Press ESC to close

Why Cyprus Companies Need Cyber Risk in the Boardroom

Cyprus companies must prioritize cyber risk at the board level. Attacks are growing more frequent, and the rising use of AI makes these threats harder to manage. Furthermore, many businesses now rely on outside tech providers, which increases their exposure. At this week’s 6th Cyber Security Conference in Nicosia, leaders and experts gathered to address these challenges. They outlined clear strategies for companies to both prepare for potential attacks and effectively respond when they occur.

Cybersecurity is a business issue

For many companies, cybersecurity is still seen as an IT job. But a major cyberattack can affect the whole business. It can stop daily work and affect customers. It can also lead to money losses and problems with regulators. Speakers at the conference said senior managers do not need to be cyber experts. But they must understand the main risks facing their companies. They also need to know what could happen after an attack. Most of all, managers need to know if the company can deal with an attack. Christos Menelaou, a manager at PwC Cyprus, said company leaders need to understand the possible effects of an attack. They also need to check if the company is ready to respond. The situation in Cyprus shows why this matters. Communications Commissioner Marios Pieri said organisations in Cyprus had an average cyber maturity score of 1.6 out of 3. He also said 49% of the required security controls were still at an early or weak stage. The gaps are not only about technology. They also affect how companies manage risk and who can access systems.

Attacks are changing quickly

The risks facing businesses are changing too. The latest ENISA Threat Landscape looked at 4,875 incidents from July 2024 to June 2025. DDoS attacks made up 77% of these cases. Experts called ransomware the most damaging threat. Phishing was still the main way attackers got into systems. Attacks on known software weaknesses came next. AI is creating another challenge. Companies can use AI to find threats and deal with security alerts. It can also help them respond faster. Attackers can use AI too. They can use it to automate parts of an attack and make attacks harder to stop. At the conference, Andreas Konstantinides, director of Odyssey Managed Services, spoke about the growth of autonomous digital agents. These tools can carry out parts of an attack with little human help. This means companies need more than security tools. They also need to check how fast those tools can react during an attack.

The risk can come from outside

Companies also face risks from their tech suppliers. Many of them now depend on cloud services, software companies, outside IT teams, and AI providers. If one supplier has a serious problem, its customers can also be affected. A service may stop working or become unsafe to use. Companies need to know which outside services are vital to their work. They also need a plan for what to do if a supplier is attacked or goes offline. New EU rules are adding to these duties. Under NIS2, the managers of some companies must approve cyber risk measures. They must also make sure these measures are put in place. DORA adds new ICT risk rules for the financial sector. The AI Act and Cyber Resilience Act also bring new rules in their areas. The conference made one point clear: companies cannot stop every cyberattack. They can, however, prepare for one. Senior managers need to understand the risks. They need to know who will make decisions during a crisis. They also need to make sure the business can keep running if its systems go down.

Don’t Miss the Latest Tech Insights

Cybersecurity is changing fast, and so are the risks for businesses. Follow TechPress for more insights on technology, cybersecurity, and the trends shaping the future of business.