A series examining how technology, AI, and cyber threats are reshaping business.
There's a new regulation every quarter. NIS2, GDPR, ISO 27001, DORA, EU AI Act, CSRD. Your inbox is full of compliance newsletters you don't read. Here's the thing: ignoring them won't make them go away. And fines don't care about your ignorance.
For many business leaders, compliance feels like a tax on productivity — an endless parade of acronyms, audits, and paperwork that distracts from the actual work of running a company. But that perspective, however understandable, is dangerously incomplete. Compliance isn't just a legal obligation. It's a structural framework that, when approached correctly, strengthens your organisation from the inside out.
The Compliance Tsunami
Let's take stock of what's on the table for businesses operating in Greece and the European Union in 2026. The regulatory landscape has never been more demanding:
GDPR — Nearly eight years after its enforcement, the General Data Protection Regulation remains poorly implemented across much of the Greek business landscape. Many organisations still treat it as a one-time checkbox exercise rather than an ongoing operational requirement. Data breaches continue to be reported months late — or not at all.
NIS2 Directive — The Network and Information Security Directive 2 dramatically expanded its scope beyond the original NIS framework. Sectors that previously flew under the radar — waste management, postal services, food production, manufacturing — now fall within its reach. The directive demands concrete cybersecurity risk management measures, incident reporting within 24 hours, and supply chain security oversight.
DORA — The Digital Operational Resilience Act targets the financial sector specifically, requiring banks, insurance companies, investment firms, and their critical ICT service providers to demonstrate resilience against digital disruptions. If your company provides IT services to a financial institution, DORA applies to you too.
ISO 27001:2022 — While not a regulation per se, ISO 27001 certification has become a de facto market requirement. Increasingly, procurement departments and tender processes demand it. The 2022 revision introduced new controls around threat intelligence, cloud security, and data masking that many certified organisations have yet to implement.
EU AI Act — The world's first comprehensive AI regulation introduces risk-based classifications for AI systems. High-risk applications in healthcare, education, employment, and critical infrastructure face stringent requirements. Even organisations using AI indirectly through third-party tools need to understand their obligations.
CSRD — The Corporate Sustainability Reporting Directive extends mandatory sustainability reporting to a far broader set of companies. While primarily focused on environmental and social governance, CSRD intersects with cybersecurity through requirements for digital ethics and data governance transparency.
That's six major regulatory frameworks, each with its own requirements, timelines, and enforcement mechanisms. And this list isn't exhaustive.
The Checkbox Problem
Most companies respond to this regulatory pressure the same way: they treat compliance as a checklist. Download a template. Fill in the blanks. File the documents. Move on. Annual review — maybe. If the auditor doesn't ask, it doesn't exist.
This approach is understandable. It's also the reason compliance fails so spectacularly when it matters most.
Consider the typical GDPR implementation at a Greek SME. There's a privacy policy on the website. A data processing agreement in a drawer somewhere. Perhaps a cookie banner that doesn't actually block cookies until consent is given. The company has technically "done GDPR." In practice, employees email personal data in unencrypted attachments, customer databases have no access controls, and nobody has tested whether the data subject request process actually works.
The documents exist. The compliance doesn't.
Why Checkboxes Fail
Compliance is fundamentally about culture and processes, not documents. A policy that nobody reads is worthless. A risk assessment that sits in a folder until the next audit achieves nothing. An incident response plan that has never been tested will fail when you need it most.
Real compliance lives in daily operations: in how your staff handles data, how your systems are configured, how your vendors are managed, how your incidents are detected and reported. It requires training, awareness, accountability, and — critically — leadership that treats regulatory requirements as operational priorities rather than administrative burdens.
The organisations that suffer the worst outcomes from regulatory enforcement aren't those that made honest mistakes. They're the ones that built elaborate paper trails while doing nothing substantive underneath.
Compliance as Navigation
We think of compliance as navigation, not stamp-collecting. You're steering an organisation through regulatory waters that shift constantly. Some channels are well-marked. Others require judgment, local knowledge, and the willingness to adjust course when conditions change.
This navigational approach means understanding that regulations don't exist in isolation. GDPR, NIS2, and ISO 27001 overlap significantly in their requirements for risk management, incident handling, and organisational accountability. A smart compliance strategy addresses these overlaps once rather than three times independently. It builds a unified governance framework that satisfies multiple obligations simultaneously.
It also means recognising that compliance requirements evolve. The organisation that built its GDPR programme in 2018 and hasn't touched it since is almost certainly non-compliant today. Regulatory navigation is continuous, not a destination you arrive at.
Compliance Does Not Equal Security
This distinction matters more than most people realise. You can be fully compliant with every applicable regulation and still be vulnerable to attack. Compliance sets a baseline — often a minimum baseline — for security controls. Sophisticated threat actors don't care whether you've passed your ISO 27001 audit.
Conversely, you can have excellent security practices and still face significant fines for non-compliance. An organisation with world-class technical defences but no documented data processing agreements, no appointed DPO where required, or no incident notification procedures is exposed to regulatory penalties regardless of how secure its systems actually are.
The goal is to build security that exceeds compliance requirements while ensuring that all regulatory obligations are documented, implemented, and demonstrable. Security without compliance leaves you legally exposed. Compliance without security leaves you operationally exposed. You need both.
The Cost-Benefit Reality
Let's talk numbers. GDPR fines can reach 4% of annual global turnover or 20 million euros, whichever is higher. NIS2 introduces fines of up to 10 million euros or 2% of global turnover for essential entities. DORA penalties can be similarly severe, with additional personal liability for management.
But fines are only part of the equation. The average cost of a data breach in 2025 exceeded 4.5 million euros globally. Add reputational damage, customer loss, legal fees, remediation costs, and business interruption. A single serious incident can cost an SME its existence.
Compare that to the cost of implementing a reasonable compliance programme. For a mid-sized business, a comprehensive initial assessment, gap analysis, policy development, and basic implementation might run between 15,000 and 50,000 euros depending on complexity. Ongoing maintenance and advisory services add annual costs. These are significant investments — but they're rounding errors compared to the cost of a breach or regulatory enforcement action.
The calculation isn't close. Compliance is cheaper than non-compliance by orders of magnitude.
The Greek Reality
Greek regulatory enforcement has been historically lenient — a fact that has bred complacency across the business landscape. Many organisations operate under the assumption that enforcement is theoretical, that the Hellenic Data Protection Authority lacks the resources to pursue smaller companies, that "nobody is actually checking."
This assumption is increasingly wrong. The HDPA has issued substantial fines in recent years and is building enforcement capacity. NIS2 transposition into Greek law has expanded the scope of organisations under regulatory scrutiny. European cross-border enforcement mechanisms mean that a complaint filed in Germany can trigger an investigation of a Greek company's practices.
The belief that "we're too small for compliance" is particularly dangerous. NIS2's expanded scope deliberately targets medium-sized enterprises that were previously exempt. Companies with 50 or more employees in covered sectors are now within scope. Many Greek businesses that assumed they were beneath the regulatory radar are about to discover otherwise.
The "we'll deal with it when they fine us" mentality ignores a fundamental reality: by the time enforcement arrives, the cost of remediation is vastly higher than the cost of proactive compliance. And in the case of a data breach, the damage is already done — no amount of retrospective compliance can undo the exposure of customer data or the disruption of critical services.
For SMEs: You Don't Need a Department
Here's the practical reality for small and medium enterprises: you don't need to hire a compliance department. You don't need a Chief Compliance Officer. You don't need enterprise-grade governance platforms.
What you need is a trusted advisor who understands your business context, your regulatory obligations, and the practical steps required to meet them. Someone who can distinguish between what's genuinely required and what's aspirational. Someone who can build a proportionate compliance framework that addresses your actual risks without drowning you in unnecessary bureaucracy.
The most effective compliance programmes for SMEs are lean, focused, and integrated into existing business processes. They leverage overlaps between regulations. They prioritise the controls that deliver the most risk reduction. They're built to be maintained by your existing team, not by a dedicated compliance function that you can't afford.
The Opportunity in Compliance
Here's what most compliance critics miss: regulatory requirements, when implemented properly, force you to do things you should be doing anyway. Documenting your processes. Understanding your data flows. Managing your vendors. Training your staff. Testing your incident response. Assessing your risks.
These aren't bureaucratic overhead. They're operational excellence. An organisation that has genuinely implemented ISO 27001 doesn't just have a certificate on the wall — it has a functioning management system that identifies and addresses risks, allocates resources effectively, and improves continuously. That's not a burden. That's a competitive advantage.
Compliance isn't the enemy. It's a roadmap someone else wrote for your protection. The organisations that thrive aren't those that resist regulation — they're those that use it as a framework to build genuine resilience.
Compliance is not a checkbox exercise — it's a continuous process of navigating regulatory requirements while building genuine operational resilience. The cost of proactive compliance is a fraction of the cost of enforcement, breach remediation, and reputational damage. For SMEs, the smartest approach is a proportionate, advisor-guided framework that turns regulatory obligations into structural improvements.
Previous in the series: The Dark Web: The Invisible Market Selling Your Data Right Now
Next in the series: Website Defacement, Brand Destruction, and Your Digital Storefront
IWH provides compliance advisory and implementation services. Contact us for a confidential consultation.