Vodafone Ireland has appointed Owen Pendlebury as Head of Cyber Security, a hire that arrives as the NIS2 Directive makes telecom network security a binding regulatory obligation rather than a reputational consideration.
Vodafone Ireland is the Irish subsidiary of Vodafone Group Plc (LSE: VOD), a FTSE 100 global telecoms operator with FY2025 group revenue of €37.4 billion. In Ireland, Vodafone is the number one mobile network and second-largest broadband provider, serving 2.4 million customers with six in ten Irish businesses as customers, and has invested more than €20 billion in the Irish market since 2001.
Ireland's service revenue grew in FY2025 due to a higher broadband customer base and improved customer loyalty, partially offset by lower mobile termination rates; Irish-specific revenue and EBITDA are not separately disclosed. Vodafone recently announced €360 million in additional network and digital infrastructure investment up to 2030.
Pendlebury joins from Bank of Ireland, where he served as Head of Cyber Resilience, leading the bank's cyber defence and resilience programme. He will report into Vodafone's EU Head of Cyber Security and join a Vodafone Group network of more than 900 cyber security experts globally.
The structural driver is Ireland's exposure to cyber risk as a concentration point for European data infrastructure. Ireland hosts the European data centres and regional headquarters of Google, Meta, Amazon, Microsoft and Apple, making it a higher-priority target for state-sponsored and criminal threat actors than its population size would suggest.
The NIS2 Directive, which Ireland transposed into national law in October 2024, imposes binding cyber security obligations on critical infrastructure operators, a category that explicitly includes telecommunications networks. Vodafone Ireland, as the country's largest mobile network with deep enterprise penetration, is both a regulated entity under NIS2 and a critical infrastructure node for hundreds of business customers whose own NIS2 compliance depends partly on the security of the networks they operate over.
Pendlebury's Bank of Ireland background is operationally relevant beyond his cyber credentials. The financial services sector operates at the highest cyber maturity level of any Irish industry, and the programme management skills required to protect a systemically important bank map directly onto the regulatory and threat environment a major telecommunications operator now faces under NIS2.
Source: dublinchamber.ie / vodafone.ie / investors.vodafone.com / ncsc.gov.ie



.png)

