Security1 publisher3 min readPublished
BH Consulting's BH Haven lets AI draft SME assessments that consultants must approve
BH Consulting launched BH Haven, a four-tier SME service in which a proprietary AI tool drafts findings and consultants approve them. CEO Brian Honan said using AI internally does not move the firm's contractual responsibility for a missed gap onto the software.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- BH Haven opens in Ireland and the UK first, with the Nordic countries and other EU markets to follow.
- Target clients answer to GDPR, NIS2, the EU AI Act and the Cyber Resilience Act, plus customers, partners and cyber insurers with rising expectations.
- A 2025 study by Munster Technological University and Ireland's NCSC found a critical cyber-resilience gap among Irish SMEs, tied to preparedness, resources and access to expertise.
- The tiers cover risk assessments, technical testing, incident response planning, data protection, AI governance, third-party risk and executive reporting.
- BH Consulting expects to add up to 50 specialist roles over three years across BH Haven and its other services.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure An SME that buys only BH Haven still has nobody watching its systems for attacks; detection has to come from an MSP, an MSSP or its own people.
- decision SMEs already paying an MSP for bundled compliance must now choose between accepting that provider's own reporting and paying a second firm to assess its controls.
- constraint A breach through a gap outside the agreed scope, or through evidence the client never handed over, falls outside what the assessment covered.
An engagement starts with a consultant learning the client's business, systems, regulatory environment, customers and risk profile, then gathering policies, technical details and earlier assessments [9]. The proprietary tool sorts and analyses that material, flags possible gaps, matches evidence to the relevant requirements and lays out a first draft of findings [9]. Honan said that takes much of the repetitive administration off consultants' desks [10].
Judgement stays with the consultant, according to Honan. "The key point is that the AI does not decide whether an organisation's risk is acceptable, whether a control is genuinely effective, or what management should do about a material risk," he said [11]. A consultant reviews the AI-assisted analysis, challenges findings, sets priorities and approves the deliverable [12]. "So there isn't a single point where AI 'hands over' to a human. The consultant remains engaged throughout the process," he said [13].
The commercial bet is on consultant hours with the drafting automated. Honan described the current state inside small firms. "We regularly see people within SMEs being given responsibility for cybersecurity, privacy or compliance alongside their normal day job, despite not necessarily having the time or specialist expertise required," he told Help Net Security [5]. The other common route, he said, is hiring several outside suppliers, one per area [6]. Cutting days from the firm's enterprise model would not fix that. "It would produce a smaller version of something designed for a fundamentally different organisation," he said [7].
The four tiers were announced without prices [1]. There is no way yet to check whether the administration the tool removes shows up as a smaller invoice for the client [1].
Asked where liability sits if a client is breached through a gap an assessment missed, Honan said: "As with any professional assessment, no consulting firm can credibly guarantee that an organisation will never suffer a breach, never experience an issue or always remain compliant." [14] An error in delivering the contracted service falls under the professional obligations and liability terms in the client's contract [15]. The client still runs its own environment and has to act on the agreed recommendations [16]. Each assessment covers its agreed scope and the evidence available at the time, and Help Net Security advised anyone signing up to read the scope section closely [22].
BH Haven does not manage a client's firewall or endpoints, and it does not run a security operations centre [18]. Its job is governance and assurance: helping management understand its risks and checking independently whether controls work [18]. Some MSPs and MSSPs already bundle compliance work into their contracts [17]. Honan sees those providers mainly as potential partners whose work BH Haven can independently assess [19]. "Ultimately, with BH Haven an SME's management team has an independent adviser sitting on its side of the table," he said [20].
What to watch
- Published prices for the Foundation, Standard, Professional and Scale tiers, and how they compare with BH Consulting's enterprise engagements.
- Launch dates for the Nordic and other EU markets, and whether the tiers change to match local NIS2 transpositions.
- Any MSP or MSSP signing a formal arrangement that lets BH Haven assess its controls for shared clients.