For years, cybersecurity sat firmly in the IT department. Leadership set the budget, the tech team handled the details, and the rest of the business got on with things. The assumption was that as long as the systems were running and the passwords were strong, the risk was managed.
That model doesn’t hold up any more — and European regulation has caught up with that reality.
The NIS2 directive, implemented in Greece as Law 5160/2024, creates binding cybersecurity obligations for thousands of businesses across critical sectors. But there’s a point of confusion that’s worth addressing directly: NIS2 compliance and financial protection are not the same thing.
Does NIS2 Apply to Your Business?
NIS2 covers 18 critical sectors, including energy, transport, banking, financial market infrastructure, healthcare, digital infrastructure, ICT service management, public administration, digital service providers, and food. It applies to medium and large businesses meeting the relevant thresholds — though it’s worth verifying exactly where your business sits.
The National Cybersecurity Authority offers an online self-assessment tool at cyber.gov.gr if you want to check your status.
What the Directive Actually Requires
NIS2 sets out concrete obligations: risk assessments, protective security measures, staff training, and documented incident response procedures. The goal is for organisations to be genuinely prepared — not just nominally compliant.
One of the most significant changes is around accountability at the top. Under NIS2, senior management can’t treat cybersecurity as someone else’s problem. Executives are expected to understand the risks, sign off on policies, and carry personal accountability for compliance. If that feels like a shift from how things have worked until now, that’s intentional.
Penalties for non-compliance are substantial — up to €10 million or a percentage of global annual turnover, depending on how your business is categorised.
To understand what a real-world incident looks like and what it costs businesses in practice: Cyberattacks on Greek Businesses: The Numbers, the Scenarios, and How to Protect Yourself .
Where NIS2 Ends
NIS2 is fundamentally a prevention framework. It pushes organisations to reduce the likelihood of an incident and respond more effectively when one occurs. On those terms, it’s valuable.
What it doesn’t do is pick up the financial cost when something goes wrong. Downtime, lost revenue, recovery expenses, legal fees, crisis communications — those sit entirely with the business. And it’s worth being explicit on one point: fines for non-compliance cannot be insured against. The financial damage from an actual incident can be.
How Cyber Insurance Fits In
Cyber insurance isn’t a shortcut around NIS2, and it doesn’t make the regulatory work optional. What it does is address the part of the risk that NIS2 can’t — the financial exposure when a breach occurs despite everything you’ve put in place.
Think of it as two separate but connected layers: compliance reduces the probability of an incident; insurance limits the damage when one happens anyway. A fully NIS2-compliant business can still be breached — because no security controls are absolute. The practical question is whether the business can absorb what comes next.
For a breakdown of what a cyber insurance policy typically covers: Cyber Insurance for Businesses: What It Is and Why Yours Needs It .
A Complete Approach
NIS2 is a step in the right direction. It creates a meaningful framework for how businesses should think about and manage cyber risk — and it holds leadership accountable for getting it right.
But a business that is compliant and uninsured still has a significant gap in its protection. Real resilience means combining regulatory compliance with insurance coverage that’s actually sized to the risk. When both are in place, a breach becomes something to manage — not something that threatens the business.
FAQ
If I’m NIS2-compliant, am I fully protected? No. NIS2 helps your business get better organized against cyber risk. But it doesn’t cover the financial impact of an attack — lost revenue, restoration costs, legal fees. That remains the business’s responsibility.
Does NIS2 apply only to large companies? It applies to medium and large businesses across 18 critical sectors — from energy and healthcare to food and digital services. If you’re not sure whether it applies to you, you can check at cyber.gov.gr.
Are NIS2 non-compliance fines covered by insurance? No. No insurance policy covers regulatory fines. That’s precisely why compliance and insurance aren’t alternatives — they’re two sides of the same strategy.
If you’d like to understand what that looks like for your specific situation, get in touch.
Contact us

