Ireland Has the EU Presidency. Here’s What It Means for Your Cyber Risk. 

TL;DR
  • Ireland holds the EU Council Presidency from July to December 2026, which raises its profile as a target for cyber attacks.
  • The NCSC’s 2025 risk assessment and ENISA’s 2025 report point the same way: more attacks, more political motivation, hacktivism now near 80% of EU incidents.
  • Smaller firms get caught in the spillover through supply chains and shared infrastructure.
  • NIS2 still isn’t Irish law, but board-level accountability is already here.
  • Five practical steps below. None of them need a big budget.

Ireland took over the Presidency of the Council of the European Union on 1 July, and holds it until the end of December. It’s a genuine moment of pride for the country. For six months, Irish ministers and officials sit at the centre of EU decision-making, from trade to climate policy. The same prominence also raises the country’s exposure to cyber attacks.

Why the Presidency raises Ireland’s cyber risk

The National Cyber Security Centre made the case in its 2025 National Cyber Risk Assessment, published last December. Richard Browne, the NCSC’s Director, put it plainly: Ireland’s national security now depends on the integrity, availability and security of its digital infrastructure, and the risks are moving faster than most organisations realise.

Ireland’s exposure runs wider than events on Irish soil. Because the country hosts so much multinational tech and financial infrastructure, Irish operations get pulled into the fallout when one of those global players is hit, even when the original target was never Irish.

What the numbers actually show

Across the EU, hacktivism now accounts for almost 80% of recorded cyber incidents, according to ENISA’s 2025 Threat Landscape. Most of that is low-impact: short attacks that knock a website offline for a while, with only about 2% causing real service disruption. Behind some of that activity sits a more serious threat. State-aligned groups hide behind a hacktivist front to run disruptive attacks while keeping deniability, which ENISA calls “faketivism”.

In March 2026, the medical technology firm Stryker had its operations badly disrupted by a destructive data-wiping attack, and the impact reached Ireland directly. Its Cork site, the company’s largest outside the US, was hit hard, with thousands of staff sent home. The group that claimed it, Handala, presents as a hacktivist collective but is widely linked to Iranian state intelligence.

Why a smaller business should care

Those pressures reach well beyond the big names. The NCSC and ENISA both point to energy, digital infrastructure and public administration as the sectors most exposed over the coming months, and very few small businesses sit apart from those.

If you supply a public body, sit in the supply chain of a larger multinational, or just share the same broadband and cloud services as everyone else, a rise in attacks on bigger targets tends to spill over. And smaller firms are usually the least able to absorb it. You don’t have the security budget or the in-house team of a government department or a multinational.

Where NIS2 stands, and why it matters now

There’s a compliance angle too. The deadline for turning the EU’s NIS2 directive into national law passed in October 2024. Ireland still hasn’t done it, and is now facing EU infringement proceedings over the delay. The legislation meant to fix that, the National Cyber Security Bill, is still working its way through.

More businesses fall into scope every year, and most of what NIS2 asks for is sensible security practice you’d want in place regardless. There’s little to gain from waiting for the law to arrive before acting.

Cyber risk is now a board responsibility

Brian Honan of BH Consulting, one of Ireland’s most respected voices on this, has said the same. A recent Institute of Directors Ireland survey found that 46% of directors expect increased cyber risk during the Presidency, and 91% say their personal liability has grown over the past few years. Under NIS2, boards are expected to approve and oversee cyber risk measures themselves rather than delegate them and step back.

Questions you can ask yourself:

  1. If NIS2 applies to your sector, are you waiting for enforcement to catch up with you, or getting ahead of it?
  2. If your systems went down tomorrow, how long would it take you to recover?
  3. Do you have an incident response plan?
  4. Are your backups actually immutable, so ransomware can’t reach and encrypt them too?
  5. Is there an ongoing programme to keep your staff aware, given human error is still behind most breaches?

Frequently asked questions

When does Ireland hold the EU Presidency?

Ireland holds the Presidency of the Council of the European Union from 1 July to 31 December 2026, taking over from Cyprus. It’s the eighth time Ireland has held the role.

Why does the EU Presidency increase cyber risk for Irish businesses?

Holding the Presidency raises Ireland’s international profile, which tends to attract more cyber activity from nation-states, hacktivists and criminals. Because Ireland also hosts a lot of multinational tech and financial infrastructure, attacks on those larger targets can spill over to smaller firms in the same supply chain.

Is NIS2 law in Ireland yet?

Not yet. The EU deadline to transpose NIS2 into national law was October 2024. Ireland missed it and is facing EU infringement proceedings. The National Cyber Security Bill is expected to bring it into Irish law, but until then the earlier NIS1 rules still apply.

Does NIS2 affect small and medium businesses?

It can. NIS2 widens the sectors and organisations in scope compared with the old rules. Even if you’re not directly in scope, you can be pulled in through a larger customer’s supply chain. Most of its requirements are good practice regardless.

What should my business do first?

Start with visibility: know what you have exposed to the internet and keep it patched. Then check your incident response plan, review your supply chain, and make sure your board understands the risk. None of these need a large budget.

Who is responsible for cyber security under NIS2?

The board and senior management. NIS2 requires management bodies to approve and oversee cyber risk measures directly, so it’s no longer something that can be fully delegated to IT.

How We Can Help
    This is the kind of work we do for customers every day: keeping an eye on what’s exposed, what needs patching, and what needs tightening before it becomes a headline. If you’d like a straight assessment of where your business stands, we’re happy to have that conversation. Call us on 0818 987 900 or email hello@intuity.ie.