
Two‑thirds of Irish businesses reported being hit by a cyber‑attack in the last twelve months, according to a survey that examined the impact on operations and finances.
Survey reveals widespread incidents and rising costs
The study, conducted by insurance broker Gallagher together with the Centre for Economics and Business Research, sampled 250 firms across Ireland. It found that 66 % of the organisations experienced at least one breach, and more than one‑third said they were targeted more than three times during the same period.
Among the companies that suffered an attack, 30 % incurred legal expenses, while 29 % reported lost revenue. Regulatory fines affected 22 % of the respondents, and 32 % were unable to serve customers while systems were down.
Michael Cunningham, Head of Financial Lines at Gallagher, said the data “reflects a significant escalation in cyber threats facing Irish firms.” He warned that the financial fallout can extend beyond the immediate cost of restoring systems, adding that “legal costs that arise from a cyber‑attack can put a huge financial strain on businesses, as can reputational damage.”
Related: Papal letter defends human dignity
Confidence in detection contrasted with legal concerns
Despite the high incidence, the research showed strong confidence among firms in their ability to manage breaches. A striking 95 % believed they could detect and contain a cyber breach, even if an attacker remained hidden for an extended period, and 55 % described themselves as “very confident.”
At the same time, the survey highlighted growing anxiety over potential litigation. Seven out of ten businesses expect that a serious cyber‑attack could trigger legal action from shareholders or investors, and a similar share think such litigation is very likely. Moreover, 84 % acknowledge that company directors could face personal liability after a significant breach.
“Shareholder litigation costs are emerging as one of the costliest consequences of cyber‑attacks for businesses,” Cunningham said, urging firms to prepare for increasingly complex legal challenges.
While the data points to a surge in attacks, the broader trend mirrors a global pattern where digital threats are becoming more sophisticated. Companies that fail to adapt may find their risk exposure growing faster than their defensive measures, a reality that highlights the need for both technical and governance improvements.
Related: Union warns civil service pensions could collapse
Insurance uptake and remaining gaps
The study found that 72 % of Irish firms now hold standalone cyber‑insurance policies. The most common coverages include business interruption costs (56 %), third‑party legal costs (50 %), data recovery and forensic investigations (46 %), and ransomware payments (42 %).
Nevertheless, Cunningham cautioned that insurance alone does not address every aspect of a breach. “While it’s encouraging to see businesses investing in cyber insurance, directors need to understand this does not cover every single aspect of a cyber‑attack,” he said. He recommended that firms also focus on employee training, system monitoring, and access controls to boost resilience.
Overall, the findings suggest that while many Irish companies feel equipped to detect intrusions, the financial and legal repercussions of attacks remain a serious concern that could influence future investment in cybersecurity measures.
Cyber risk is rising.
Leave a Reply