BH Consulting has launched BH Haven, a subscription-style service aimed at Irish and UK small and medium-sized enterprises that must juggle GDPR, NIS2, the EU AI Act, and the Cyber Resilience Act. The offering stems from research by Munster Technological University and Ireland's NCSC showing that many SMEs lack the time, resources, and expertise to manage cyber resilience on their own. Rather than shrinking its enterprise consulting model, BH Consulting built four tiers—Foundation, Standard, Professional, and Scale—that pair consultants with a proprietary AI tool for evidence review, regulatory mapping, and drafting.
In practice, a consultant first maps the client's business and risk profile, then feeds policies and technical details into the AI. The tool flags potential gaps and produces a first draft, but the consultant reviews the analysis, challenges findings, and signs off before anything reaches the client. CEO Brian Honan stressed that AI never decides whether a risk is acceptable or a control is effective; the human stays engaged throughout. Liability for missed gaps follows the same path as any professional assessment—covered by the contract's terms, not shifted to the software.
BH Haven deliberately avoids managing firewalls, endpoints, or a security operations center. Its role is governance and assurance: helping management understand risks and independently verifying that controls work. Honan sees managed service providers as potential partners whose work BH Haven can assess, giving SMEs an adviser on their side of the table. The company expects to create up to 50 specialist roles over the next three years across this service and its broader portfolio.