Lawyer of the Month: Laura Gillespie
Laura Gillespie
The numbers show that data security incidents have ascended ineluctably during the past five years. And according to the UK’S Cyber Security Breaches Survey, cybersecurity is not necessarily getting worse just because a greater percentage of companies are being attacked, but rather the attacks that do succeed are becoming more consequential.
Figures published in December 2025 by Northern Ireland Statistics and Research Agency (NISRA) statisticians in the Department of Justice show that around one in nine respondents (11 per cent) had been a victim of cybercrime, with a further 37 per cent indicating someone had attempted to commit a cybercrime against them personally.
No one is immune – from those of us receiving an e-mail informing us that hundreds of pounds have been spent on our Amazon account (and directing us to a tempting link to resolve the situation) to ransomware that has recently impacted major organisations including Marks & Spencer, the Co-op and NHS-related organisations.
In the Republic of Ireland, the high-profile 2021 cyber attack against the Health Service Executive (HSE) was an early example of what has now become a wider trend towards infrastructure-based attacks.
Laura Gillespie – a partner at Pinsent Masons in Belfast, who specialises in helping clients prepare for, and respond to, cyber incidents – is a co-author of the firm’s Cyber Report and has commented on the issue on media platforms such as the BBC and Irish News.
Celebrating her 25th anniversary at Pinsent Masons this month she says: “The focus of my practice is around three main pillars: cyber and incident response, general commercial litigation with a focus on privacy and technology, and more general practice, including dispute resolution and mediation across a range of sectors both on a Northern Irish and national basis.
“If a client has experienced a cyber event, we will help them manage the incident and all the consequences that flow from it.”
Her focus on the cyber, technology and privacy space has evolved over the years as the role of technology within the general business environment has grown. “When GDPR came into force in 2018 and reporting became mandatory for certain data breaches, we established a cyber centre of excellence in Belfast as part of the national team” she explains.
“We’ve since dealt with hundreds of breaches on a national and international level, handling anything from a business email compromise through to ransomware on an international scale.”
The team in Belfast, she says, regularly works with colleagues in Dublin and London to manage incidents and is equipped to equally handle incidents for clients across multiple jurisdictions.
“With 31 offices globally, we have a strong network allowing us to bring in local counsel support depending on affected jurisdictions – so it’s very much an international practice.”
She’s encouraged that the business community is alive to the risk that a cyber incident can pose and of the data protection risks that follow. “The consequences of a breach are much broader than the fact that someone’s personal data has been compromised,” she stresses.
“For example, if a company’s systems are encrypted and can’t operate, that has very immediate and very serious consequences in terms of the business’ ability to function.
“I think boards are very much aware of the nature of the risk, but as AI starts to be deployed in various ways it will give threat actors greater speed and efficiency in detecting vulnerabilities within systems. And, if large copies of databases have been extracted, AI can be used to process that information much more quickly to make it understandable.”
The consequences can extend beyond the company itself, however. “We’re increasingly seeing incidents not just targeted directly at the victim organisation, but an increasing trend toward ‘supply chain events’, in which threat actors target organisations which feed into the supply chain and see that as a way of causing disruption,” adds Laura.
Ms Gillespie emphasises that businesses shouldn’t wait for a ransomware attack to impact their business before considering how it would respond.
“Businesses must be aware of the need to plan for these incidents but also spend time and effort ensuring that they have a clear incident response plan in place. It’s a much better idea to plan for that in the calm of a boardroom than when you’re directly encountering the incident.
“In the immediate aftermath, businesses also need to quickly understand the impact of the incident. How are they affected as a business? What data has been affected – is it the personal data of staff, of customers or a combination of the two?
“Equally, we help businesses understand who they need to notify – this can range from privacy regulators (such as the DPC or ICO), to customers to whom a contractual obligation is owed, to telling individuals who are at “high risk” because of the incident.”
To help clients with this, Pinsent Masons has developed Cyturion, its own cyber-incident response platform. “It’s a cloud-based product where clients can host their incident response plan,” Ms Gillespie explains.
Cyber attacks, she points out, are sector agnostic with everyone at potential risk and she deals with a wide range of clients, including SMEs, and operates on several insurer panels. “Through that, clients range from third-sector organisations. to multinational corporations.”
The incidents are equally varied: “A client may be concerned that they have sent an email to the wrong person with an attachment that may be a potential data breach, through to ransomware on a global scale.”
A native of Armagh, Ms Gillespie graduated from Queen’s University Belfast and joined L’Estrange and Brett, which merged first with McGrigors in 2009 then Pinsent Masons in 2012 and says she always had a keen interest in studying law. “It’s something I find really fulfilling and what strikes me at this point in my career is how diverse and exciting it is – and how much it’s changed.
“If I reflect on how law was practised when I joined the profession, it’s a very different environment now, one in which we must be commercially focused and are very much looking to help clients anticipate problems as well as resolve them.”
With two small children to attend to, she impressively has enough energy left to have completed four World Marathon Majors, in New York, London, Berlin and Chicago in a series of city races that attracts both elite athletes and everyday runners from all over the globe.
“I’m probably the tortoise of the race when it comes to getting round the course but it’s something that I enjoy,” she laughs. “And as the children get a bit older, it gives me another goal on the horizon.”
Any cyber incident, she points out, can be a worrying time and clients may need a degree of comfort as well as practical help. “It’s rewarding to be able to reassure clients that we are experienced in handling incidents and will use that experience to help them navigate what can be a stressful period.
“Drawing on my experience to reassure clients and guide them through a difficult period is one of the most rewarding parts of my job.”



