LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
ai

In this new SME cybersecurity service, the AI assists and the consultants decide

BH Consulting, an Irish cybersecurity and data protection consultancy, has launched BH Haven, a new ongoing service designed to provide small and medium-sized enterprises (SMEs) with access to specialist consultants. This service is supported by a proprietary AI tool that assists with analysis, evidence review, regulatory mapping, and reporting. Initially targeting Ireland and the UK, BH…

ZeroDay News ·

Source: Help Net Security

BH Consulting, an Irish cybersecurity and data protection consultancy, has launched BH Haven, a new ongoing service designed to provide small and medium-sized enterprises (SMEs) with access to specialist consultants. This service is supported by a proprietary AI tool that assists with analysis, evidence review, regulatory mapping, and reporting. Initially targeting Ireland and the UK, BH Consulting plans to expand the service to Nordic countries and other EU markets.

The service aims to address a critical gap in cyber resilience among Irish SMEs, as identified by the Munster Technological University and Ireland's National Cyber Security Centre (NCSC) in their "SME Cyber Resilience State of the Sector 2025" study. This study highlighted issues related to preparedness, resources, and access to expertise within the SME sector. BH Consulting CEO Brian Honan noted that individuals within SMEs are often tasked with cybersecurity, privacy, or compliance responsibilities in addition to their primary roles, frequently lacking the necessary time or specialized knowledge. He also pointed out that relying on multiple external suppliers for different areas is a common but often fragmented approach.

BH Haven is structured into four tiers: Foundation, Standard, Professional, and Scale. The services offered range from risk assessments and technical testing to incident response planning, data protection, AI governance, third-party risk management, and executive reporting. Honan emphasized that SMEs require robust cybersecurity and governance, but these must be delivered in a manner proportionate to their specific risks, resources, and business operations.

In a typical engagement, a consultant first familiarizes themselves with the client's business, systems, regulatory environment, customer base, and risk profile. They then gather relevant evidence, such as policies, technical specifications, and previous assessments. The AI tools subsequently sort and analyze this material, identify potential gaps, map evidence to applicable requirements, and generate an initial draft of findings. Honan explained that this process significantly reduces the administrative burden on consultants.

However, the AI's role is strictly assistive. It does not make definitive judgments regarding the acceptability of an organization's risk, the effectiveness of controls, or recommendations for addressing material risks. A consultant reviews the AI-assisted analysis, challenges findings, prioritizes actions, and ultimately approves all deliverables. The consultant remains actively involved throughout the entire process, ensuring human oversight and judgment.

Regarding liability, Honan stated that no consulting firm can credibly guarantee that a client will never experience a breach or always remain compliant. Professional obligations and liability terms are governed by the client's contract, and the internal use of AI does not shift this responsibility from the consulting firm. Clients remain responsible for managing their own environments and implementing agreed-upon recommendations. The scope of each assessment is clearly defined in the contract and covers the evidence available at the time of the assessment.

BH Haven focuses on governance and assurance, helping management understand risks and independently verifying the effectiveness of controls. It does not manage client firewalls or endpoints, nor does it operate a security operations center (SOC). Honan views managed service providers (MSPs) and managed security service providers (MSSPs) as potential partners whose work BH Haven can independently assess. BH Consulting anticipates creating up to 50 specialist roles over the next three years to support BH Haven and its other services.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

ai

Apple tightens macOS disk access as AI agents become more powerful

Apple is implementing stricter controls for Full Disk Access in macOS, citing an increased risk to user privacy from increasingly capable and autonomous AI agents. The company indicated that future macOS versions will require users to take explicit steps to grant applications this permission. A specific rollout date and the precise mechanics of these new controls have not yet been detailed.

vulnerability

AI slop submissions force Google to freeze its open-source bug bounty

Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) for new product vulnerability submissions, effective October 1, 2026. The company cited a substantial increase in automated, AI-generated reports, most of which were invalid, as the reason for the pause. This influx of low-quality submissions overwhelmed the engineers and open-source maintainers…

nation-state

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

David Robinson, a veteran safety expert at OpenAI, has resigned from the company, citing concerns about its culture and rapid AI development model. Robinson, who was instrumental in authoring safety reports accompanying major product launches during his three-and-a-half-year tenure, stated that he believes the company's current trajectory is unacceptable.

patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

breach

Frontline Education Breach Impacts K-12 School District Staff

Frontline Education, a prominent software provider for K-12 school districts in the United States, has confirmed a data breach that exposed the personal information of school staff. The incident, which was discovered on August 14, 2026, stemmed from a vulnerability in a third-party software product utilized by the company.