BH Consulting, the Dublin-based cybersecurity and data protection consultancy, has introduced BH Haven, an ongoing service giving Irish small and medium-sized enterprises access to its specialist consultants. The service matters to the sector because it bundles governance, technical assurance and AI oversight for firms that cannot afford dedicated security, privacy and compliance teams.

BH Haven is available in four tiers, namely Foundation, Standard, Professional and Scale, and covers cyber risk assessments, technical testing, incident response, data protection support, AI governance, third-party risk management and executive reporting. Consultants work alongside a proprietary AI tool that handles analysis, evidence review and regulatory mapping, with accountability remaining with the people.

The timing reflects a resilience gap among Irish SMEs identified in research from Munster Technological University and Ireland's National Cyber Security Centre. Customers, insurers and regulators are simultaneously raising expectations under GDPR, NIS2, the EU AI Act and the Cyber Resilience Act.

Brian Honan, CEO of BH Consulting, said: "SMEs don't need less rigorous cybersecurity and governance but they do need them delivered in a way that is proportionate to their risks, resources, and business." He added: "Cybersecurity, GDPR, AI governance, and cyber resilience are often treated as separate problems, but businesses don't experience risk that way."

Professional obligations in the client contract govern any delivery error, and Honan has stated that using AI internally does not shift that responsibility onto the software. He contrasted this with large organisations, which typically employ a CISO, a DPO and dedicated risk and compliance staff.

BH Consulting will target Ireland and the UK first before moving into the Nordic countries and other EU markets, and expects the service and wider demand to support up to 50 additional roles over three years. The rollout is timed to coincide with European Cybersecurity Awareness Month in October.

The structural driver is regulatory convergence, with overlapping privacy, security and AI obligations pushing SMEs towards bundled advisory services rather than separate specialist engagements.

For the sector, this points to AI-assisted delivery reshaping how consultancies serve smaller clients, with repetitive analysis moving to software while professional accountability stays with consultants.

Source: irishtechnews.ie / helpnetsecurity.com / techcentral.ie