News

News and insights

What we are seeing in the field, and what it means for organisations in Greece and Southeast Europe.

NIS2 enforcement is arriving: what to do in the next ninety days

Supervisory activity is moving from guidance to inspection. A short, practical plan for companies that have not started.

Many organisations in scope of NIS2 have completed a gap analysis and stopped there. Supervisors are now asking for evidence: risk assessments with dates, incident procedures that name people, training records and supplier clauses. The good news is that the first ninety days are mostly organisational rather than technical. Confirm your scope in writing, appoint an accountable manager, document your risk assessment, and rehearse one incident scenario end to end. Technical hardening follows, and it is easier to fund once management has seen the gaps.

Why the 3-2-1 backup rule is no longer enough

Modern attackers target backup infrastructure first. Immutability and verified restores are now the parts that matter.

In most ransomware cases we are called into, the backups technically existed. What failed was that the backup server shared credentials with the domain, or the only off-site copy was a synchronised folder that faithfully replicated the encryption. Three copies on two media with one off-site is still a sound foundation, but it needs two additions: one copy that cannot be modified or deleted for a fixed retention period, and a verification report that a human reads. Test a restore before you need one.

Phishing in the age of generative AI

The spelling mistakes are gone, and so is the advice built around spotting them. What to teach staff instead.

For years, awareness training taught people to look for bad grammar and odd phrasing. Generative tools have removed those signals, including in Greek and other languages that once slowed attackers down. The reliable indicators are now contextual rather than linguistic: an unexpected request, urgency around payment or credentials, a change of bank details, or a channel that bypasses normal process. Teach verification through a second, known channel, and make it socially acceptable to check, even when the request appears to come from a director.

Resilience is a decision. Make it before you need it.

Get a free assessment of your current backup, recovery and security posture.

Request a free assessment

Free 30-minute resilience review

Book yours