The Cyber Ostrich and the CyFUN Reality Check
Discover how Ireland's CyFUN framework helps organisations improve cyber resilience, prioritise security risks and prepare for NIS2.

August 27, 2026
For years, many organisations have taken what you might call the "ostrich approach" to cybersecurity: Keep the business running. Focus on day-to-day priorities. Hope cyber threats, regulators and customer security questionnaires pass by unnoticed.
The problem is that cyber risk catches organisations before they realise it.
That is why Ireland's Cyber Fundamentals Framework (CyFUN) deserves attention. Introduced by the National Cyber Security Centre (NCSC) and aligned to recognised standards such as NIST, CyFUN gives Irish organisations a practical, scalable way to improve cyber resilience and support NIS2 readiness. Most importantly, it addresses a question many organisations are asking: Where do we start?
Death by Framework
For many Irish businesses, cybersecurity is no longer a technology problem. It is a navigation problem. Boards and leadership teams face an endless stream of guidance, regulations and acronyms: NIS2, ISO 27001, NIST, CIS Controls, DORA, GDPR, Cyber Essentials, supply chain security reviews, customer audits and insurer questionnaires. Every framework matters. Every adviser has recommendations. Every regulator has requirements.
The result is often confusion rather than clarity. Business leaders understand cybersecurity is important. What they struggle with is deciding what matters most for their organisation, what should happen first and where limited resources will have the greatest impact. With no obvious starting point, cyber risk can easily become something to revisit later.
The trouble is that cybercriminals rarely wait until later.
Why the Ostrich Approach No Longer Works
Historically, some organisations assumed they were too small, too local or too insignificant to attract attention from attackers.
That assumption no longer holds.
Recent research by eir business, supported by Microsoft and Dr Mauricio Perez-Alaniz of the Kemmy Business School, found that Irish SMEs lose more than 7.2 million working days every year due to cyber incidents. For individual businesses, that equates to almost three working weeks of lost productivity annually.
Modern attackers are opportunistic. They focus on weak passwords, unpatched systems, vulnerable suppliers and poorly managed environments. They care less about how large an organisation is and more about how easy it is to compromise.
The consequences extend far beyond recovering systems. Downtime, reputational damage, regulatory scrutiny, loss of customer confidence and disruption to operations can all leave a lasting impact. In an economy increasingly dependent on digital services, cyber resilience has become a business issue, not just an IT one.
Enter CyFUN
This is where CyFUN changes the conversation. Instead of asking organisations to navigate dozens of frameworks and hundreds of controls at once, it provides a structured path forward. The framework helps organisations understand their current maturity, identify gaps and prioritise improvements in a logical and achievable way.
Think of CyFUN as a cybersecurity satnav. It does not demand perfection from day one. Instead, it helps organisations build capability over time, working towards an assurance level that reflects their size, risk profile and operational importance, whether that is Basic, Important or Essential.
Its practicality is what makes it valuable. A small manufacturing company, a professional services firm and a critical national infrastructure provider face very different risks. They should not all be expected to implement the same controls at the same pace. CyFUN recognises that reality.
Start with the Fundamentals
One of the most common questions executives ask is simple: "What should we do first?"
The answer is usually less complicated than expected. Before considering advanced security tools or major transformation programmes, organisations should be able to answer a handful of fundamental questions:
- Do we know our most critical systems and data?
- Do we understand our cyber risks?
- Are our systems securely configured and regularly updated?
- Can we detect suspicious activity?
- Do we have a plan if a cyber incident occurs?
- Have we assigned accountability for cybersecurity at leadership level?
These are not technical questions. They are business resilience questions. They determine how prepared an organisation is when something inevitably goes wrong and whether leadership has a clear understanding of its cyber exposure. CyFUN provides a structured and measurable way to answer them.
A Business Opportunity, Not Just a Compliance Exercise
Cybersecurity discussions are often framed around compliance, regulation and risk reduction. While all of those matter, there is another perspective worth considering.
Trust is increasingly becoming a competitive advantage. Customers, partners, insurers and regulators want evidence that organisations can protect data and operate securely. A recognised cybersecurity framework helps demonstrate that capability, strengthens commercial confidence and supports growing supply chain expectations.
Viewed this way, CyFUN becomes more than a compliance tool. It becomes a practical framework for building resilience, credibility and organisational confidence.
Get Your Head out of the Sand
The Irish cybersecurity landscape will continue to evolve. New threats will emerge, regulations will mature and customer expectations will increase.
The organisations that succeed will not necessarily be those that spend the most on cybersecurity. They will be the ones that approach cyber risk in a structured, practical and consistent way.
Faced with a forest of frameworks, standards and regulations, it is easy to become overwhelmed. CyFUN offers something refreshingly simple: a place to start.
And for organisations still practising the “ostrich approach”, getting their head out the sand may be the most important cybersecurity decision they make this year.