Trinity College Dublin - The University of Dublin

10/07/2026 | Press release | Distributed by Public on 10/07/2026 07:28

New Trinity cybersecurity supply chain report highlights need for clearer guidance as EU rules shift

New Trinity cybersecurity supply chain report highlights need for clearer guidance as EU rules shift

Posted on: 07 October 2026

The new report, published following a roundtable coordinated by Trinity, also spotlights the need for stronger collaboration and practical support as Ireland hosts EU Cyber Week.

As Ireland hosts Cyber Week during its Presidency of the Council of the European Union, a new report informed by a Trinity College Dublin roundtable has highlighted the growing complexity of cybersecurity supply chains and the practical challenges facing organisations as they prepare for changing European regulation.

Read the Cybersecurity Regulations for M(S)SPs in the Supply Chain here.

Managed service providers (MSPs) and managed security service providers (MSSPs) play an increasingly important role in the secure delivery of their customers' services. They work with suppliers, end customers and critical organisations across sectors, often operating within complex supply chains where responsibility, control and liability are not always straightforward.

The report sets out the challenges that organisations face as they work through NIS2, the Cyber Resilience Act, the AI Act and wider EU cybersecurity regulation. It points to the need for more practical guidance, clearer roles and continued dialogue between regulators, suppliers, service providers and customers, while considering other parties working in the supply chain, for example fourth, fifth agents etc.

Convened at Trinity College Dublin through the Centre for Digital Security and Societal Resilience and the School of Law, in partnership with the Research Ireland ADAPT Centre, the roundtable brought together representatives from ICT suppliers, MSPs, MSSPs, advisers, supervisors, and other experts to discuss how the cybersecurity regulatory framework is understood and implemented in practice.

Participants included representatives from Arctic Wolf, Cisco, Eir Business, Fortinet, Innovate, Mason Hayes & Curran, Microsoft, Mulcahy Ward, the National Cyber Security Centre and Trinity College Dublin among others. The report was authored by Dr Pauline Meyer, Professor Maria Grazia Porcedda and Tara Kerins Aylmer.

According to Trinity's School of Law Dr Pauline Meyer, co-author of the report, a recurring theme throughout the roundtable was that cybersecurity supply chains do not always operate like a simple chain. Multiple participants described them as more of a matrix or a complex ecosystem, involving multiple actors, hidden dependencies and complex contractual relationships.

In practice, not every actor in the chain is visible to every other actor, which is of importance when unseen agents' work impacts critical services of end customers. Furthermore, responsibilities are not clearly divided considering power dynamics, and legal liabilities are not always clear as entities may simultaneously operate in multiple roles under the applicable regulations.

The report also highlights the compliance challenges facing both regulators and regulated organisations. Multiple participants called for better harmonisation of regulations, including definitions and compliance thresholds. They also expressed their wish to avoid box-ticking regulations and their hope for the concretisation of clearer guidance and compliance tools such as common templates, self-assessment, ongoing auditing and certification.

Artificial intelligence was also featured in the discussion. Participants recognised the risks that AI can create for cybersecurity, but also discussed the potential for AI to support vulnerability management, compliance, regulatory supervision and faster patching. The report stresses that human oversight and appropriate assessment and evaluation of processes remains essential.

Despite the complexity of the issues discussed, the report also points to opportunity. Participants saw scope for cybersecurity and compliance to become a competitive advantage, particularly where organisations can demonstrate strong security practices, clear governance and the ability to collaborate across the supply chain.

Finally, the report notes that successful implementation of cybersecurity regulation will depend not only on legal compliance, but on trust, cooperation and a shared understanding of responsibility. Participants also emphasised the need to move away from a blame culture, noting that if one organisation in the supply chain is insufficiently secure and compliant, the entire supply chain can suffer.

As Ireland hosts Cyber Week during its Presidency of the Council of the European Union, the report lands in the middle of a live European policy debate on cybersecurity, resilience, AI and technological sovereignty.

The EU is seeking to strengthen and simplify its cybersecurity framework, including through proposed changes to the Cybersecurity Act, targeted amendments to NIS2 and measures to reinforce ENISA's role.

Against that backdrop, this report provides a practical, industry-informed contribution to the conversation, showing why cybersecurity supply chains must be understood not only as a technical issue, but as a matter of business continuity, trust and the secure provision of critical services.

Trinity College Dublin - The University of Dublin published this content on October 07, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 07, 2026 at 13:29 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]