Cybersecurity Reference Material — NCSC, ENISA, NIST

Curated links to NCSC Ireland, ENISA, NIST, and other authoritative cybersecurity sources for Irish business owners, IT teams, and compliance officers.

A curated library of 57 authoritative sources referenced across the Pragmatic Security article library — official guidance, legislation, frameworks, research, and tools.

Every link on this page has been cited in our articles. These are the primary sources behind the advice we give Irish businesses.

Source Categories

Irish Government & Regulatory Bodies (19 sources)

Official guidance, advisories, and regulatory resources from Irish government agencies. Sources include NCSC Ireland (its website, SME cyber security guidance, the CyFUN framework and FAQ, NIS2 Directive guidance, draft risk management measures guidance, the NIS2 guide for organisations, the Cyber Security Baseline Standards, the Microsoft 365 Secure Configuration Framework, threat landscape publications, small business advice, and quishing guidance); the Data Protection Commission (with its data breach notification and generative AI guidance); the Central Bank of Ireland (cyber security and DORA); An Garda Síochána's cyber crime guidance; and the National Cyber Security Strategy on Gov.ie.

EU Legislation & Regulation (8 sources)

Primary legislation and official guidance from EU institutions. Sources include the full texts of the NIS2 Directive, the GDPR, and the EU AI Act on EUR-Lex; ENISA, the EU's cybersecurity agency; the European Commission's NIS2 and Cyber Resilience Act overviews; a focused NIS2 Article 21 reference; and IAPP analysis of NIS2 and Ireland's National Cyber Security Bill.

International Frameworks & Standards (5 sources)

Globally recognised cybersecurity frameworks and standards. Sources include the NIST Cybersecurity Framework 2.0 and its full publication, the UK NCSC's Cyber Essentials scheme, and the Australian Cyber Security Centre's Essential Eight framework and maturity model.

Research & Industry Reports (10 sources)

Key research publications, threat intelligence reports, and industry studies. Sources include the IBM Cost of a Data Breach Report 2024; Cyber Ireland's SME Cyber Resilience: State of the Sector 2025 and Annual Report 2023; the Hiscox Cyber Readiness Report for Ireland; the Travelers Q2 2025 Cyber Threat Report; RTÉ reporting on consumer trust after data breaches; Silicon Republic and Tech Central coverage; William Fry legal analysis of NIS2 enforcement; and IAPP analysis of NIS2 and the Cyber Resilience Act.

Technical Reference & Tools (9 sources)

Technical documentation and tools for implementing specific security controls. Sources include Cloudflare and Valimail on SPF, DKIM, and DMARC; the MXToolbox email security testing tool; Microsoft Learn on Zero Trust for SMBs and Essential Eight backups; Acronis on backup types; SentinelOne and Palo Alto Networks on EDR; and NIST's getting-started guide to the CSF functions.

Irish Business & Sector Resources (6 sources)

Resources from Irish business organisations, sector bodies, and media. Sources include Cyber Ireland's publications and SME risk-reduction guidance, ThinkBusiness threat analysis, the Competition and Consumer Protection Commission (CCPC), Fit.ie analysis of the cost of cyber threats, and Business Post coverage of AI cyber threat levels.

Need Help Interpreting Any of These?

Official guidance and legislation can be dense. If you have read something here and are unsure what it means for your business, book a free 20-minute call. We will give you a plain-English answer.