Cyber Security Review Grant
An independent, NCSC-aligned review of your cybersecurity, with 80% of the cost covered by Enterprise Ireland.
If your company is an Enterprise Ireland client, you can have your cybersecurity independently reviewed by an expert for a net cost of €600. The Cyber Security Review Grant, run by Enterprise Ireland in partnership with the National Cyber Security Centre, covers 80% of a fixed €3,000 project cost. Funding is limited, allocated on a first come first served basis, and each company can avail of one review.
Stage 1 · Cyber Security Review Grant
Stage 2 · Cyber Security Improvement Grant
Stage 1: the Cyber Security Review Grant
Stage 1 is the review itself. Enterprise Ireland funds 80% of the fixed €3,000 cost, leaving you €600 to pay, with funding allocated on a first come first served basis and one review per company. We handle the process end to end: a scoping call at no charge to confirm eligibility and fit, the review delivered over a small number of days with minimal disruption, a written report aligned with NCSC best practice with a walkthrough session where you can question every finding, and support with the Enterprise Ireland application and claim paperwork at both ends.
Stage 2: the Cyber Security Improvement Grant
Stage 2 is where the findings get fixed. The NCSC Cyber Security Improvement Grant provides up to €60,000, again at 80% of project cost, towards implementing the priority recommendations from your Stage 1 report. We help you turn the report into a fundable improvement project: defining the scope, gathering supplier costs, preparing the application and then overseeing the implementation. Because we do not sell products or licences, our role in Stage 2 sits entirely on your side of the table, specifying what is needed, evaluating suppliers and holding them to the standard the funding requires.
How the two stages connect
A Stage 1 report is the qualifying step for Stage 2, which means it has to be written with Stage 2 in mind. We structure findings as prioritised, costable actions rather than general observations, so when you apply for the Improvement Grant the scope is already defined and defensible. A review treated as a tick-box exercise often produces a report that cannot support a funding application, and the thinking has to be done twice.
What the review covers
A review is only as good as the person conducting it, so we start with how your business actually runs rather than a generic checklist. We examine identity and access across Microsoft 365 and Entra, the configuration of your cloud platforms and core business applications, the security arrangements you have with your IT provider or managed service partner, backup and recovery, remote access, and how your people would respond to a phishing or ransomware incident. Where your environment spans multiple regions or hosting arrangements, the review reflects that reality.
What you receive
You get a written report aligned with NCSC best practice, a prioritised remediation roadmap that distinguishes what is urgent from what can wait, and findings written so that a managing director, a board or a cyber insurer can understand them without translation.
Thinking about ISO 27001?
For companies whose customers are beginning to ask about certification, the review doubles as a realistic first step towards ISO 27001. We will tell you frankly what certification would involve for a business of your size, what it would cost and whether you need it yet.