Are the country's Municipalities vulnerable to cyberattacks? The recent hacking incident in the Municipality of Thessaloniki is one of many that are likely to occur, taking into account the general situation in the infrastructure and procedures of the country's Municipalities.

See also: DoppelPaymer renamed to Grief ransomware
A cyberattack incident in a municipality, especially one of the largest in the country, is not just a bolt from the blue. When the level of protection is not as expected and the potential benefit is significant, a cyberattack becomes possible.
The Municipality of Thessaloniki had been partially warned at least since December 2019, when Your Data Matters completed and published its research on the degree of adaptation of the country's Municipalities to the GDPR. We say partially, as the audit only concerned the Municipality's website, where a series of factors were measured that indicate the level of adaptation of the Municipality to the requirements of the legislation.
See also: Ransomware: Common ways hackers break into a network
We would like to remind you that one of the most important issues in the protection of personal data is its security, especially in the digital world. The Confidentiality – Integrity – Availability principle is a central principle in information security. This principle is a requirement for compliance with the GDPR.
When the Your Data Matters survey was completed, all the municipalities in the country were informed by separate letters about the general result and were given the opportunity to receive more specific information about the results of each municipality individually, if they so wished, without any financial burden of course.
The Municipality of Thessaloniki was interested in learning its results, with Protocol No. 257385/23-12-2019, signed by Deputy Mayor Mr. Avarlis.
Your Data Matters responded immediately with a letter stating, among other things:
"The survey data indicates that your Municipality's website has a limited to low level of compliance with the General Data Protection Regulation 679/2016/EU and e-privacy legislation (Law 3471/2006)."
"The absence of reference to the existence of a DPO, the absence of reference to the rights of the subjects and the failure to mention the purposes of processing in the Privacy Policy constitute significant shortcomings, which, if not covered by some other means, indicate a violation of the GDPR, while further giving the impression of limited compliance, possibly regardless of the existing level of compliance of the Municipality of Thessaloniki."
See also: Microsoft on BazarCall: Initial attacks can lead to ransomware within 48 hours
"Furthermore, the failure to display information about the use of cookies also constitutes an omission of e-privacy legislation."
"The survey criteria do not exhaust the overall evaluation of your Municipality's website."
At the same time, Your Data Matters expressed its availability "for exchange of views, information and cooperation in relation to personal data protection issues of the Municipality.".
See also: Biden: Cyberattacks could lead to a real war
Since then, there has been no further communication from the Municipality of Thessaloniki to Your Data Matters.
In the detailed presentation of the research by Your Data Matters, it was emphasized that the Municipality's website (as well as any institution) is its public image from which conclusions of a more general nature are drawn. An institution that shows the required care and does what is necessary to comply with the requirements of the GDPR is expected to be reflected in its public image. The reverse is also true: if the public image is not good, this is an indication that the problem does not only concern the public image.
A question that arises effortlessly is "if the Municipality of Thessaloniki, which has more resources than most Municipalities, is in such a situation, what happens to smaller Municipalities?".

A second question is whether the APDPH has taken any action towards the municipalities of the country. It should be noted that the Your Data Matters survey with the analytical data of the municipalities had been officially sent to the APDPH as early as December 2019.
Third question: were the provisions of the GDPR implemented in cases of violation? Within 72 hours, was there a detailed update on whether personal data was violated (in any way), who was affected, how the problem will be remedied (and to what extent)? Since there is no relevant announcement, does this mean that nothing like this has happened or that the Municipality was unable to meet its obligations towards citizens and supervisory authorities?
In any case, this incident and its handling should ring alarm bells about the level of protection of citizens' personal data more than 3 years after the implementation of the GDPR.
Source of information: news247.gr
