Special Reports
A special report is content that is edited and produced by the special reports unit within The Irish Times Content Studio. It is supported by advertisers who may contribute to the report but do not have editorial control.

Strengthening digital trust

In an increasingly AI-driven world, organisations can protect identities, secure customer interactions and build confidence

When it comes to cybersecurity, regulators expect clear accountability, oversight and evidence of control effectiveness.
When it comes to cybersecurity, regulators expect clear accountability, oversight and evidence of control effectiveness.

The World Economic Forum Global Cybersecurity Outlook 2026 identifies cyber-enabled fraud as one of the most significant cyber risks facing organisations, while advances in artificial intelligence are making phishing, impersonation and other forms of online deception increasingly convincing. As organisations accelerate digital transformation, maintaining trust in digital services, communications and transactions is becoming a strategic business priority.

Digital trust means customers, staff and partners can rely on an organisation to protect their data, verify identities accurately, and interact securely, says Dani Michaux, EMA cyber leader, KPMG in Ireland. “It’s built through strong cybersecurity controls, ethical data practices and clear governance, and measured through hard metrics like breach frequency and authentication failures, alongside softer ones such as customer satisfaction.

“KPMG’s Global Tech Report found Irish leaders now rank cyberattacks as their leading AI-related risk, reinforcing why digital trust is increasingly tracked as a board-level priority rather than a purely technical one.”

However, digital trust, on its own, is flawed, counters David McNamara, founder, Commsec. “That is precisely why zero trust exists. Every person and every system needs to be identified and authenticated, every time, without exception. With remote and hybrid working now the norm, you need a cybersecurity strategy that brings identity, access, and location together as one picture.

CommSec founder David McNamara: 'Not everyone needs the same level of access.'
CommSec founder David McNamara: 'Not everyone needs the same level of access.'

“Not everyone needs the same level of access. An administrator, an HR user, a salesperson, and a chief executive all carry different risk profiles, and access has to be fit for purpose for each of them. In practice, Secure Access Service Edge, privileged access management, and strong access control are what make that workable across a hybrid environment.”

A new age of trust

Organisations need to treat digital trust as a business resilience issue, not just a cyber-control issue, says Keith Power, trust in AI leader, PwC Ireland. “AI-enabled fraud means people, processes and technology must work together. That starts with organisation-wide awareness, including realistic exercises for executives and boards. It also means stronger identity controls, phishing-resistant authentication and zero-trust principles.

“But organisations should assume incidents will occur, so response, recovery and crisis plans must be tested against critical services and clear board-level ownership.”

Multifactor authentication, biometric verification and behavioural analytics add layers of protection beyond passwords alone, while zero-trust architectures continuously verify users rather than assuming trust within a network, explains Michaux. “There is a further shift: rather than framing AI purely around efficiency, organisations are increasingly using it defensively, for threat detection, anomaly monitoring and stress-testing decisions before issues arise.”

Dani Michaux, EMA cyber leader, KPMG in Ireland: 'Businesses can demonstrate digital trust through independent certifications.'
Dani Michaux, EMA cyber leader, KPMG in Ireland: 'Businesses can demonstrate digital trust through independent certifications.'

Confidence improves when organisations make the responsible choice the easy choice, says Power. “Consumers should be told, in plain language, what data is collected, why it is needed, how it is used and when it is shared. Privacy choices should be simple, not hidden behind lengthy terms and conditions.

“Organisations should also minimise the data they collect, secure it properly and use recognised assurance where appropriate. The goal is transparency by design: clear enough to build confidence, but not so complex that it creates friction.”

Governing the ungovernable

Maintaining customer trust in an age of AI is all about governance, says McNamara. “There is no substitute for it. The board needs to understand where AI works, why it works there, and what risk comes attached to that use case. Policy has to be agreed first, then operational usage worked through with stakeholders, not the other way around.

“Transparency is not a marketing statement, it is something that gets tested against compliance frameworks such as ISO 27001, NIS2, and DORA.”

Digital trust is increasingly a genuine differentiator, particularly as consumers become more selective about who they share data with, says Michaux. “Businesses can demonstrate digital trust through independent certifications, transparent reporting on security practices, and jargon-free communication about how data and AI are managed.

“Engaging proactively with regulators on this basis signals real maturity, reflected over time in customer loyalty and business performance.”

Customers experience trust through reliable services, secure interactions and clear communication when issues arise, agrees Power. “Partners need assurance that controls are independently tested and third-party risks are managed. Regulators expect clear accountability, oversight and evidence of control effectiveness.

“The organisations that benefit will be those that can demonstrate trust consistently, not simply claim it when challenged.”

Edel Corrigan

Edel Corrigan is a contributor to The Irish Times