Cybersecurity Standards: Which One Is Right for Our Sector?

ISO/IEC 27001, NIS2, NCSC Cyber Security Baseline Standards, CyFun, NIST CSF 2.0: how many of these could you confidently say, off the top of your head, are certifications, regulations, or reference frameworks? In our experience working with institutions across Ireland's education and research sector, these terms often get lumped together in the same conversation, as if they were equivalent options within the same category. The natural question that follows is: ‘which one is right for our sector?’

This talk takes that question as its starting point and offers a more structured look at the topic. We’ll explore how these different standards, regulations, and frameworks actually relate to one another, where genuine overlaps exist, and how institutions in the sector have been weighing their priorities in this landscape. We’ll also touch on a shift gaining momentum behind the scenes: insurers and partners are increasingly asking institutions to demonstrate that controls work in practice, not just present certificates.

By the end of the session, attendees will have a clearer sense of how to map their own institution’s starting point, along with a more useful question to bring back to their teams. Not just ‘which standard should we choose’, but ‘what’s the right next step for us, given where we are today’.”

Daniella Vendramini
Asiera