Security Roundup July 2026

Security Watch

Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants.

NIS2 not yet law in Ireland, but nonetheless in force

The European Commission is taking four member states to court for failing to implement the NIS2 Directive, the EU’s flagship cybersecurity law. Ireland, Spain, France and the Netherlands are more than 20 months late in transposing the NIS2 Directive, which sets minimum security standards for critical services such as healthcare, energy, transport and public administration. The original deadline for implementing the law was October 17 2024. Recorded Future’s coverage noted that, of the four countries, Ireland was the only one to make a statement about its implementation plans, “with the minister responsible expecting to notify transposition by end of 2026”. The National Cyber Security Bill will transpose NIS2 and place the National Cyber Security Centre on a statutory footing.

The Business Post reported that Ireland faces substantial fines for failing to enact the law. Daily fines could range between €2,000 to €21,000, and the report suggested a penalty of over €4 million was possible. BH Consulting CEO Brian Honan wrote on LinkedIn that “even without its formal legal transposition status in Ireland, the directive still applies to regulated entities within Ireland, Spain, France, and the Netherlands. Therefore, if your organisation is affected by NIS2, compliance with the directive is necessary, regardless of its transposition status.”

EU REPRESENTATIVE FOR GDPR

GDPR’s reach extends beyond EU borders. No matter where they’re located, organisations selling products or services to individuals in the European Union must have an authorised point of contact based within the EU zone. As a Dublin-based consultancy with years of experience in data protection, BH Consulting provides English-speaking subject matter experts who can communicate with data subjects, liaise with supervisory authorities and maintain records. With our nominated EU Representative service, you’re fully compliant with regulatory requirements while getting dedicated data protection support for a fixed annual fee. Talk to us today.

Data protection and privacy roundup: AI adds to DPC caseload; sharenting shock; and burying breaches

The Data Protection Commission saw a 45 per cent rise in complaints last year, its latest annual report found. Many of those new cases were generated with AI’s assistance, the regulator said. Most data breaches were attributable to human error such as unauthorised disclosures or incorrect recording of details. BH Consulting’s senior data protection consultant Fearghal Keyes analysed the report, saying human oversight is needed more than ever given AI’s increasing influence.

A companion survey from the DPC looked at ‘sharenting’, and found 75 per cent of parents had posted content about their children online. Some 40 per cent of parents rarely ask their children’s permission before posting, even though 66 per cent are aware of the risk of those images being misused.

Meanwhile, some organisations may be failing to report data breaches, according to a survey of 150 compliance professionals. The Compliance Institute polled professionals mainly from the financial sector: 26 per cent said the fear of personal accountability could explain low reporting; 22 per cent cited concerns about brand damage; 19 per cent said regulatory scrutiny or fines would be the main reason for not reporting breaches.

On the subject of protecting minors, Ireland’s Digital Services Coordinator said it will investigate more tech companies, focusing on age assurance, parental controls, and content flagging.

Across the Atlantic, data sharing between the EU and US is under fresh threat following a recent Supreme Court ruling which grants the US president the right to fire officers of independent agencies like the FTC. Privacy campaigners say independent oversight of how Europeans’ data is handled is vital to the deal and are threatening to challenge it.

Downtime and disruption from cyber incidents cost SMEs €3.4 billion

Irish small and medium-sized enterprises (SMEs) lose more than 7.2 million working days every year due to cyber incidents, and affected businesses experience multiple incidents per year. A new report has measured the collective cost of disruption due to cybersecurity incidents and breaches at up to €3.4 billion every year. The average cost of an incident per SME is close to €50,000, and affected firms lose nearly three working weeks. Those figures come from a report, The Hidden Cost of Cyber Risk, published by eir Business and supported by Microsoft and the Kemmy Business School at the University of Limerick.

Although coverage in RTÉTechcentral.ie and elsewhere focused on the headline number, the report itself emphasises that the biggest expense is not a single major breach but the cumulative effect of repeated incidents, downtime, lost productivity, and interruptions to regular operations as staff time gets diverted from their everyday work. Dr Mauricio Perez-Alaniz, assistant professor in the Department of Economics at the Kemmy Business School, said the report attempts to quantify the costs of cyberattacks in terms of the direct economic impact and potential costs associated with downtime. “It is important to keep in mind that fully quantifying such costs is difficult,” he said. “While the estimates presented by the report are necessarily high-level and resting on a set of assumptions, they offer important insights into the scale and nature of the issue.” The report also notes that businesses with stronger preparedness can reduce annual downtime from more than 30 days to around five days. The 19-page high-level report is free to download.

Links we liked

Public consultation has opened on Ireland’s next cybersecurity strategy. MORE

The EU’s new action plan on cybersecurity and AI addresses risks. MORE

Europol’s report into organised crime in the EU has a strong digital angle. MORE

Apple’s ‘Hide my Email’ feature appears to have sprung a leak. MORE

An oldie from Zack Whittaker: how to read a data breach notice. MORE

Cisco Talos researchers found a toolkit that automates email scams. MORE

Profiling Allison Nixon’s excellent work unmasking cybercriminals. MORE

A data breach with consequences, exposing over a million passports. MORE

Patch Tuesday is about to get a lot busier because of AI. MORE

ZEGO in Germany is the latest firm forced out of business by cybercrime. MORE

Have you signed up to our monthly newsletter? Every month we send out the latest cybersecurity and data protection news, trends and advice from around the globe.

Sign up here

Why get in touch with BH Consulting

BH Consulting is a trusted, independent cybersecurity and data protection consultancy with over 20 years of experience. Whether you need expert guidance on compliance, risk management, or security strategy, our team delivers practical, vendor-neutral advice tailored to your needs.

Let’s start a conversation about securing your business.

cyber ireland 2021 logo
Respect in Security Pledge logo

Areas of interest*