CYBERSECURITY AUDIT FOR IRISH ORGANISATIONS
Most breaches aren’t sophisticated. That’s the problem.
In 2025 the Data Protection Commission received 6,521 valid breach notifications from Irish organisations. Around half came down to correspondence sent to the wrong recipient — not zero-day exploits, not state-sponsored attackers. Everyday process failures, unclear responsibilities, and systems nobody had looked at closely in a while.
That’s what an audit is for. Not to tell you that cyber crime exists, but to tell you specifically where your organisation is exposed, how serious each gap is, and what to do about it in what order.
Matrix Internet has been building and securing systems for Irish organisations since 2000 — including credit unions, public bodies, and EU institutions. We test, we report, and we fix.
Source: DPC Annual Report 2025

Our Cyber Security Services
- Vulnerability assessment
- Penetration testing
- Staff phishing simulation
- Staff awareness training
- GDPR gap analysis
- Cloud security audit
- Source code review
- Incident response planning
Security Metrics
Let’s talk about your risk.
Book a free 30-minute consultation with our cyber security team.
Email: sales@matrixinternet.ie
Address: Merchants Court, 24–26 Merchant’s Quay, Dublin 8
Why now
Ireland hasn't transposed NIS2 yet, and in July 2026 the European Commission referred Ireland to the Court of Justice of the EU over the delay. That doesn't mean you're unaffected — obligations are arriving through contracts, in-scope EU customers are pushing incident reporting and evidence requirements down onto Irish suppliers now.
GDPR requires "appropriate technical and organisational measures." An audit gives you documented evidence that you assessed your risk, which is what the DPC looks for when an incident or complaint lands.
Financial entities face DORA. Credit unions face Central Bank outsourcing and operational resilience expectations. Public bodies face procurement security requirements. We've worked inside all three.
Cyber insurance renewals and supplier security questionnaires may ask for evidence you don't have yet: pen test results, patch cadence, incident response plans, access reviews. We help you produce it and fix what the questionnaire exposes.
Prevent, detect, contain — meet your cybersecurity team
Trust us for fewer breaches, tighter controls, and business that stays online.
Tomas Herink
Head of Development
Brian Power
Head of Cybersecurity & Principal Technical Architect
Bernard Hanna
Senior Developer
Colm Reidy
Cybersecurity Support Developer
What we do
- Penetration testing — web apps, APIs, mobile, external network perimeter
- Vulnerability assessment & recurring scanning
- Cloud & infrastructure security audit (AWS, Azure, DigitalOcean)
- Source code review
- Server hardening & secure configuration review
- Phishing simulation
- Staff security awareness training
- Board & management briefings on governance responsibilities
- GDPR gap analysis & remediation planning
- ISO 27001-aligned policy suites & ISMS documentation
- Supplier security questionnaire support
- NIS2 readiness assessment
- Incident response plan & playbook development
- Cybersecurity tabletop exercise, scored findings + written report
- Rapid response: malware removal, backdoor patching, clean restoration, forensic review
How we test?
Methodology
Testing follows the OWASP Web Security Testing Guide and is assessed against OWASP. Findings are scored using CVSS v4.0, so severity is comparable across engagements and defensible to an auditor, insurer or customer. Automated tooling is used for coverage; every finding is manually verified before it reaches your report. We do not send you raw scanner output.
Scope and authorisation
Every engagement begins with written rules of engagement: what is in scope, what is explicitly out, testing windows, escalation contacts, and a signed authorisation to test. Where you host with a third party, we handle the provider notification.
Your data
Test data and evidence are held encrypted, in the EU, and destroyed on an agreed schedule after report acceptance. We will sign your NDA or provide ours.
What you get?
The report
- An executive summary your board can read without translation
- Every finding with evidence, business impact, CVSS score, and specific remediation steps
- A prioritised remediation plan — what to fix this week, this quarter, and next year
- A free retest of remediated findings within 90 Days, and a clean-status letter you can send to customers or insurers
Process
- Initial risk assessment A structured conversation with your team to understand your setup, your data obligations, and where the obvious gaps are. No tools, no scans. Hours, not days.
- Scoping and authorisation We agree exactly what will be tested, when, and by whom, and put it in writing.
- Vulnerability assessment Automated analysis of your systems, networks and hosting, with results triaged and verified rather than dumped.
- Penetration testing Manual testing that simulates a real attacker against your applications, APIs, email infrastructure and perimeter.
- Human risk testing Controlled phishing simulation and staff awareness training built around what the results actually show.
- Reporting and walkthrough Written report plus a live session with your team to work through findings and agree the remediation plan.
- Remediation and retest We can fix it, or work alongside your existing provider. Either way, we retest and confirm closure.
Timeline: an initial assessment can be delivered within 2 weeks. A full audit including penetration testing, staff training and GDPR gap analysis typically runs 5 to 6 weeks from kick-off to final report, depending on scope.
FAQs
Cyber security is not the same as IT support. Most support contracts cover helpdesk, hardware and software - not penetration testing, phishing simulation, or GDPR gap analysis. Ask your current provider what their contract specifically covers for security, and whether they'd be assessing their own work.
GDPR requires organisations to implement appropriate technical and organisational measures to protect personal data. An audit gives you documented evidence that you've assessed your risks, which is what the Data Protection Commission looks for if a complaint or incident is reported.
Ireland hasn't transposed NIS2 yet, but that doesn't delay the obligation reaching you. In-scope customers elsewhere in the EU are already writing incident notification timelines, control requirements and audit rights into supplier contracts. What you typically need to evidence: a documented risk assessment, an incident response plan that has been tested, patch and vulnerability management, access control, and supplier due diligence of your own. We assess you against those requirements and produce the evidence pack.
A scanner finds known signatures. It won't chain two low-severity issues into a serious one, won't find broken access control between two user roles, and won't tell you which findings actually matter for your business. We use scanning for coverage and people for judgement.
No. Testing is scoped and scheduled with you, with agreed windows and an escalation contact throughout. Denial-of-service testing is only performed if you specifically request it, against a non-production environment.
We offer rapid response and recovery — malware removal, backdoor patching, restoration from clean backups, and forensic review to establish what was accessed. We then harden the infrastructure to prevent recurrence and advise on your notification obligations, including the 72-hour DPC deadline where personal data is involved.
An initial assessment can be completed within a week. A full audit including penetration test, staff training and GDPR gap analysis typically takes [[three to four weeks]] from kick-off to final report.
Pricing depends on scope, the number of applications, user roles and environments in play. After the initial consultation you get a fixed-price proposal, so there are no day-rate surprises.
Yes. After your initial consultation we produce a short proposal with scope, price and timeline. Most clients find this makes internal approval significantly easier.
Very common, and we do this regularly. We complete the questionnaire with you, flag the answers that would fail scrutiny, and give you a remediation plan to close those gaps before the next one arrives.
Annually as a baseline, and after any significant change, a new application, a migration, a new integration, or a change of hosting provider. Regulated clients and those in enterprise supply chains typically test twice a year.
Case Studies

IE Domain
Rebuilding the IE Domain Registry website
- Cloud based Software Development
- Consultancy
- Cybersecurity
- GDPR Compliance
- Hosting
- UX/UI Design
- Website Development

Dundalk credit union
A marketing strategy that’s delivering results every month
- Cybersecurity
- Paid Digital Marketing
- SEO Services
- Website Development

European Environment Agency
One shared vision for a complex communications landscape
- Consultancy
- Cybersecurity
- Email Marketing Services
- Technical Support
- UX/UI Design
- Website Development