What we do

Cybersecurity banner

CYBERSECURITY AUDIT FOR IRISH ORGANISATIONS

Stop a breach before it stops your business

Book a free consultation

 

Most breaches aren’t sophisticated. That’s the problem.

In 2025 the Data Protection Commission received 6,521 valid breach notifications from Irish organisations. Around half came down to correspondence sent to the wrong recipient — not zero-day exploits, not state-sponsored attackers. Everyday process failures, unclear responsibilities, and systems nobody had looked at closely in a while.

That’s what an audit is for. Not to tell you that cyber crime exists, but to tell you specifically where your organisation is exposed, how serious each gap is, and what to do about it in what order.

Matrix Internet has been building and securing systems for Irish organisations since 2000 — including credit unions, public bodies, and EU institutions. We test, we report, and we fix.

Source: DPC Annual Report 2025

Get in touch

Cyber Ireland Badge 26-27 (1)


Our Cyber Security Services

  • Vulnerability assessment
  • Penetration testing
  • Staff phishing simulation
  • Staff awareness training
  • GDPR gap analysis
  • Cloud security audit
  • Source code review
  • Incident response planning

Security Metrics

0
+
security vulnerabilities patched across client platforms
0
%
uptime maintained thanks to proactive monitoring and threat prevention
counters

Why now – Compliance

The questions are coming from your customers, not just the regulator

NIS2 and your supply chain Ireland has not yet transposed the NIS2 Directive, the National Cyber Security Bill remains unenacted, and in July 2026 the European Commission referred Ireland to the Court of Justice of the EU over the delay. That does not mean Irish businesses are unaffected. NIS2 obligations are arriving through contracts: customers and partners in other Member States who are already in scope are pushing incident reporting, control requirements and evidence obligations down onto their Irish suppliers now. If you sell to a large EU customer, you are likely already being assessed.

GDPR GDPR requires “appropriate technical and organisational measures.” An audit gives you documented evidence that you assessed your risk, which is what the DPC looks for when an incident or complaint lands.

Sector-specific obligations Financial entities face DORA. Credit unions face Central Bank outsourcing and operational resilience expectations. Public bodies face procurement security requirements. We’ve worked inside all three.

Insurers and supplier reviews Cyber insurance renewals and enterprise supplier security questionnaires may ask for evidence you may not have: penetration test results, patch cadence, incident response plans, access reviews. We help you produce it and fix what the questionnaire exposes.

What we do

Testing and assessment

  • Penetration testing — web applications, APIs, mobile apps, external network perimeter
  • Vulnerability assessment and recurring scanning
  • Cloud and infrastructure security audit (AWS, Azure, DigitalOcean)
  • Source code review
  • Server hardening and secure configuration review
To the point

Incident readiness and response

  • Incident response plan and playbook development
  • Cyber security tabletop exercise, facilitated scenario testing for your leadership and technical teams, with scored findings and a written post-exercise report
  • Rapid response: malware removal, backdoor patching, clean restoration, forensic review, and hardening to prevent recurrence
Code

People

  • Phishing simulation
  • Staff security awareness training
  • Board and management briefings on governance responsibilities
Checked

Governance and compliance

  • GDPR gap analysis and remediation planning
  • ISO 27001-aligned policy suites and ISMS documentation
  • Supplier security questionnaire support (CAIQ, CCM, insurer and enterprise questionnaires)
  • NIS2 readiness assessment
Website wireframe

How we test? 

Methodology

Testing follows the OWASP Web Security Testing Guide and is assessed against OWASP. Findings are scored using CVSS v4.0, so severity is comparable across engagements and defensible to an auditor, insurer or customer. Automated tooling is used for coverage; every finding is manually verified before it reaches your report. We do not send you raw scanner output.

Scope and authorisation

Every engagement begins with written rules of engagement: what is in scope, what is explicitly out, testing windows, escalation contacts, and a signed authorisation to test. Where you host with a third party, we handle the provider notification.

Your data

Test data and evidence are held encrypted, in the EU, and destroyed on an agreed schedule after report acceptance. We will sign your NDA or provide ours.

 

What you get?

The report

  • An executive summary your board can read without translation
  • Every finding with evidence, business impact, CVSS score, and specific remediation steps
  • A prioritised remediation plan — what to fix this week, this quarter, and next year
  • A free retest of remediated findings within 90 Days, and a clean-status letter you can send to customers or insurers

Download a redacted sample report

See the format and depth of what you’d actually get, personal and client details removed. A lower-commitment option for visitors who aren’t ready to book a call yet.

    Process

    1. Initial risk assessment A structured conversation with your team to understand your setup, your data obligations, and where the obvious gaps are. No tools, no scans. Hours, not days.
    2. Scoping and authorisation We agree exactly what will be tested, when, and by whom, and put it in writing.
    3. Vulnerability assessment Automated analysis of your systems, networks and hosting, with results triaged and verified rather than dumped.
    4. Penetration testing Manual testing that simulates a real attacker against your applications, APIs, email infrastructure and perimeter.
    5. Human risk testing Controlled phishing simulation and staff awareness training built around what the results actually show.
    6. Reporting and walkthrough Written report plus a live session with your team to work through findings and agree the remediation plan.
    7. Remediation and retest We can fix it, or work alongside your existing provider. Either way, we retest and confirm closure.

    Timeline: an initial assessment can be delivered within 2 weeks. A full audit including penetration testing, staff training and GDPR gap analysis typically runs 5 to 6 weeks from kick-off to final report, depending on scope.

    Why Matrix?

    • Irish-owned and Dublin-based since 2000 — your data doesn’t leave the EU, and your point of contact doesn’t change
    • In-house testing team. We don’t subcontract your engagement to a third party
    • Cyber Ireland member
    • Trusted by regulated and public sector organisations: IE Domain Registry, the European Environment Agency, Anyone else (pull from case studies)
    • We build as well as test. Findings come with remediation from people who can actually implement them

    Our own posture We hold ourselves to what we recommend. Matrix Internet operates an ISO 27001-aligned policy framework, we’ll happily complete your supplier security questionnaire, we’re on the other side of that process regularly.

    Prevent, detect, contain — meet your cybersecurity team

    Trust us for fewer breaches, tighter controls, and business that stays online.

    Tomas Herink

    Tomas Herink

    Head of Development

    Brian Power

    Brian Power

    Head of Cybersecurity & Principal Technical Architect

    Bernard Hanna

    Bernard Hanna

    Senior Developer

    Colm Reidy

    Colm Reidy

    Cybersecurity Support Developer

    FAQs

    Cyber security is not the same as IT support. Most support contracts cover helpdesk, hardware and software - not penetration testing, phishing simulation, or GDPR gap analysis. Ask your current provider what their contract specifically covers for security, and whether they'd be assessing their own work.

    GDPR requires organisations to implement appropriate technical and organisational measures to protect personal data. An audit gives you documented evidence that you've assessed your risks, which is what the Data Protection Commission looks for if a complaint or incident is reported.

    Ireland hasn't transposed NIS2 yet, but that doesn't delay the obligation reaching you. In-scope customers elsewhere in the EU are already writing incident notification timelines, control requirements and audit rights into supplier contracts. What you typically need to evidence: a documented risk assessment, an incident response plan that has been tested, patch and vulnerability management, access control, and supplier due diligence of your own. We assess you against those requirements and produce the evidence pack.

    Yes. We combine manual testing with automated tooling, following the OWASP Web Security Testing Guide and scoring findings with CVSS v4.0. Coverage includes web applications, APIs, mobile apps, network perimeter and email infrastructure. Every finding is manually verified, and a retest is included.

    A scanner finds known signatures. It won't chain two low-severity issues into a serious one, won't find broken access control between two user roles, and won't tell you which findings actually matter for your business. We use scanning for coverage and people for judgement.

    No. Testing is scoped and scheduled with you, with agreed windows and an escalation contact throughout. Denial-of-service testing is only performed if you specifically request it, against a non-production environment.

    We offer rapid response and recovery — malware removal, backdoor patching, restoration from clean backups, and forensic review to establish what was accessed. We then harden the infrastructure to prevent recurrence and advise on your notification obligations, including the 72-hour DPC deadline where personal data is involved.

    An initial assessment can be completed within a week. A full audit including penetration test, staff training and GDPR gap analysis typically takes [[three to four weeks]] from kick-off to final report.

    Pricing depends on scope, the number of applications, user roles and environments in play. After the initial consultation you get a fixed-price proposal, so there are no day-rate surprises.

    Yes. After your initial consultation we produce a short proposal with scope, price and timeline. Most clients find this makes internal approval significantly easier.

    Very common, and we do this regularly. We complete the questionnaire with you, flag the answers that would fail scrutiny, and give you a remediation plan to close those gaps before the next one arrives.

    Annually as a baseline, and after any significant change, a new application, a migration, a new integration, or a change of hosting provider. Regulated clients and those in enterprise supply chains typically test twice a year.

    Digital Marketing Team Workshop

    Case Studies

    IE Domain

    IE Domain

    Rebuilding the IE Domain Registry website

    • Cloud based Software Development
    • Consultancy
    • Cybersecurity
    • GDPR Compliance
    • Hosting
    • UX/UI Design
    • Website Development
    See more
    Dundalk credit union

    Dundalk credit union

    A marketing strategy that’s delivering results every month

    • Cybersecurity
    • Paid Digital Marketing
    • SEO Services
    • Website Development
    See more
    eea-hero

    European Environment Agency

    One shared vision for a complex communications landscape

    • Consultancy
    • Cybersecurity
    • Email Marketing Services
    • Technical Support
    • UX/UI Design
    • Website Development
    See more
    See all case studiesArrow