Company Details
jennings-o'donovan-&-partners
89
4,500
237
jodireland.com
0
JEN_2896984
In-progress

Jennings O'Donovan & Partners Company CyberSecurity Posture
jodireland.comJennings O’Donovan is a multidisciplinary consulting engineering firm specialising in renewable energy, water supply, wastewater treatment and in the provision of planning and environmental services. Founded in 1950, the company, has offices across the country in Sligo and Dublin. Since 1st August 2023, the company is part of RSK Group. The extent of the services provided by the company covers a broad range of sectors including civil, structural and environmental engineering, health and safety, housing and commercial, aquaculture, flood relief, tourism, leisure amenity, water, wastewater and the renewable energy sector. The services we provide are based on over 70 years of experience working with local authorities, utilities, commercial entities and industries in Ireland and overseas. At Jennings O’Donovan, we pride ourselves on being responsive and in our ability to deliver clients expectations in an efficient and effective manner. The primary markets the company is currently operating in are Ireland, the United Kingdom and Eastern Europe.
Company Details
jennings-o'donovan-&-partners
89
4,500
237
jodireland.com
0
JEN_2896984
In-progress
Between 700 and 749

JOP Global Score (TPRM)XXXX

Description: A cyber attack targeted **Jennings O'Donovan**, an engineering firm responsible for assessing applications under Ireland’s **Defective Block Grant Scheme**. The breach compromised **personal data** of applicants, including **addresses, contact details, and photos of crumbling homes** affected by defective bricks. The incident was isolated to the firm, but the stolen data raises concerns over privacy and potential misuse, given the sensitivity of the information tied to vulnerable homeowners. The **Irish Housing Agency** is coordinating with the company to investigate the breach, notify affected individuals, and implement safeguards. The **Data Protection Commissioner** and local authorities were also alerted. While the attack did not disrupt the grant scheme itself, the exposure of personal records—particularly for families already facing housing crises—heightens risks of fraud, identity theft, or further exploitation. The firm and government agencies are under pressure to provide **transparency on the timeline, nature of the compromised data, and mitigation steps** to restore trust among impacted applicants.


Jennings O'Donovan & Partners has 0.0% fewer incidents than the average of same-industry companies with at least one recorded incident.
Jennings O'Donovan & Partners has 56.25% more incidents than the average of all companies with at least one recorded incident.
Jennings O'Donovan & Partners reported 1 incidents this year: 1 cyber attacks, 0 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.
JOP cyber incidents detection timeline including parent company and subsidiaries

Jennings O’Donovan is a multidisciplinary consulting engineering firm specialising in renewable energy, water supply, wastewater treatment and in the provision of planning and environmental services. Founded in 1950, the company, has offices across the country in Sligo and Dublin. Since 1st August 2023, the company is part of RSK Group. The extent of the services provided by the company covers a broad range of sectors including civil, structural and environmental engineering, health and safety, housing and commercial, aquaculture, flood relief, tourism, leisure amenity, water, wastewater and the renewable energy sector. The services we provide are based on over 70 years of experience working with local authorities, utilities, commercial entities and industries in Ireland and overseas. At Jennings O’Donovan, we pride ourselves on being responsive and in our ability to deliver clients expectations in an efficient and effective manner. The primary markets the company is currently operating in are Ireland, the United Kingdom and Eastern Europe.

Some 45 years ago, we set out with the ambitious goal of providing affordable housing, working to make Brazilian dreams come true. Over the last few years, we have crafted and shaped our story, becoming a brand-leading platform that offers a variety of housing solutions for individuals and families

Egis is an international player active in the consulting, construction engineering and mobility service sectors. We design and operate intelligent infrastructure and buildings capable of responding to the climate emergency and helping to achieve more balanced, sustainable and resilient territoria
Performance to succeed today. Technology to lead tomorrow. Epiroc is your partner for mining and infrastructure equipment. We're excited to build on proven expertise and performance with the same people and a bold new drive to make what's good even better. Just like our name ‘Epiroc’ says, we w
Tetra Tech is a leading, global provider of consulting and engineering services. We are differentiated by Leading with Science® to provide innovative technical solutions to our clients. We support global commercial and government clients focused on water, environment, sustainable infrastructure, ren

Mott MacDonald is an employee-owned engineering, development and management consultancy, with more than 20,000 people in over 50 countries. We plan, design, deliver and maintain the transport, energy, water, buildings and wider infrastructure that is integral to people’s daily lives. Our core streng

Water and Power Development Authority (WAPDA) has been dominating the national economic scene of Pakistan for well over 50 years now. WAPDA is given the following charter of duties: generation, transmission and distribution of power; Irrigation, water supply and drainage; Prevention of waterlogging

We are committed to addressing the world’s biggest challenges in the areas of water, energy and communities. GHD is a global network of multi-disciplinary professionals providing clients with integrated solutions through engineering, environmental, design and construction expertise. Our future-focu

Ramboll is a global architecture, engineering and consultancy company founded in Denmark in 1945. Our 18,000+ experts create sustainable solutions across Buildings, Transport, Energy, Environment & Health, Water, Management Consulting and Architecture & Landscape. Across the world, Ramboll combi

We are UEM Group Berhad (UEM Group), one of Malaysia's leading engineering-based infrastructure and services conglomerate with an established track record and global operations. We have the ability, expertise and resources to deliver and manage key infrastructure development projects and services
.png)
It seemed as if Kilmacabea were firmly on course for victory after substitute Liam McCarthy fired in their second goal inside the last...
The Cahermore Ploughing Association hosted its 69th annual ploughing match last Sunday on the lands of Stephen and Catherine Barry at...
Cyber incident at engineering firm impacts personal information contained in files submitted by Mayo applicants to the defective concrete...
I just thought I'd have a lash and for once they went over," said the man of the match as the reigning champions Kilmacabea got the better...
The Housing Agency has warned of a cyberattack on one of its engineering consultant companies.
An engineering firm that works to assess grant applications has been targeted by hackers.
Cyber incident impacts personal information contained in files submitted by Donegal applicants to the defective concrete blocks grant...
Donegal Deputy Charles Ward has called on the Housing Agency, the Minister for Housing, and the Data Protection Commission to provide full...
The Housing Agency has been notified of a cyber incident involving one of the engineering consultant companies that works with the Agency on...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Jennings O'Donovan & Partners is http://www.jodireland.com.
According to Rankiteo, Jennings O'Donovan & Partners’s AI-generated cybersecurity score is 735, reflecting their Moderate security posture.
According to Rankiteo, Jennings O'Donovan & Partners currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Jennings O'Donovan & Partners is not certified under SOC 2 Type 1.
According to Rankiteo, Jennings O'Donovan & Partners does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Jennings O'Donovan & Partners is not listed as GDPR compliant.
According to Rankiteo, Jennings O'Donovan & Partners does not currently maintain PCI DSS compliance.
According to Rankiteo, Jennings O'Donovan & Partners is not compliant with HIPAA regulations.
According to Rankiteo,Jennings O'Donovan & Partners is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Jennings O'Donovan & Partners operates primarily in the Civil Engineering industry.
Jennings O'Donovan & Partners employs approximately 89 people worldwide.
Jennings O'Donovan & Partners presently has no subsidiaries across any sectors.
Jennings O'Donovan & Partners’s official LinkedIn profile has approximately 4,500 followers.
Jennings O'Donovan & Partners is classified under the NAICS code 237, which corresponds to Heavy and Civil Engineering Construction.
No, Jennings O'Donovan & Partners does not have a profile on Crunchbase.
Yes, Jennings O'Donovan & Partners maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/jennings-o'donovan-&-partners.
As of November 27, 2025, Rankiteo reports that Jennings O'Donovan & Partners has experienced 1 cybersecurity incidents.
Jennings O'Donovan & Partners has an estimated 5,728 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with direct outreach to affected applicants; public statements via housing agency and charles ward td; notification to data protection commissioner and local authorities...
Title: Cyber Attack on Jennings O'Donovan Affecting Ireland's Defective Block Grant Scheme
Description: A cyber attack on Jennings O'Donovan, an engineering firm assessing applications for Ireland's defective block grant scheme, may have resulted in the theft of personal data, including addresses, contact details, and photos of affected homes. The Irish Housing Agency is investigating and notifying impacted applicants.
Type: data breach
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Data Compromised: Addresses, Personal contact details, Photos of affected homes
Brand Reputation Impact: high (public concern, loss of trust in handling sensitive data)
Identity Theft Risk: potential (personal data exposed)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Identifiable Information (Pii), Addresses, Contact Details, Photographs Of Homes and .

Entity Name: Jennings O'Donovan
Entity Type: engineering firm
Industry: construction/engineering
Location: Republic of Ireland
Customers Affected: applicants of Ireland's defective block grant scheme (thousands of homeowners in Clare, Donegal, Limerick, Mayo, and Sligo)

Entity Name: Irish Housing Agency
Entity Type: government agency
Industry: housing/public sector
Location: Republic of Ireland

Incident Response Plan Activated: True
Communication Strategy: Direct outreach to affected applicants; public statements via Housing Agency and Charles Ward TD; notification to Data Protection Commissioner and local authorities.

Type of Data Compromised: Personal identifiable information (pii), Addresses, Contact details, Photographs of homes
Sensitivity of Data: high (includes highly sensitive homeowner data and images of defective properties)
Data Exfiltration: likely (data described as 'may have been stolen')
File Types Exposed: documentsimages

Regulatory Notifications: Data Protection Commissioner (Ireland)local authorities

Source: Irish Housing Agency (public statement)

Source: Charles Ward TD (100% Redress Party)
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Irish Housing Agency (public statement), and Source: Charles Ward TD (100% Redress Party).

Investigation Status: ongoing (Housing Agency working with Jennings O'Donovan to ascertain details)
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Direct outreach to affected applicants; public statements via Housing Agency and Charles Ward TD; notification to Data Protection Commissioner and local authorities..

Stakeholder Advisories: Housing Agency and Charles Ward TD have issued public statements urging transparency and clarity for affected families.
Customer Advisories: Affected applicants are being contacted directly by the Housing Agency. Uncontacted applicants are confirmed as unaffected.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Housing Agency and Charles Ward TD have issued public statements urging transparency and clarity for affected families. and Affected applicants are being contacted directly by the Housing Agency. Uncontacted applicants are confirmed as unaffected..

High Value Targets: Personal Data Of Homeowners, Defective Block Grant Scheme Records,
Data Sold on Dark Web: Personal Data Of Homeowners, Defective Block Grant Scheme Records,
Most Significant Data Compromised: The most significant data compromised in an incident were addresses, personal contact details, photos of affected homes and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were addresses, personal contact details and photos of affected homes.
Most Recent Source: The most recent source of information about an incident are Charles Ward TD (100% Redress Party) and Irish Housing Agency (public statement).
Current Status of Most Recent Investigation: The current status of the most recent investigation is ongoing (Housing Agency working with Jennings O'Donovan to ascertain details).
Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Housing Agency and Charles Ward TD have issued public statements urging transparency and clarity for affected families., .
Most Recent Customer Advisory: The most recent customer advisory issued was an Affected applicants are being contacted directly by the Housing Agency. Uncontacted applicants are confirmed as unaffected.
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.