Newsletters


Irish Businesses Need to Step Up Cyber Defences as Ireland Assumes EU Presidency

Back to Articles

22 July 2026

PwC today warns Irish businesses to step-up cyber defences as Ireland assumes the Presidency of the Council of the European Union. 

According to PwC, the exposure to heightened cyber attacks is significant not only in their cost but in their disruption to business: Ireland is widely recognised as Europe’s largest data hosting cluster, alongside several transatlantic subsea cable landing points. Disruption here carries continent-wide consequences.

Cyber threats will likely rise sharply as Ireland assumes the Presidency and Irish businesses really need to be prepared.  Ireland will host EU Government Leaders and Heads of State and the European Political Community from up to 47 European countries including 22 informal Ministerial meetings and around 250 additional events attended by more than 30,000 delegates.  The country becomes the temporary routing hub for sensitive EU political, economic, sanctions and foreign-policy material, and a priority target for state-aligned threat actors, hacktivists and organised cyber-criminals.” 

Ireland's National Cyber Security Centre (NCSC) recently confirmed that, as a nation, we are "in a heightened cyber risk environment."

A wider geopolitical storm 

The Presidency window does not exist in isolation. It coincides with continuing war in Ukraine and Middle East instability where we have seen increased threat activity including significant daily hacktivism. Threat actors have also been active against the current Cypriot Presidency, with cyber activity centred on airports. The Irish Presidency amplifies an already deteriorating baseline.   AI models capable of autonomously identifying and exploiting system vulnerabilities can quickly move from defenders' hands into those of attackers.

For Ireland, as a leading digital and data hub, this underlines a key point: Presidency-related risk is amplified by the wider global threat environment, not driven by EU activity alone. 

The regulatory backdrop is tightening 

The cybersecurity regulatory environment is tightening. The National Cyber Security Bill 2024, which transposes the Network and Information Security Directive 2 (NIS2), the EU-wide legislation on cybersecurity and grants the NCSC statutory powers, has not yet been enacted. The Critical Entities Resilience (CER) Directive raises the bar further on physical and operational resilience for essential services.  Boards should expect both new regulations to shape supervisory expectations through the Presidency window and beyond.

AI is accelerating both sides of the race

PwC's Annual Threat Dynamics 2026 report underscores the urgency: AI is creating a shared urgency.  

  • Threat actors now treat AI as core tradecraft, not an enhancement. They use it to automate reconnaissance, craft convincing phishing lures, speed up malware development, and scale social engineering across languages and platforms. 

  • The gap between an AI capability's public release and its weaponisation is shrinking sharply. Autonomous AI agents that can execute full attack sequences without human input are a primary concern. 

  • However, AI is also defenders' single greatest opportunity to match that pace, enabling faster detection, automated containment, and intelligence led decision making at scale.

Actions for companies to mitigate cyber risk

PwC Ireland recommends that Irish businesses take the following steps now to mitigate cyber risk: 

Treat 1 July–31 December 2026 as a sustained elevated-threat window. Update cyber risk and threat scenario scoring accordingly. 

Lock down government and EU-related interfaces. Audit and tighten any connections used by government counterparties or Presidency support functions (if relevant). 

Accelerate patching cadence. Subscribe to NCSC Alerts & Advisories and apply their Cyber Vitals Checklist during heightened-threat periods. 

Stress-test supply chain and third-party risk. Map critical IT and OT suppliers, require evidence of NIS2 aligned controls, and identify single points of failure. Internet-exposed VPN concentrators must require MFA. 

Rehearse crisis response. Run scenario exercises around the major Presidency set-pieces, using the European Union Agency for Cybersecurity (ENISA) Cybersecurity Exercise Methodology as a structuring framework. 

Harden internet-facing assets. Apply zero-trust principles: least privilege, continuous monitoring, encryption and device security. 

Train staff for AI-enabled social engineering. Expect highly convincing phishing, voice cloning and deepfake impersonation aimed at finance, procurement and executive functions. 

Businesses need to be on red alert and step up their cyber defences at this time.  Organisations that are resilient, and have undertaken appropriate cyber risk assessments, will be much more able to defend any attackers.  We urge all businesses to take action now and follow steps to mitigate cyber risk.

By Will O’Brien, Director, Cybersecurity Practice, PwC Ireland

 

Please login or register to post comments.
My HomeNews and MediaNewsletters