Ireland's NIS2 Case and Its Externally Visible Security Vendors - CipherCue
Directory<br>EU Vendors<br>Docs<br>Pricing<br>Blog<br>Log in
Book a demo<br>Sign up free
analysis<br>Ireland Is Being Taken to Court Over NIS2. 88% of the Security Vendor Detections We Found Were American.
12 August 2026 · 10 min read<br>· By Chris McCabe
Ireland took over the rotating Presidency of the Council of the EU on 1 July 2026. A week later, on 8 July 2026, the European Commission referred Ireland to the Court of Justice of the EU, along with Spain, France, and the Netherlands, for failing to notify full transposition of the NIS2 cybersecurity directive. The deadline had been 17 October 2024. Most of the EU's 27 member states missed it too, 23 of 27 hadn't transposed on time, but by mid-2026, after a formal notice in November 2024 and a reasoned opinion in May 2025, most had closed the gap. These four hadn't, and are the ones the Commission has now escalated to court, seeking financial penalties. Ireland now chairs the same cybersecurity and digital sovereignty agenda its own government is late implementing.
Against that backdrop, we externally fingerprinted the security and access-control vendors visible on organisations in our Irish dataset, to see whose technology actually shows up at the perimeter.
88.2% of the 119 security and auth-category vendor detections in our Irish dataset trace to a US-parented company
We recorded 119 security and authentication vendor detections across 81 of the 310 organisations in our sample, one detection per vendor per organisation: 88.2% trace to a US-headquartered ultimate parent, 8.4% to a single Danish company, 2.5% to a company now owned by a French parent, and 0.8% to one owned by a Dutch private equity firm. These are detection counts, not a share of the 310 organisations: most of the sample had no security or auth-category vendor visible to our fingerprinting at all.
Snyk, the vendor at the centre of the AIB controversy that prompted this question, doesn't appear anywhere in this data, and can't: it's a developer-tooling product used in CI/CD pipelines, not something visible on a public website, VPN portal, or DNS record. We have no direct observation of Snyk deployment at AIB or anywhere else in this sample. What we can measure is external vendor concentration, a narrower question than which vendor a company has actually contracted with.
What we measured
For each of the 310 organisations, we ran DNS-based subdomain discovery, then fingerprinted the primary domain and any discovered subdomains classified as login, SSO, admin, dashboard, or VPN/remote-access surfaces. Matches come from HTTP response headers, page titles, response body markers, and MX records, checked against a fixed set of vendor signatures. This identifies a vendor only if we hold a signature for it and the surface is internet-reachable; a firewall management console sitting behind a client VPN, for example, is invisible to this method regardless of whether it exists.
Vendor sovereignty, by current parent company
We classify each vendor by its current ultimate parent company's headquarters, not by where it was founded or where its own headquarters happens to sit if a parent company owns it. A vendor founded in one country and later acquired by a company headquartered in another is classified under the acquirer. Founding country is mentioned separately where it adds real context.
105
United States
88.2%
10
Denmark
8.4%
France
2.5%
Netherlands
0.8%
119 security/auth-category vendor detections across 81 organisations in our Irish dataset, by ultimate parent-company headquarters (one detection per vendor per organisation)
The Denmark figure is Cybot, trading as Cookiebot, a genuinely Danish-headquartered independent company. Its product is cookie-consent management, not a firewall, IAM platform, or VPN gateway; it sits in this chart because our fingerprint rule set files privacy tooling under the same category as security tooling, alongside OneTrust (also consent management, US-owned) and TrustArc (also consent management, now owned by Main Capital Partners of the Netherlands). Consent-management tooling accounts for 37 of the 119 detections here, a real EU data point, but not what most readers picture when they think "security infrastructure."
The France figure is entirely Imperva, a web application firewall vendor founded in Israel in 2002, listed on the NYSE in 2011, bought by Thoma Bravo (US private equity) in 2019, and bought again by Thales, the French defence and technology group, in 2023. Its current parent is French; its founding country is Israeli.
A second category-label issue: 9 of the 119 detections are Akamai, tagged "security" in our rule set on the strength of the X-Akamai-Transformed response header. That header only confirms traffic passed through Akamai's CDN edge; our rule set has no signature that distinguishes a WAF-enabled Akamai deployment from a plain CDN one, so these 9...