Ramping up risk management at Forvis Mazars

Alex Burnham, head of IT audit and cyber security, was featured in a recent article in Business Plus by Sorcha Corcoran.

At present, Forvis Mazars is spending a lot of time working with clients in preparation for the transposition of the EU’s Network and Information Systems Directive 2 (NIS2) into Irish law.

“NIS2 is a key area of focus for a large portion of our client base, as, when enacted, it will elevate cyber security from an IT issue to a board-level governance responsibility,” Alex Burnham, head of IT audit and cyber security at Forvis Mazars, says.

“To support our clients with this, we’re leveraging our team’s previous experience of conducting NIS1 reviews of operators of essential services in Ireland on behalf of the National Cyber Security Centre (NCSC).

“We also have a specialist team assisting our clients with the development and implementation of a robust cyber-security framework in line with National Cyber Security Centre [NCSC] guidance.”

Under NIS2, and according to NCSC’s guidance, management bodies are now explicitly accountable for the oversight of cyber-security risk management and compliance.

However, one of the key findings from Forvis Mazars’ 2026 C-Suite Barometer report is that only 54 per cent of Irish business leaders say their company’s data is completely protected, down 13 points from 2025.

Over the past 12 months, the professional services firm has seen an increase in cyber incidents that resulted in “significant operational disruptions”, Burnham notes.

“Such incidents have captured our clients’ attention and prompted an increase in requests related to governance, risk and accountability, cyber resilience, supply-chain risk management and asset management,” Burnham says.

“The increasing frequency of attacks on organisations’ supply chains and third-party service providers has highlighted the critical importance of supply-chain risk management.

“While organisations may not consider themselves a direct target, we’ve seen numerous instances where critical third-party providers have been targeted due to their geographic location, strategic importance or the nature of the clients they serve, resulting in significant downstream impacts for organisations in Ireland.”

Most organisations have technical tools that provide an inventory of assets operating within their environment, but effective asset management extends beyond maintaining a technical asset register, Burnham explains.

“As the saying goes, ‘you can’t protect what you don’t know exists.’ Effective asset management requires organisations to identify and prioritise critical business processes and understand the dependencies that support them.

“This includes mapping critical processes to technical assets, data sources, thirdparty service providers and other supporting resources.

“By establishing this visibility, organisations can ensure that appropriate controls are implemented, risks are effectively managed and assets are protected in line with their business criticality and operational importance.”

Over the past few years — and particularly with the rapid advancement of AI — traditional vulnerability-management processes are no longer sufficient to address the evolving threat landscape, Burnham continues.

Among the factors driving this is an “expanding attack surface” as a result of increased adoption of cloud services, remote- and hybrid-working models and the growing use of internet-ofthings devices.

There has also been an increase in the speed with which attackers weaponise vulnerabilities to exploit and attack organisations’ systems and infrastructure.

“These factors have elevated vulnerability management from a technical function to a key governance and compliance requirement for organisations,” Burnham says.

“Cyber-security standards such as the Cyber Fundamentals Framework — which has been adopted by the NCSC — now have clearly detailed best practices in this area that require enhanced risk assessment and management of vulnerabilities across the lifecycle.”

While AI has significantly enhanced cyber-security capabilities, it has also introduced new risks and challenges that organisations must address.

Forvis Mazars has continued to invest in its AI governance and security capabilities through targeted upskilling, strategic recruitment and the development of robust processes and controls to support the responsible and secure use of AI.

“AI has changed the cyber-security landscape by providing attackers with increasingly sophisticated tools and techniques.

“Attackers can now scan larger attack areas at an accelerated rate, identify potential vulnerabilities more efficiently, and increase the speed at which zero-day vulnerabilities can be discovered and exploited,” Burnham says.

“In response to the evolving cyber and geopolitical threat landscape, organisations must strengthen their focus on operational resilience to ensure the continuity and timely recovery of critical services during and after a cyber attack.”

Read the original article on the Business Plus website.

Contact