication on critical systems, secure emergency communication channelsISO/IEC 27002 §5.17

4. Management liability — why it concerns you directly

The Security Officer's strongest argument to management is not technical but legal:

  • Approval and oversight by management (NIS2 Article 20(1)). The management body approves the measures, oversees their implementation and "can be held liable" for infringements.
  • Mandatory management training (Article 20(2)). Members of the management body are required to follow cybersecurity training.
  • Sanctions. For essential entities, administrative fines of up to EUR 10 million or 2% of worldwide turnover (for important entities, up to EUR 7 million or 1.4%). In addition, for essential entities the authorities may request a temporary prohibition on exercising managerial functions for natural persons at CEO or legal-representative level (Article 32(5)).

5. What the case law teaches

Court and supervisory-authority decisions show precisely where a healthcare organisation's liability is decided in practice:

The burden of proof is yours — CJEU C‑340/21

Court of Justice of the EU, judgment of 14.12.2023 (VB v Natsionalna agentsia za prihodite)

Following a hacking attack, the Court held that (a) a successful third-party attack does not by itself prove that the security measures were inappropriate, but (b) the controller bears the burden of proving that the measures under Article 32 GDPR were appropriate, and the courts review them on the merits. Moreover, even the fear of possible future misuse of the data can constitute compensable non-material damage.

What it means for you: without documentation (policies, risk register, test records, logs), the organisation cannot discharge the burden of proof — even if the measures existed. What is not written down, legally never happened.

Compensation with no "seriousness threshold" — CJEU C‑300/21 and C‑687/21

Court of Justice of the EU, 4.5.2023 (Österreichische Post) and 25.1.2024 (MediaMarktSaturn)

A GDPR infringement does not automatically create a right to compensation — actual damage and a causal link are required. However, no minimum "threshold of seriousness" applies to non-material damage, while a purely hypothetical risk of misuse does not suffice.

What it means for you: in a breach of the health data of thousands of patients, every affected person with documented harm (including psychological) may claim compensation — the cumulative civil exposure often exceeds the administrative fine.

Fines on the legal person, with fault — CJEU C‑807/21 and C‑683/21

Court of Justice of the EU, 5.12.2023 (Deutsche Wohnen and Nacionalinis visuomenės sveikatos centras)

A GDPR fine can be imposed directly on a legal person, without attributing the infringement to a specific natural person — but fault (intent or negligence) is required, taking into account what the organisation ought to have known.

What it means for you: "we didn't know" is no defence. A documented security programme that identifies and prioritises risks is the primary means of excluding negligence.

Access control over patient records — Haga Hospital (Netherlands) and Barreiro‑Montijo (Portugal)

Dutch Data Protection Authority 2019 (fine of EUR 460,000) and Portuguese CNPD 2018 (fine of EUR 400,000)

At Haga, dozens of employees had opened a celebrity patient's record without reason — the authority found access control and logging insufficient and required strong authentication. At Barreiro‑Montijo, the hospital maintained hundreds of active "doctor" accounts — several times the number of doctors actually employed — with full access to clinical data.

What it means for you: the two most common hospital findings — "everyone can see everything" and "dormant accounts that never get closed" — have already been priced by the authorities. Role-based access, periodic account reviews and logging are not luxuries.

Personal criminal liability — the Vastaamo case (Finland)

Helsinki District Court 2023 (conviction of the former CEO) and 2024 (conviction of the attacker, imprisonment of over 6 years)

After the breach of the Vastaamo psychotherapy centre and the extortion of thousands of patients with their psychiatric records, the former CEO was criminally convicted, among other things because the breach was concealed instead of being notified. The company collapsed and went bankrupt.

What it means for you: concealing an incident is the only scenario worse than the incident itself. The deadlines in §2 are not bureaucracy — they are the line separating a manageable event from personal liability.

6. What the data says — arguments for management

Documented evidence supporting the Security Officer's budget and priorities:

  • Healthcare is the most expensive sector. The average cost of a breach in healthcare is USD 7.42 million — consistently the top sector worldwide for more than a decade (IBM, Cost of a Data Breach Report 2025).
  • Ransomware dominates. In European healthcare, ransomware accounts for the largest share of incidents, with hospitals the sector's most frequent target (ENISA Threat Landscape: Health Sector, 2023).
  • Attacks cost lives, not just money. A hospital ransomware attack was associated with increased cardiac-arrest incidence and worse outcomes even at neighbouring, untargeted hospitals absorbing the diverted load (Pham et al., 2024, Critical Care Explorations).
  • Recovery is measured in months. In the attack on the Irish health service (HSE, 2021) about 80% of the IT environment was encrypted and full recovery took months. WannaCry (2017) cost the NHS roughly 19,000 cancelled appointments and an estimated GBP 92 million.
  • Annual "tick-box" training is not enough. A large randomised field study found no protective effect of annual training against phishing (Ho et al., 2025), while knowledge decays noticeably after four months and returns to baseline at around six (Reinheimer et al., 2020; Chou et al., 2026). Practical consequence: short, role-targeted refreshers every three to six months — not one "mass" session a year.

7. Immediate action list for the Security Officer

#ActionWhy (reference)
1Confirm the entity's registration with the National Cybersecurity Authority and the appointment of a Security Officer and deputyLaw 5160/2024
2Set up the 24/72-hour reporting process with ready templates and a communication treeNIS2 Art. 23, GDPR Art. 33
3Map the 10 measures of Article 21 to a "have / missing / in progress" statusNIS2 Art. 21(2)
4Document everything — policies, decisions, tests, trainingCJEU C‑340/21 (burden of proof)
5Review access rights and dormant accounts on clinical systemsHaga 2019, Barreiro 2018
6Test backup restoration and departmental downtime proceduresISO 22301, HSE 2021 experience
7Schedule role-based training with refreshers every 3–6 months and tabletop exercisesNIS2 Art. 20(2) and 21(2)(g), Reinheimer 2020
8Inform management in writing of its liability and obtain approval of the measuresNIS2 Art. 20, Art. 32(5)
Tools. On the Tools page you will find the NIS2 implementation checklist with progress tracking, the role-based advisor, the emergency response console (works offline) and staff training with pseudonymisation and adaptive scheduling. (Tools interface currently in Greek.) Download the phishing card (PDF).

Sources and references

  • Directive (EU) 2022/2555 (NIS2), in particular Articles 20, 21, 23, 32. Official Journal of the EU.
  • Greek Law 5160/2024 — transposition of NIS2. National Cybersecurity Authority (delegated acts; JMD 1689/2025 for the health sector).
  • Regulation (EU) 2016/679 (GDPR), in particular Articles 9, 32, 33, 34. Greek Law 4624/2019.
  • CJEU, C‑300/21, Österreichische Post, 4.5.2023. CJEU, C‑340/21, VB v Natsionalna agentsia za prihodite, 14.12.2023. CJEU, C‑683/21 and C‑807/21 (Deutsche Wohnen), 5.12.2023. CJEU, C‑687/21, 25.1.2024 (curia.europa.eu).
  • Autoriteit Persoonsgegevens (Netherlands), Haga Hospital decision, 2019. CNPD (Portugal), Centro Hospitalar Barreiro‑Montijo decision, 2018.
  • IBM Security. (2025). Cost of a Data Breach Report 2025.
  • ENISA. (2023). Threat Landscape: Health Sector. ENISA. (2025). Cyber Hygiene in the Health Sector.
  • Pham, T. T., et al. (2024). Ransomware cyberattack associated with cardiac arrest incidence and outcomes at untargeted, adjacent hospitals. Critical Care Explorations, 6(4), e1079.
  • Ho, G., et al. (2025). Understanding the efficacy of phishing training in practice (large randomised field study).
  • Reinheimer, B., et al. (2020). An investigation of phishing awareness and education over time. USENIX SOUPS 2020. Chou, T.-L., et al. (2026), on the six-month decay of preparedness in a hospital environment.
  • ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27005:2022, ISO 27799:2016, ISO 22301:2019, NIST Cybersecurity Framework 2.0 (2024).