Frequently Asked Questions

Find answers to frequently asked questions about BH Consulting’s cybersecurity, data protection, compliance, AI governance and training services. If you cannot find the information you need, contact our team for independent advice tailored to your organisation.

Business team posing for a portrait in the office

Frequently Asked Questions

What does BH Consulting do?

BH Consulting is an independent cybersecurity and data protection consultancy. We help organisations manage cyber risk, protect personal and business information, meet regulatory obligations and strengthen their overall security and resilience.

Our services cover cybersecurity advisory, security testing and assurance, data protection, compliance, AI governance, security and data protection awareness training.

BH Consulting provides a comprehensive range of cybersecurity services, including:

  • Virtual CISO (CISO as a Service)
  • Cybersecurity maturity assessments 
  • Business continuity and incident response planning 
  • Third-party risk management 
  • M365, Azure, AWS, Google Workspace and other Cloud based security assessments 
  • Penetration testing and vulnerability assessments 
  • Identity and access management advisory
  • Operational technology and smart-building security 
  • Cybersecurity awareness training 
  • AI Governance and AI implementation assurance


We tailor each engagement to the organisation’s size, risk profile, regulatory obligations and business objectives.

BH Consulting provides advisory and alignment services covering several recognised regulations, standards and frameworks, including:

  • ISO 27001 and ISO 27701 
  • NIS2 (incorporating Cyber Fundamentals)
  • GDPR 
  • DORA 
  • Cyber Essentials 
  • PCI DSS 
  • TISAX 
  • STAR, Cloud Security Alliance


The most appropriate framework will depend on your industry, location, contractual commitments and regulatory obligations.

Yes. BH Consulting is fully independent and is not tied to particular cybersecurity vendors, technologies or products. This enables our consultants to provide impartial, vendor-neutral recommendations based on each client’s needs.

No. Our services are delivered exclusively by highly experienced senior consultants. This ensures clients receive expert guidance, efficient delivery and consistently high-quality outcomes. Our experienced team is known for completing projects cost effectively, while maintaining a clear scope and minimising project delays or unexpected additional costs.

A Virtual Chief Information Security Officer, or Virtual CISO, provides experienced cybersecurity leadership without the cost of employing a full-time CISO.

BH Consulting’s Virtual CISO service can help an organisation develop its cybersecurity strategy, manage risk, oversee security programmes, report to senior management and prepare for regulatory or customer requirements.

Our cybersecurity maturity assessments evaluate an organisation’s existing security arrangements, identify gaps and provide a prioritised improvement roadmap.

Depending on your requirements, we can assess your organisation against recognised frameworks, industry standards, regulatory obligations or agreed security objectives.

Yes. BH Consulting provides penetration testing, vulnerability assessments and specialist technical security reviews. These services can help organisations identify and address weaknesses across networks, applications, cloud environments, firewalls, Microsoft 365 and Google Workspace.

The appropriate assessment will depend on your in-scope systems and applications, risk profile and reasons for testing.

BH Consulting helps organisations establish and maintain effective data protection programmes. Our services include:

  • Outsourced Data Protection Officer (DPO) services 
  • GDPR maturity assessments and audits 
  • Data Protection Impact Assessments 
  • Preparation of Records of Processing Activities 
  • Tailored policy development 
  • EU & UK Representative services 
  • Data protection awareness training 
  • EU–US Data Privacy Framework implementation support 


Our advice is practical, risk-based and tailored to the personal data your organisation processes, with whom and why.

An outsourced Data Protection Officer, or DPO, provides independent data protection expertise and oversight without requiring the organisation to recruit a full-time internal DPO.

BH Consulting can help monitor GDPR compliance, advise senior management, review policies and assessments, support staff and act as a contact point for data protection authorities and individuals.

Yes. BH Consulting helps organisations assess their readiness for NIS2 and develop a structured programme for addressing relevant cybersecurity risk management and governance requirements.

Support may include readiness assessments, gap analysis, NIS2 alignment, incident response planning, supply-chain security and senior management briefings.

Yes. BH Consulting can help organisations assess and align their cybersecurity maturity against the Cyber Fundamentals framework, commonly known as CyFun.

Our consultants can identify gaps, evaluate existing controls and develop a practical roadmap to support alignment with the framework and relevant NIS2 obligations.

BH Consulting can help organisations prepare for ISO 27001 certification by establishing, improving and maintaining an Information Security Management System.

Our ISO 27001 services include gap assessments, alignment support, policy development, risk management, internal audits and ISMS Manager as a Service. Certification itself must be awarded by an independent accredited certification body.

Yes. BH Consulting helps organisations use artificial intelligence securely, responsibly and in compliance with applicable data protection and regulatory requirements.

Our AI governance, risk and compliance services can help with AI risk assessments, governance frameworks, policies, acceptable-use guidance, security and privacy reviews, regulatory readiness and the safe implementation of tools such as Microsoft Copilot and ChatGPT.

Yes. BH Consulting provides cybersecurity awareness and data protection training for employees, managers and senior leadership.

Training can be tailored to your organisation’s industry, workforce, risk profile and regulatory obligations. We also provide specialist presentations, workshops and incident response tabletop exercises.

No. BH Consulting works with organisations of different sizes and across a range of sectors. Our services can be adapted for small and medium-sized businesses, multinational companies, public-sector bodies, charities and other organisations requiring independent cybersecurity or data protection expertise.

Yes. BH Consulting is headquartered in Dublin and serves clients internationally, including organisations across Ireland, the UK, the US, Europe, the Middle East and Asia-Pacific. BH Consulting also has office locations in Ireland, the United Kingdom and the United States.

BH Consulting provides independent, practical and expert-led advice tailored to each organisation. We have more than 20 years of experience helping organisations manage cybersecurity, privacy and compliance risks.

Because we are not tied to specific technology vendors, our recommendations are entirely vendor neutral, based on our clients’ business needs and risk exposure.

You do not need to identify the exact service before contacting us. Our team can discuss your organisation’s challenges, objectives and regulatory obligations before recommending an appropriate assessment or programme of work.

You can contact BH Consulting by emailing info@bhconsulting.ie, calling +353 1 440 4065 in Ireland or completing the consultation form on our contact page.