powered_by-logo reporter-logo inbusiness-news-logo GOLD-DIGITAL-EDITIONS

New Commissioner of Communication shares his three priorities for the coming years: "Cybersecurity is moving from the IT Department to the Boardroom"

In June, Marios Pieris was appointed Commissioner of Communications, responsible for the Office of the Commissioner for Electronic Communications & Postal Regulation (OCECPR) and the Digital Security Authority (DSA), both increasingly crucial services, which underpin and facilitate key sectors.

In a recent interview with GOLD magazine, he explains the impact of transformative regulatory overhauls and never-ending efforts to keep pace with ever-advancing technology.

 

After being appointed Commissioner of Communications, you spoke about your ambitious goals for the Office in the upcoming years. What are the most exciting and the most important for you?

The years ahead will not be defined only by technological progress but by which countries succeed in turning technology into trust, resilience and sustainable economic value.

For Cyprus, I see three priorities as especially important. The first is to strengthen national cyber resilience through the effective implementation of NIS2. This is not simply a compliance exercise. It is about ensuring that essential services can continue to operate, that organisations can withstand and recover from incidents, and that citizens and businesses can use digital services with confidence.

The second is to maintain a modern, predictable and investment-friendly regulatory environment for electronic communications. Cyprus needs secure, affordable and high-capacity connectivity, effective competition and the right conditions for continued investment in next-generation networks. Postal services also remain an important part of our mandate and they must continue to modernise while preserving accessibility, quality and universal service.

The third priority concerns institutional capability. The Office has a broad and increasingly strategic mandate, encompassing electronic communications, postal regulation and digital security. My ambition is to build on the strong foundation that already exists and develop an organisation that combines regulatory excellence, technical expertise, operational readiness and international engagement. This requires continuous investment in our people, clear priorities and a culture of accountability, collaboration and innovation.

Sustainable success is never the work of one person; it is achieved when an entire organisation understands its purpose and works in the same direction. Cyprus has already developed important capabilities through the Digital Security Authority, CSIRT-CY, NCC-CY, the ICT Academy and the Security Operations Centre. It also contributes to major international cybersecurity initiatives, including the Maritime Cybersecurity Centre of Excellence, MarCCE, coordinated by the Shipping Deputy Ministry, in cooperation with the Deputy Ministry of Research, Innovation and Digital Policy and international partners, with the active participation of our Office. Our close cooperation with the European Commission, ENISA, the European Cybersecurity Competence Centre, fellow Member States and strategic partners demonstrates that Cyprus can play a role far beyond its size.

Ultimately, I want the Office to be recognised not only as an effective regulator but as a trusted institution that protects the public interest, enables investment and innovation, and contributes meaningfully to the European and international digital agenda. My goal is to leave behind an organisation that is stronger, more capable and even more respected than it is today.

The NIS2 Directive was transposed into national legislation in 2025, raising the number of supervised entities. What impact has this had on Cyprus so far?

The most important impact of NIS2 is that cybersecurity is moving from the IT Department to the Boardroom. The Directive, which was transposed into Cypriot law in 2025, expanded the supervisory scope from approximately 70 to around 600 entities across the 18 sectors covered by NIS2. For these organisations, cybersecurity is now a governance and business-continuity responsibility. Senior management must understand the risks, approve appropriate measures and ensure that they are implemented. This includes risk management, incident reporting, business continuity, supply-chain security, audits, cyber hygiene and employee training. The transition is significant. Many newly supervised entities are assessing their maturity, formalising responsibilities and investing in controls for the first time.

At the same time, this expansion creates genuine challenges, particularly in relation to specialised skills, budgets and the availability of qualified professionals. Our role is therefore not limited to enforcement. The Digital Security Authority is developing the supervisory framework, guidance, digital reporting and stakeholder-management tools needed to support entities through this transition. The objective is proportionate and effective implementation: strong enough to reduce national risk but practical enough to help organisa-tions build sustainable resilience rather than treat compliance as a checklist.

What are the most commonly identified major gaps in private companies’ cybersecurity protocols and what support is available to them?

The most common gap is not a particular technology; it is the absence of clear governance and a mature cybersecurity culture. In many organisations, particularly SMEs, responsibility is fragmented, risks are not assessed regularly and security decisions remain reactive. Typical weaknesses include incomplete asset inventories, outdated systems, weak access controls, insufficient use of multi-factor authentication, limited incident-response and business-continuity planning, inadequate employee awareness and insufficient oversight of suppliers. Supply-chain risk is especially important because an organisation may have strong internal controls and still be exposed through a critical partner or service provider.

Having spent much of my career managing technology in a highly sensitive healthcare environment, I know that cyber resilience is not an abstract compliance issue. It is about keeping essential services available when people need them most. Support is available through the Digital Security Authority, NCC-CY and the ICT Academy in the form of guidance, awareness initiatives, specialised training, workshops and information-sharing activities. Almost 9,000 participants have taken part in ICT Academy training over the past two and a half years.

Through NCC-CY and the Research and Innovation Foundation, more than €3.5 million in cybersecurity funding opportunities has also been made available for technologies, services and skills. NCC-CY also supports organisations seeking access to European funding programmes, including Horizon Europe and Digital Europe, through guidance, networking and partnership building. The aim is to combine regulation with practical capability-building, so that organisations do not merely comply with legal requirements but become genuinely more secure and resilient.

The National CSIRT-CY handled more than 500 reported incidents in 2024 alone. Has this picture shifted in 2026 and where do you see the trend heading?

It is important to be careful when comparing a completed year with partial-year data. What we can say in 2026 is that pressure remains high and the threat environment is becoming more complex. We continue to see activity affecting finance, telecommunications, energy, public administration, healthcare and other essential services. An increase in reported incidents should not automatically be interpreted only as an increase in successful attacks. It can also reflect stronger reporting obligations, better detection capabilities and greater trust between organisations and CSIRT-CY. The direction, however, is clear. Threat actors are using automation and artificial intelligence to scale phishing, business email compromise and social-engineering attacks. They continue to exploit internet-facing systems, unpatched vulnerabilities, weak credentials and third-party dependencies. Ransomware, data theft and service disruption remain serious risks. Our response must combine prevention, early detection, rapid incident handling, exercises, threat-intelligence sharing and tested recovery plans. Resilience is measured not by whether an organisation is ever attacked but by how effectively it can contain the impact, recover and continue operating.

Is Cyprus facing advanced state-linked threats or is it mostly opportunistic exploitation by individuals and groups? How does this impact the work of your Office?

The honest answer is that Cyprus operates in a threat environment that includes both opportunistic cybercrime and more sophisticated campaigns conducted by highly capable actors. Our strategic location, international business activity, shipping sector and digital connectivity increase our exposure to campaigns that may be regional or global in scope. Attribution, however, must be approached responsibly. We do not label an incident as state-linked without high-confidence evidence and coordination with the competent national and international authorities. From an operational perspective, our approach is intelligence-led and threat-agnostic. Organisations must be able to detect, respond to and recover from an incident, regardless of who is behind it. This requires strong technical capabilities, secure and timely threat-intelligence exchange, continuous exercises and close cooperation with national authorities, the private sector, the European CSIRT Network, ENISA and trusted international partners. Many incidents affecting Cyprus are part of wider campaigns rather than attacks directed exclusively at the country. That makes international cooperation indispensable. Cybersecurity is a shared responsibility and trust between institutions is one of the most powerful defensive capabilities we can build.

This interview first appeared in the July edition of GOLD magazine. Click here to view it.