Ireland faces EU financial sanctions over NIS2 delay as Aon urges businesses to act - techbuzzireland.com

Aon plc, a leading global professional services firm, has urged organisations not to delay preparations for the EU’s NIS2 Cybersecurity Directive as Ireland faces financial sanctions following its referral to the Court of Justice of the European Union (CJEU) in recent weeks for failing to fully transpose the legislation into national law.

Under the Commission’s published methodology for calculating financial sanctions, Aon has estimated that Ireland has an exposure of approximately €2.8 million, with daily penalties accruing on top for as long as the delay continues. Ireland previously faced a €4.5 million fine over a three-year delay in transposing the European Electronic Communications Code.

Ireland was referred to the CJEU alongside France, Spain and the Netherlands for failing to fully transpose NIS2, which set a legal deadline of 17th October 2024. Almost two years on, Ireland remains non-compliant while the National Cyber Security Bill continues through the legislative process. The Netherlands transposed the directive within recent weeks.

The Directive will substantially expand the number of organisations subject to regulation in Ireland, with increased emphasis on cyber governance, risk management, incident reporting and board accountability.

Aon is calling on the Government to prioritise the National Cyber Security Bill, which transposes the directive, when the Oireachtas returns in September and to progress it through its remaining stages as quickly as possible. With Ireland currently holding the Presidency of the Council of the EU, there is an opportunity to complete transposition and give organisations certainty on the framework that will underpin cyber security governance across critical sectors.

Leann Moroney, Associate Director for Cyber Risk Management, Aon Ireland, said: “NIS2 represents one of the most significant changes to cyber security regulation in recent years and will have implications for thousands of organisations across Ireland, either directly or through their supply chains.

“While the legislation will provide important clarity on how the new framework will operate in practice, organisations should not view transposition as the starting point for action.Cyber threats are not waiting for legislation, and businesses shouldn’t either. The direction of travel is already clear, and cyber risk needs to be treated as a board-level priority now.

“This becomes even more important as organisations adopt AI and other emerging technologies. Strong governance, effective risk management and robust cyber security controls will enable organisations to embrace innovation with confidence while strengthening resilience against cyber threats.”

The firm is also urging organisations not to delay preparations while the legislation completes its passage. Many will face new obligations directly under NIS2, while others will be affected through contractual requirements from customers, suppliers and regulated partners.

As cyber resilience becomes an increasingly strategic business issue, Aon has set out a five-step action plan to help organisations prepare for the new regulatory environment.

  1. Understand organisational exposure

Assessing whether an organisation falls directly within the scope of NIS2, or may be impacted through customer, supplier or partner requirements For example, we have seen this for companies not directly in scope, but key customers are, so it anticipates stricter cyber requirements in contracts

  1. Strengthen governance structures

Embedding cyber risk within governance structures and ensuring appropriate oversight at board and senior leadership level. This can include developing  a “Technology & Cyber Risk” committee that reviews NIS2 readiness, key risks, and incident reports quarterly or may require senior management updating risk appetite statements to explicitly reference cyber risk, including tolerance for ransomware-related downtime or data loss.

  1. Assess cyber resilience capabilities

Reviewing cyber security controls, cyber hygiene measures, business continuity arrangements and incident response plans to identify areas requiring enhancement. Aon have supported many of our clients in conducting a gap assessment against NIS2 security requirements (e.g. MFA coverage, logging and monitoring, patch management, network segmentation).

  1. Manage supply chain risk

Evaluating the resilience of critical suppliers and third-party providers as part of a broader cyber risk management framework. Some key mitigating factors include introducing minimum security requirements into contracts for managed service providers and cloud vendors (e.g. ISO 27001 certification, breach notification timeframes, logging standards).

  1. Prepare for incident reporting requirements

Reviewing incident management and reporting procedures to support compliance with evolving regulatory and stakeholder expectations. This might include updating the incident response playbook to include NIS2 notification timelines (e.g. initial notification within 24 hours) and responsible owners for regulatory reporting.

By Jim O Brien/CEO

CEO and expert in transport and Mobile tech. A fan 20 years, mobile consultant, Nokia Mobile expert, Former Nokia/Microsoft VIP,Multiple forum tech supporter with worldwide top ranking,Working in the background on mobile technology, Weekly radio show, Featured on the RTE consumer show, Cavan TV and on TRT WORLD. Award winning Technology reviewer and blogger. Security and logisitcs Professional.

Leave a Reply

Discover more from techbuzzireland.com

Subscribe now to keep reading and get access to the full archive.

Continue reading