BH Consulting, an Irish cybersecurity and data protection consultancy, has launched BH Haven, a new ongoing service designed to provide small and medium-sized enterprises (SMEs) with access to specialist consultants. This service is supported by a proprietary AI tool that assists with analysis, evidence review, regulatory mapping, and reporting. Initially targeting Ireland and the UK, BH Consulting plans to expand the service to Nordic countries and other EU markets.
The service aims to address a critical gap in cyber resilience among Irish SMEs, as identified by the Munster Technological University and Ireland's National Cyber Security Centre (NCSC) in their "SME Cyber Resilience State of the Sector 2025" study. This study highlighted issues related to preparedness, resources, and access to expertise within the SME sector. BH Consulting CEO Brian Honan noted that individuals within SMEs are often tasked with cybersecurity, privacy, or compliance responsibilities in addition to their primary roles, frequently lacking the necessary time or specialized knowledge. He also pointed out that relying on multiple external suppliers for different areas is a common but often fragmented approach.
BH Haven is structured into four tiers: Foundation, Standard, Professional, and Scale. The services offered range from risk assessments and technical testing to incident response planning, data protection, AI governance, third-party risk management, and executive reporting. Honan emphasized that SMEs require robust cybersecurity and governance, but these must be delivered in a manner proportionate to their specific risks, resources, and business operations.
In a typical engagement, a consultant first familiarizes themselves with the client's business, systems, regulatory environment, customer base, and risk profile. They then gather relevant evidence, such as policies, technical specifications, and previous assessments. The AI tools subsequently sort and analyze this material, identify potential gaps, map evidence to applicable requirements, and generate an initial draft of findings. Honan explained that this process significantly reduces the administrative burden on consultants.
However, the AI's role is strictly assistive. It does not make definitive judgments regarding the acceptability of an organization's risk, the effectiveness of controls, or recommendations for addressing material risks. A consultant reviews the AI-assisted analysis, challenges findings, prioritizes actions, and ultimately approves all deliverables. The consultant remains actively involved throughout the entire process, ensuring human oversight and judgment.
Regarding liability, Honan stated that no consulting firm can credibly guarantee that a client will never experience a breach or always remain compliant. Professional obligations and liability terms are governed by the client's contract, and the internal use of AI does not shift this responsibility from the consulting firm. Clients remain responsible for managing their own environments and implementing agreed-upon recommendations. The scope of each assessment is clearly defined in the contract and covers the evidence available at the time of the assessment.
BH Haven focuses on governance and assurance, helping management understand risks and independently verifying the effectiveness of controls. It does not manage client firewalls or endpoints, nor does it operate a security operations center (SOC). Honan views managed service providers (MSPs) and managed security service providers (MSSPs) as potential partners whose work BH Haven can independently assess. BH Consulting anticipates creating up to 50 specialist roles over the next three years to support BH Haven and its other services.






