NIS2 National Cybersecurity Framework
National Cybersecurity Requirements Framework (S3): a New Era for Security in the Digital World
What every business needs to know in 2025 – Full guide by EMD Infotech
What is S3 and why is it relevant to every modern business?
In 2025, cybersecurity enters a new era with the implementation of the National Cybersecurity Requirements Framework (S3), which is the key tool for the implementation of the European NIS2 Directive (Directive 2022/2555/EU).S3 sets out specific obligations and measures for organisations that are considered “key” and “important entities” and operate in critical sectors of the Greek economy and society.
The new Greek legislation (Law 5160/2024 and relevant ministerial decisions of May 2025) is directly binding and affects public, but mainly PRIVATE businesses operating in:
-
Telecommunications
-
Energy
-
Health
-
Transport
-
Information technologies
-
Financial services
-
Food
-
Water management
-
Critical industrial infrastructure
-
Plenty of other sectors, including the hotel and tourism business
What changes with S3 and the new legislation?
It is now required:
-
Holistic risk management: Policies, procedures and measures based on international standards (ISO, NIST, etc.), with documentation of all actions.
-
Explicit management responsibility: top management bodies (Board, CEO, etc.) are now personally responsible for implementation and accountability.
-
Continuous risk assessment and management: regular review of threats, measures and incident response plans.
-
Safety policies & procedures: Mandatory existence and regular updating of policies for access, account management, encryption, encryption, backups, physical and environmental security, vendor partnerships, software development, etc.
-
Designation of a Safety Officer (SHO): a mandatory role in every entity reporting directly to management.
-
Independent checks and tests: Annual internal/external audits and penetration testing.
-
Continuous staff training: Awareness and technical training programmes for all staff.
-
Incident management and notification: Recording, analysis and mandatory reporting of cybersecurity incidents to competent authorities.
More specifically for Hotels & Tourism Businesses
Very often hotel businesses handle critical customer data, online booking processes, payment systems, and smart hospitality technologies (smart rooms, self check-in, etc.). Compliance with S3 is legally mandatory and will now be audited on a regular basis.
Who is at risk if they do not comply?
-
Fines and legal sanctions
-
Loss of partnerships/contracts
-
Damage to reputation
-
Real operational risk (downtime, data loss)
How can EMD Infotech help?
EMD Infotech provides a complete package of cybersecurity compliance and management services, which includes:
-
Initial Audit – gap analysis: investigation of the current situation and weaknesses of your business in relation to S3/NIS2 requirements.
-
Preparation and updating of security policies: We prepare tailor-made policies and procedures (for access, asset management, incidents, encryption, backups, supply chain, etc.).
-
Technical implementation of measures: we install and configure endpoint protection systems, firewalls, MFA, data encryption, etc.
-
Staff and management training: seminars and online workshops, tailored to the role of each team.
-
Conduct penetration tests and vulnerability assessments: annual or ad hoc audits, with full reporting and suggestions for improvement.
-
DPO/CISO-as-a-Service: permanent or on-demand consultancy to maintain compliance.
-
Incident management and reporting support: immediate response to incidents and guidance on mandatory incident notification.
The next steps for each business:
-
Contact EMD Infotech directly for a first update and free compliance assessment.
-
Start with a complete inventory of your assets, systems and processes.
-
Train and raise awareness among your staff.
-
Adopt international cybersecurity standards and practices.
-
Keep active engagement with experts as the threat landscape is constantly changing.
EMD Infotech is here to ensure that your business is shielded, compliant and ready for the digital future.
For any questions or support requests, please contact our team.
More Information
Incident Update: Cloudflare Outage
CLOUDFLARE ISSUE EMD - Impacted Parts of Our Infrastructure Today, a major disruption occurred in the global infrastructure of Cloudflare, affecting a significant number of online services worldwide — including certain servers and platforms operated by EMD Infotech....
EMD Infotech Undertakes Two Strategic Projects for the Municipal Port Fund of Rethymno
Digital Innovation at the Port of RethymnoAutomation and Transparency for the Public SectorEMD Infotech Undertakes Two Strategic Projects for the Municipal Port Fund of Rethymno EMD Infotech officially undertook the implementation of two important digital projects for...
The Next Generation of Artificial Intelligence is here
ChatGPT-5 with "Thinking Mode" announcedThe Next Generation of Artificial IntelligenceWhat GPT-5 brings to the world of AI OpenAI unveiled GPT-5, the most advanced AI model to date. It is a unified system that combines: Rapid response for simple questions. The special...
The New “Agent” Function in Artificial Intelligence
The Step Towards the Digital Assistants of the FutureThe New "Agent" Function in Artificial Intelligence: The Step Towards the Digital Assistants of the FutureArtificial intelligence is evolving rapidly and now brings to professionals the new dynamic of the “Agent”...
Google Gemini gains millions of users
Gemini gained 400 million monthly active users Gemini: Google's new "digital brain" that's winning millions of users This year's Google I/O 2025 stage hid many announcements, but one dominated: the Gemini, Google's advanced AI assistant, has now reached 400 million...
Agentic Ai
The new generation of autonomous digital partners"Agentic AI: The new generation of autonomous digital partners" What is Agentic AI? Agentic AI is the new evolution in terms of AI - it is "multiple autonomous agents" that work cooperatively, make decisions and perform...
Google New AI Mode in Search
Google Globally Activates New AI Mode in SearchThe Next Revolution Is HereGoogle's long-awaited "AI Mode" feature, which until now has been exclusively available in the US, is now taking the big step towards the global user, starting in India and soon in all markets -...
New Accessibility Obligations for Businesses
European Accessibility Act (EAA)New Accessibility Obligations for Businesses: What Directive 2019/882/EU and Greek Legislation Provides forFrom June 2025, significant changes for businesses offering products and services in the European area will come into force,...
The Big Change in Search
Artificial Intelligence is changing the search experienceThe Big Change in Search: How AI Is Changing Users' Digital Habits Traditional search engines, such as Google and Bing, remain at the top of users' choices worldwide. But 2025 brings rapid changes, with...