CyFun, AI and Government: Why Cybersecurity Governance Is Entering a New Era
Governments are entering a new phase of digital transformation.
Cloud platforms are expanding.
Digital public services are becoming more connected.
Data is moving across agencies.
And now, AI is rapidly becoming part of public-sector operations.
The cybersecurity challenge is no longer simply about protecting traditional IT infrastructure.
Government organizations now need to consider:
- AI systems
- Data governance
- Third-party technology
- Cloud services
- Critical infrastructure
- Operational technology
- Citizen data
- Cross-agency digital services
This is creating a new governance challenge.
How can public-sector organizations adopt new technology without losing visibility and assurance?
CyFun is becoming increasingly relevant to this conversation.
In Ireland, the National Cyber Security Centre has positioned CyFun as a recognized, structured and risk-based approach to helping entities organize and evidence cybersecurity controls, including for public administration entities within the NIS2 environment.
More recently, Irish public-sector cybersecurity guidance has explicitly connected secure AI deployment resources with CyFun controls, allowing AI cybersecurity work to be evidenced against the same cybersecurity control environment organizations are already using.
This points toward an important future trend:
AI governance and cybersecurity compliance cannot operate as completely separate programs.
Government Is Moving From Digital Transformation to Digital Assurance
For years, government technology strategies focused on digital transformation.
The priority was to:
- Digitize services.
- Improve citizen experiences.
- Move to the cloud.
- Increase automation.
Today, a second challenge has emerged.
How do governments assure these technologies are continuously?
A system can be digitally advanced and still introduce:
- Security risks
- Data governance issues
- Access control gaps
- Third-party dependencies
- AI-specific vulnerabilities
This is why cybersecurity governance is becoming a central part of digital transformation.
AI Is Changing the Government Cybersecurity Equation
AI introduces opportunities for public services.
But it also introduces new questions.
For example:
- Where is AI being used?
- What data is being processed?
- Who owns the system?
- What third parties are involved?
- How is the AI system secured?
- How are risks assessed?
- What evidence demonstrates governance?
The Irish NCSC's Secure AI resources specifically focus on helping public-sector organizations assess, evidence, and track cybersecurity and assurance work for AI deployments, while aligning those activities with CyFun controls.
This is a significant development.
It suggests that AI security is increasingly becoming part of the broader cybersecurity assurance environment rather than an isolated innovation project.
Why Governance Is the Missing Layer
Government cybersecurity teams already manage:
- Security technologies
- Policies
- Risk assessments
- Incident response
- Audits
But AI and digital transformation can create fragmented ownership.
An AI system may involve:
- A business department
- An IT team
- A cloud provider
- A software vendor
- A data owner
- A cybersecurity team
- A legal or privacy team
Without governance, accountability becomes unclear.
CyFun 2025 introduced Governance Measures designed to support stronger cybersecurity oversight and align cybersecurity with organizational objectives.
For government organizations, this creates an opportunity to bring cybersecurity discussions closer to executive and management decision-making.
From "Is It Secure?" to "Can We Govern It?"
This is the new question.
Traditional cybersecurity often asks:
Is the system secure?
Modern government cybersecurity also needs to ask:
Can we govern the system throughout its lifecycle?
That includes:
Before Deployment
Risk assessment and control design.
During Deployment
Configuration and access management.
During Operation
Monitoring and evidence collection.
When Technology Changes
Reassessment and governance review.
During an Incident
Clear response and accountability.
CyFun as a Common Control Language
One of the biggest challenges in government organizations is fragmentation.
Different departments may use different approaches to:
- Risk
- Security
- Technology governance
- Audit
- AI
A structured framework can create a common language.
CyFun can help connect cybersecurity activities across:
- Governance
- Asset management
- Protection
- Detection
- Response
- Recovery
Ireland's NIS2 guidance describes CyFun as a structured framework for organizing and evidencing cybersecurity measures and notes its connection with the NIST CSF model.
The benefit is not simply framework compliance.
The benefit is organizational consistency.
The Public Sector Trend: Evidence Must Keep Up With Innovation
Government organizations are under pressure to innovate.
But innovation creates evidence challenges.
When a new system is introduced, organizations may need to demonstrate:
- Risk assessment
- Security controls
- Governance decisions
- Access management
- Testing
- Monitoring
The faster technology is introduced, the harder manual documentation becomes.
This is where automation and continuous assurance become important.
Rather than collecting evidence after deployment, organizations can work toward collecting and organizing relevant evidence throughout the technology lifecycle.
A Modern CyFun Model for Government
Government organizations can think about cybersecurity assurance across five connected areas.
1. Governance
Define accountability for cybersecurity and technology risk.
2. Visibility
Maintain awareness of systems, controls, risks and evidence.
3. Evidence
Capture relevant assurance information throughout the year.
4. Monitoring
Identify important control gaps and changes.
5. Remediation
Track issues through to resolution.
Why This Matters Now
Ireland's government cybersecurity strategy for 2026 includes increased investment in cybersecurity capacity, a new cybersecurity strategy, support for secure AI use in the public sector and updated national cyber resilience capabilities.
At the same time, government guidance is increasingly connecting leadership responsibilities, NIS2 obligations, AI security and CyFun as part of a more integrated cybersecurity approach.
This reflects a larger global trend.
Government cybersecurity is becoming:
More governed. More connected. More continuous.
How Quantarra Supports Government Cyber Assurance
Quantarra can help government and public-sector organizations centralize cybersecurity and compliance operations.
The platform supports a connected approach to managing:
Controls
Centralize control requirements and ownership.
Evidence
Organize evidence from relevant operational environments.
Risks
Maintain visibility into cybersecurity and compliance risks.
Frameworks
Map controls across applicable cybersecurity and regulatory requirements.
Workflows
Assign and track security and remediation activities.
Executive Visibility
Provide stakeholders with clearer views of assurance and compliance posture.
This helps organizations move toward a model where cybersecurity evidence and governance do not need to be rebuilt from scratch for every new audit, framework, or technology initiative.
Conclusion
The next era of government cybersecurity will not be defined only by stronger security technology.
It will be defined by stronger assurance.
As governments adopt AI, cloud and increasingly connected digital services, they need to maintain confidence throughout the lifecycle of those technologies.
CyFun provides a structured foundation.
But the future lies in connecting that framework with:
- Governance
- Continuous evidence
- Technology visibility
- Risk management
- Automated workflows
- Ongoing assurance
The objective is no longer simply to become compliant.
It is to build a government cybersecurity program capable of keeping pace with digital transformation.
From periodic assessments to continuous assurance that is where public-sector cybersecurity is heading.