ADAPT researchers contribute to national conversation on cyber resilience

30 September 2026

Researchers from ADAPT at Trinity College Dublin and DCU contributed to a wide-ranging programme at the Business Post Cyber Security Summit in Croke Park (29 September), bringing expertise across regulation, supply-chain risk, election security, digital sovereignty, critical infrastructure and international cooperation.

The Summit brought together leaders from industry, government and research to look at how organisations can build resilience in an environment shaped by AI, geopolitical risk, regulation and growing dependence on digital infrastructure. 

Regulation, resilience and responsibility

Associate Professor Maria Grazia Porcedda joined a panel examining regulation, risk and competitive advantage, including NIS2, DORA, GDPR, the Cyber Resilience Act and the AI Act.

A recurring theme was the need for organisations to move away from treating compliance as a separate exercise and instead build governance, resilience and legal requirements into digital transformation from the start.

The discussion also explored the challenge facing organisations trying to navigate a fast-moving regulatory environment while continuing to innovate and deploy new technologies. Rather than adding governance after a system is already in place, the panel considered how legal, technical and operational expertise can be brought into design and decision-making at an earlier stage.

Looking beyond the immediate supplier

Dr Pauline Meyer took part in a panel on supply-chain and third-party cyber risk.

The discussion highlighted how organisations increasingly need to understand not only their direct suppliers, but the deeper dependencies beneath them.  Fourth- and fifth-party providers, open-source components, cloud infrastructure and AI services can all create points of vulnerability that may not be immediately visible.

For organisations, the issue is not simply whether a supplier meets a particular standard. It is also about understanding what happens if that supplier fails.

The panel discussed the importance of knowing which services are critical, having visibility over the technologies and software an organisation depends on, and planning in advance for disruption. That includes knowing how an organisation would continue to operate if a major cloud or AI provider suffered an outage or cyber incident.

Digital sovereignty also featured in the discussion, with the focus less on withdrawing from global technology providers and more on retaining sufficient control over data, access, continuity and the ability to switch or recover critical services.

Cybersecurity, elections and sovereignty

The relationship between cybersecurity, democracy and national resilience was explored in a panel featuring Professor Hitesh Tewari, Associate Professor Eileen Culloty of DCU and David Hickton, Founding Director of the University of Pittsburgh Institute for Cyber Law, Policy and Security.

The discussion looked at the growing challenge of protecting elections and democratic institutions in an environment shaped by cyber threats, foreign influence operations, disinformation and emerging technologies such as AI.

Eileen Culloty, an ADAPT academic at DCU whose research focuses on misinformation, disinformation and digital media, brought the information environment into the discussion, highlighting the importance of understanding how misleading and manipulative content can affect public trust and democratic processes.

Hitesh Tewari focused on the technical side of election security and digital sovereignty. He introduced zkBallot, which explores privacy-preserving approaches to digital voting, and InvizCrypt, research addressing sovereign control of sensitive data. The discussion also touched on questions around jurisdiction and access to data held by global cloud providers, including the implications of the U.S. CLOUD Act.

David Hickton drew on his experience as former U.S. Attorney for the Western District of Pennsylvania and his work on major cybercrime and national-security cases, including investigations involving state-linked actors.

Together, the discussion showed that protecting democratic systems is not simply a matter of securing voting technology. It also requires attention to the integrity of information, an informed and educated public, the protection of sensitive data and the wider resilience of the digital systems on which democratic processes increasingly depend.

Sea-Scan: protecting critical infrastructure

The afternoon programme moved from digital systems to physical infrastructure with a presentation from Professor Marco Ruffini and Commander Brian Mathews of the Irish Naval Service on Sea-Scan.

Sea-Scan uses existing subsea fibre-optic cables together with AI to detect and monitor vessel activity. The project is exploring how communications infrastructure already lying on the seabed can also act as a large-scale sensing network, strengthening maritime awareness and helping protect critical national infrastructure.

Sea-Scan brings together researchers in optical communications, acoustics, engineering, signal processing, AI and machine learning with Defence Forces operational expertise. The project won the Research Ireland Defence Organisation Innovation Challenge, securing €1.2 million to advance the technology towards wider deployment.  The Research Ireland Defence Organisation Innovation Challenge is supported by the Department of Defence and the Defence Forces.  

The discussion highlighted the importance of collaboration between research and operational partners in responding to emerging threats to subsea infrastructure, particularly as Ireland’s dependence on international connectivity continues to grow.

Across the day, the common theme was that cyber resilience is no longer solely a technical issue. It spans law, governance, supply chains, democratic systems, data, infrastructure and organisational decision-making.