The State could face financial penalties of €2.8 million, alongside daily fines, as a result of the delay in transposing new European Union cybersecurity rules into law.The European Commission has in recent weeks referred the Republic, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to transpose the EU’s NIS2 Cybersecurity Directive into law.The commission had set a legal deadline of October 17th, 2024, for countries to adopt the legislation.Professional services firm Aon has warned that almost two years on, the State remains non-compliant. Using the commission’s methodology for calculating financial sanctions, the company estimated that the State had an exposure of about €2.8 million, with daily penalties accruing on top for as long as the delay continues. The legislation introduces various cybersecurity risk management measures, incident reporting requirements, and accountability for management bodies.It will also expand the number of organisations subject to regulation in the Republic.The Government has blamed the complexity of the legislation for the delay.Aon called on the Government to prioritise the National Cyber Security Bill, which transposes the directive, when the Oireachtas returns in September “and to progress it through its remaining stages as quickly as possible. How many new homes does Ireland really need? Listen | 42:23“With Ireland currently holding the presidency of the council of the EU, there is an opportunity to complete transposition and give organisations certainty on the framework that will underpin cybersecurity governance across critical sectors,” it said.“NIS2 represents one of the most significant changes to cybersecurity regulation in recent years and will have implications for thousands of organisations across Ireland, either directly or through their supply chains,” said Leann Moroney, associate director for cyber risk management at Aon Ireland.“While the legislation will provide important clarity on how the new framework will operate in practice, organisations should not view transposition as the starting point for action,” said Moroney.“Cyber threats are not waiting for legislation, and businesses shouldn’t either. The direction of travel is already clear, and cyber risk needs to be treated as a board-level priority now,” she said.“This becomes even more important as organisations adopt AI [artificial intelligence] and other emerging technologies,” she said.“Strong governance, effective risk management and robust cybersecurity controls will enable organisations to embrace innovation with confidence while strengthening resilience against cyber threats,” she said.As cyber resilience becomes an increasingly strategic business issue, Aon has set out a five-step action plan to help organisations prepare for the new regulatory environment, which includes measures to strengthen their governance structures and assess their cyber resilience capabilities.The State previously faced a €4.5 million fine due to a three-year delay in transposing the European Electronic Communications Code.