Useful Reference Material
A curated library of 57 authoritative sources referenced across the Pragmatic Security article library — official guidance, legislation, frameworks, research, and tools.
Every link on this page has been cited in our articles. These are the primary sources behind the advice we give Irish businesses.
Irish Government & Regulatory Bodies
Official guidance, advisories, and regulatory resources from Irish government agencies relevant to cybersecurity and data protection.
NCSC Ireland — Official Website
The National Cyber Security Centre (NCSC) is Ireland's primary government agency for cybersecurity. The website provides threat advisories, incident reporting, SME guidance, and the CyFUN framework documentation. Essential reading for any Irish business.
Official GuidanceNCSC Ireland — SME Cyber Security Guidance (2025)
A practical, free guide from the NCSC specifically for Irish small and medium businesses. Covers the most common threats, basic controls, and how to get started with CyFUN. Recommended as the first document any Irish SME owner should read.
Official GuidanceNCSC Ireland — CyFUN Framework
The official CyFUN framework page, including the selection tool, implementation guidance, and documentation for all three maturity levels (Basic, Important, Essential). The primary path for Irish organisations to demonstrate NIS2 compliance.
Official GuidanceNCSC Ireland — CyFUN Frequently Asked Questions
Official answers to the most common questions about CyFUN — who needs it, how it maps to NIS2, how to use the selection tool, and what the three maturity levels require. Useful for businesses beginning their CyFUN journey.
Official GuidanceNCSC Ireland — NIS2 Directive Guidance
The NCSC's official NIS2 guidance page, covering scope, obligations, the transposition timeline, and how to prepare. Includes links to the draft legislation and the risk management measures guidance.
Official GuidanceNCSC Ireland — NIS2 Draft Risk Management Measures Guidance
Detailed guidance on the specific risk management measures required under NIS2 Article 21. Covers all ten security domains and provides practical implementation guidance for Irish organisations.
Official GuidanceNCSC Ireland — NIS2 Guide for Organisations
A concise guide explaining NIS2 obligations, the scope criteria, the security measures required, and the incident reporting obligations. Designed for senior management and directors.
Official GuidanceNCSC Ireland — Cyber Security Baseline Standards
Ireland's national baseline cybersecurity standards, covering the minimum security controls expected of Irish organisations. Predates CyFUN but provides useful context for the evolution of Irish cybersecurity policy.
Official GuidanceNCSC Ireland — Microsoft 365 Secure Configuration Framework
Practical configuration guidance for securing Microsoft 365 environments, covering authentication, email security, data loss prevention, and admin controls. Directly applicable to the majority of Irish SMEs using Microsoft 365.
Official GuidanceNCSC Ireland — Threat Landscape
Regular threat intelligence publications from the NCSC covering the current cyber threat landscape in Ireland. Includes sector-specific threat assessments and advisories on active campaigns targeting Irish organisations.
Official GuidanceNCSC Ireland — Small Business Cyber Security Advice
A practical, accessible resource specifically for small businesses, covering the most common threats and the basic controls that provide the greatest protection. Plain English, no technical background required.
Official GuidanceNCSC Ireland — QR Code Phishing (Quishing) Guidance
A quick guide to QR code phishing (quishing) — how it works, how to recognise it, and how to protect your business. Particularly relevant as QR code attacks have increased significantly in 2025–2026.
Official GuidanceData Protection Commission (DPC) — Official Website
Ireland's independent data protection supervisory authority. The website provides GDPR guidance, enforcement decisions, data breach notification procedures, and guidance on emerging issues including AI and generative AI.
Official GuidanceDPC — Data Breach Notification Guidance
Official guidance on when and how to notify the DPC of a personal data breach. Covers the 72-hour reporting obligation, the information required, and when affected individuals must also be notified.
Official GuidanceDPC — Guidance on Generative AI
The DPC's guidance on the GDPR implications of using generative AI tools. Covers data minimisation, lawful basis, data processing agreements, and the specific risks of using consumer AI tools for work involving personal data.
Official GuidanceCentral Bank of Ireland — Cyber Security and Resilience
The Central Bank's regulatory expectations for cybersecurity in the financial services sector. Covers DORA obligations, operational resilience requirements, and the Central Bank's supervisory approach to cyber risk.
Official GuidanceCentral Bank of Ireland — Digital Operational Resilience Act (DORA)
The Central Bank's guidance on DORA implementation for Irish financial entities. Covers the five pillars of DORA (ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing) and the supervisory timeline.
Official GuidanceAn Garda Síochána — Cyber Crime
Garda guidance on reporting cybercrime in Ireland, including fraud, BEC attacks, ransomware, and online scams. Includes the contact details for the Garda National Cyber Crime Bureau (GNCCB) and advice on preserving evidence.
Official GuidanceGov.ie — National Cyber Security Strategy
Ireland's national cybersecurity strategy, setting out the government's priorities for protecting Irish citizens and businesses from cyber threats. Provides context for the regulatory and policy environment Irish businesses operate in.
Official GuidanceEU Legislation & Regulation
Primary legislation and official guidance from EU institutions on cybersecurity, data protection, and digital regulation.
NIS2 Directive — Full Text (EUR-Lex)
The full text of the NIS2 Directive (Directive (EU) 2022/2555) on EUR-Lex. Essential reference for understanding the specific obligations, scope criteria, and enforcement provisions. Article 21 (security measures) and Article 23 (incident reporting) are the most relevant for most organisations.
LegislationGDPR — Full Text (EUR-Lex)
The full text of the General Data Protection Regulation (GDPR). The primary reference for data protection obligations in Ireland and across the EU. Article 32 (security of processing) and Articles 33–34 (breach notification) are most relevant for cybersecurity purposes.
LegislationEU AI Act — Full Text (EUR-Lex)
The full text of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). The world's first comprehensive AI regulation, classifying AI systems by risk level and imposing obligations proportionate to that risk. Relevant for businesses developing or deploying AI systems.
LegislationENISA — European Union Agency for Cybersecurity
ENISA is the EU's cybersecurity agency. Its website provides threat landscape reports, guidelines for NIS2 implementation, sector-specific security guidance, and resources for SMEs. The ENISA Threat Landscape report is published annually and is the authoritative source for EU-level threat intelligence.
Official GuidanceEuropean Commission — NIS2 Directive Overview
The European Commission's overview of the NIS2 Directive, including the policy rationale, key changes from NIS1, and implementation guidance. Useful for understanding the broader EU cybersecurity policy context.
Official GuidanceEuropean Commission — Cyber Resilience Act
The European Commission's overview of the Cyber Resilience Act, which introduces mandatory cybersecurity requirements for products with digital elements. Relevant for businesses that manufacture, import, or distribute connected products.
Official GuidanceNIS2 Directive — Article 21 Security Measures
A focused reference for NIS2 Article 21, which specifies the ten security domains that in-scope organisations must address. Useful for mapping your existing controls against the specific requirements.
Official GuidanceIAPP — NIS2 and Ireland's National Cyber Security Bill
An analysis by the International Association of Privacy Professionals of NIS2 transposition in Ireland and what management boards specifically need to know and do. Covers director liability, governance obligations, and the Irish legislative timeline.
News & AnalysisInternational Frameworks & Standards
Globally recognised cybersecurity frameworks and standards referenced throughout the Pragmatic Security content library.
NIST Cybersecurity Framework 2.0
The US National Institute of Standards and Technology's Cybersecurity Framework, version 2.0. The foundation on which CyFUN is built. Provides a common language for cybersecurity risk management across organisations of all sizes and sectors.
Official GuidanceNIST CSF 2.0 — Full Publication
The full NIST CSF 2.0 publication. Covers the six functions (Govern, Identify, Protect, Detect, Respond, Recover), the core categories and subcategories, and implementation guidance. Essential reference for organisations implementing CyFUN.
Official GuidanceUK NCSC — Cyber Essentials
The official UK government Cyber Essentials scheme, covering the five technical controls (firewalls, secure configuration, user access control, malware protection, patch management) and the certification process. Directly relevant to Irish businesses seeking Cyber Essentials certification.
Official GuidanceAustralian Cyber Security Centre — Essential Eight
The ACSC's Essential Eight framework — eight mitigation strategies to protect against the most common cyber attack techniques. Widely referenced in Irish and European security contexts for its practical, measurable approach to ransomware resilience.
Official GuidanceACSC — Essential Eight Maturity Model
Detailed guidance on the four maturity levels (0–3) of the Essential Eight framework. Explains what is required at each level for each of the eight strategies, enabling organisations to assess their current maturity and plan improvements.
Official GuidanceResearch & Industry Reports
Key research publications, threat intelligence reports, and industry studies referenced in Pragmatic Security articles.
IBM Cost of a Data Breach Report 2024
IBM's annual global study on the financial impact of data breaches, based on analysis of real-world incidents. The 2024 report found the global average cost of a data breach reached $4.88 million. Provides sector-specific data and analysis of the factors that increase or reduce breach costs.
ResearchCyber Ireland — SME Cyber Resilience: State of the Sector 2025
A 2025 report on the state of cybersecurity among Irish SMEs, covering current security posture, awareness levels, investment patterns, and the most common vulnerabilities. Essential reading for understanding the Irish SME cybersecurity landscape.
ResearchCyber Ireland — Annual Report 2023
Cyber Ireland's annual report covering the state of the Irish cybersecurity industry, the threat landscape, and the key challenges facing Irish organisations. Provides useful context for the scale and nature of cyber threats in Ireland.
ResearchHiscox Cyber Readiness Report — Ireland
Hiscox's annual cyber readiness report includes Ireland-specific data on cyber attack frequency, financial impact, and the security controls that most effectively reduce risk. Particularly useful for understanding the insurance and risk management perspective.
ResearchTravelers — Q2 2025 Cyber Threat Report
Travelers Insurance's quarterly cyber threat report covering the most active threat actors, attack techniques, and sectors targeted in Q2 2025. Useful for understanding current threat trends from an insurance perspective.
ResearchRTÉ — 65% Would Not Return to Retailer After Data Breach
RTÉ reporting on research showing that 65% of Irish consumers would not return to a retailer following a data breach. Provides important context for the reputational and commercial impact of cyber incidents on Irish businesses.
News & AnalysisSilicon Republic — Cybersecurity in Ireland
Silicon Republic is Ireland's leading technology news publication. Its cybersecurity coverage provides regular updates on Irish cyber incidents, regulatory developments, and the broader technology landscape relevant to Irish businesses.
News & AnalysisTech Central — Cyber Security in Late 2025
An analysis of the Irish cybersecurity landscape in late 2025, covering the key threats facing Irish SMEs and the regulatory pressures driving security investment. Provides useful context for the current environment.
News & AnalysisWilliam Fry — NIS2 Enforcement and Supervision
Legal analysis from William Fry solicitors on NIS2 enforcement mechanisms, supervisory powers, and the personal liability provisions for directors. Authoritative legal perspective on the enforcement landscape.
News & AnalysisIAPP — Navigating NIS2 and the EU Cyber Resilience Act
IAPP analysis of the relationship between NIS2 and the Cyber Resilience Act, covering how the two regulations interact and what organisations need to do to comply with both. Particularly relevant for businesses that both use and produce digital products.
News & AnalysisTechnical Reference & Tools
Technical documentation, tools, and resources for implementing specific security controls referenced in Pragmatic Security articles.
Cloudflare — DMARC, DKIM, and SPF Explained
A clear, comprehensive explanation of the three email authentication protocols — SPF, DKIM, and DMARC — how they work together, and how to implement them. Essential reading for any business looking to prevent email spoofing and BEC attacks.
Official GuidanceValimail — DMARC, DKIM, SPF Explained
An alternative explanation of email authentication protocols with practical implementation guidance. Useful as a second reference alongside the Cloudflare resource.
Official GuidanceMXToolbox — Email Security Testing
A free online tool for testing your email security configuration — checking SPF, DKIM, and DMARC records, testing blacklists, and diagnosing email delivery issues. Useful for verifying that your email authentication is correctly configured.
ToolMicrosoft Learn — Zero Trust Guidance for SMBs
Microsoft's practical zero trust implementation guidance for small and medium businesses, covering identity, devices, applications, and data. Directly applicable to businesses using Microsoft 365.
Official GuidanceMicrosoft Learn — Essential Eight Backups
Microsoft's guidance on implementing the Essential Eight backup strategy using Microsoft technologies. Covers backup configuration, testing, and the specific requirements for immutable backups.
Official GuidanceAcronis — Incremental vs Differential Backups
A clear explanation of the different backup types — full, incremental, and differential — with guidance on choosing the right approach for your business. Useful context for implementing the 3-2-1-1-0 backup strategy.
Official GuidanceSentinelOne — Best EDR Solutions for Small Business
An overview of endpoint detection and response (EDR) solutions suitable for small businesses, covering features, pricing, and deployment considerations. Useful for businesses evaluating EDR tools.
Official GuidancePalo Alto Networks — EDR vs Antivirus
A clear explanation of the difference between traditional antivirus and modern EDR, covering detection methods, response capabilities, and why EDR provides significantly better protection against modern threats.
Official GuidanceNIST — Getting Started with the Cybersecurity Framework
NIST's introductory resource for the five (now six) CSF functions, with explanations and examples for each. A useful starting point for organisations new to the framework.
Official GuidanceIrish Business & Sector Resources
Resources from Irish business organisations, sector bodies, and media relevant to cybersecurity for Irish SMEs.
Cyber Ireland — Publications
Cyber Ireland is the national cybersecurity cluster organisation for Ireland. Its publications page includes research reports, industry surveys, and policy submissions on Irish cybersecurity. A useful resource for understanding the Irish cybersecurity ecosystem.
ResearchCyber Ireland — Reducing Cyber Security Risks for Irish SMEs in 2025 and Beyond
Cyber Ireland's practical guidance for Irish SMEs on reducing cyber risk in 2025 and beyond. Covers the key threats, the most effective controls, and the resources available to Irish businesses.
Official GuidanceThinkBusiness — Irish SMEs and Cyber Threats
ThinkBusiness analysis of the cyber threats facing Irish SMEs, with a focus on email-based attacks. Provides useful Irish-specific context and statistics.
News & AnalysisCCPC — Consumer Protection and Cyber Scams
The Competition and Consumer Protection Commission (CCPC) provides guidance on consumer protection, including warnings about online scams and fraud targeting Irish consumers and businesses. Relevant for businesses handling consumer transactions.
Official GuidanceFit.ie — Cyber Threats Costing Irish Businesses
An analysis of the financial impact of cyber threats on Irish businesses and the cost-effective solutions that SMEs are adopting. Provides useful Irish-specific financial context.
News & AnalysisBusiness Post — AI Cyber Threat Levels
Business Post analysis of the rising AI-powered cyber threat landscape and the controls that can contain it. Provides Irish business media perspective on the AI security challenge.
News & AnalysisNeed Help Interpreting Any of These?
Official guidance and legislation can be dense. If you have read something here and are unsure what it means for your business, book a free 20-minute call. We will give you a plain-English answer.
Book a Free 20-Minute Call