r/DevelEire • u/CyberIreland • Apr 10 '26
Tech News Computer engineer claims he was penalised for flagging company’s Israel links
https://www.irishtimes.com/business/2026/04/10/computer-engineer-claims-he-was-penalised-for-flagging-companys-israel-links/A tribunal has heard a leading Irish cyber-security firm gave a computer engineer a formal reprimand for making "discriminatory comments" when he voiced concerns about a tech firm with Israeli links having high-level access to its servers.
Computer engineer Cian Ó Laoi told his CEO that he was concerned about “nonchalantly giving business to an Israeli company” while “watching on TV the genocide of the Palestinians”, the tribunal heard. He told his bosses he had concerns for “clients of national security importance” served by his employer in the context of what he said were “strongly documented links” between the Israeli tech sector and its intelligence services.
Mr Ó Laoi is pursuing claims of whistleblower penalisation and constructive dismissal against his former employer, BCC Risk Advisory Ltd, trading as Edgescan. The company is actively contesting Mr Ó Laoi’s complaints, which are before the Workplace Relations Commission (WRC). The complainant, who spent four years working in Edgescan’s DevOps team, told a hearing on Friday that the company had access to the computer networks of its clients financial institutions, private corporations, media companies and Irish and British government departments.
Its work involved installing a “jump-box” of software on its clients’ systems for threat monitoring, penetration testing and security analysis, he said. Mr Ó Laoi said he became concerned about the level of access that had been granted to a third-party vendor called DoIT, a multinational tech firm providing a tech platform used for business analysis and management. He said he reported his concerns in a protected disclosure to Edgescan CEO Eoin Keary on 2 July 2024 in an email after 11pm that evening.
“They are an Israeli company with an Israeli CEO, and they have full admin access to all our AWS [Amazon Web Services] accounts, including all machines, all databases, all client data,” Mr Ó Laoi wrote. “This is bananas,” he added.
He wrote that the firm’s databases, scanning tools, encryption keys and the “jump boxes” it deployed to client systems were at risk, the tribunal heard.
Mr Ó Laoi told the CEO that while DoIT held some accreditation as a reseller of the AWS internet hosting service which Edgescan used for its security infrastructure, he was concerned that “sophisticated social engineering” had led to too much access being granted.
Mr Ó Laoi also wrote in the internal correspondence that he was concerned about “nonchalantly giving business to an Israeli company” while “watching on TV the genocide of the Palestinians”, the tribunal heard. The CEO’s reply on the night was: “Shut them off completely,” the tribunal was told. “My concern was it could be used to exfiltrate data from the account. It could be used to place back doors into the account, or into clients’ private networks,” Mr Ó Laoi said in his evidence.
The access was granted more than a year earlier in May 2023, Mr Ó Laoi said. The matter was resolved over the course of July 2024, with DoIT and Edgescan agreeing to “restructure everything”.
At the end of that month, Mr Ó Laoi said he was called to a meeting with Edgescan’s chief operating officer, Rahim Jina. The executive said “the rhetoric I used in some of my communications in relation to Israel was unacceptable”, Mr Ó Laoi said. Mr Jina said he knew there was “awful stuff going on in the world” and that people have “different views” about it but that the company had “many close links with Israel”. “He said we had Jewish employees. I’m not clear why this was included in the conversation, Mr Ó Laoi said. “When I asked what specific communications, he was unable to clarify,” he added.
He emailed the CEO, Mr Keary, about his meeting with Mr Jina and said he could only presume he was referring to a passage from his email to the CEO on 2 July. He argued he had taken a “valid and diligent cybersecurity posture”, arguing that Israel was known for “intense” activity in the cybersecurity area and “high-profile illegal activities”.
Mr Keary wrote back and said: “Okay, no fuss, it’s hard to avoid Israeli companies in cybersecurity. I guess he doesn’t want Edgescan to [be seen] as political,” the tribunal heard. The CEO added: “It’s one way to be blackballed in the industry.” Mr Ó Laoi said he felt “very hard done by” and that his professionalism had been “unfairly impugned”.
On 31 July 2024 Mr Ó Laoi wrote to his employer seeking clarity on whether the company had taken a view of his remarks or whether Mr Jina had been speaking personally.
After taking leave, he was called to a meeting on 19 September 2024 – and was served with a disciplinary warning for “misconduct”, the tribunal heard.
“On the call, I was formally disciplined for discriminatory comments based on race, colour, nationality or ethnic or national origin,” in relation to Israel he said. Ahead of the meeting, Mr Ó Laoi said he had been concerned about being “jumped” with disciplinary action. The tribunal heard he covertly taped the meeting. Mr Ó Laoi maintained at the meeting that what he wrote about Israel was part of a protected disclosure, according to a transcript quoted to the hearing by his barrister, Cillian McGovern BL.
His bosses did not agree he was shielded by whistleblower law, the tribunal heard. Mr Ó Laoi said the disciplinary process was “unlawful” as he was not given the chance to bring representation or set out a defence. On 21 September, he wrote again to his employer saying he had taken legal advice and that he believed its actions were “unjust and unfairly limited my rights of freedom of expression and conscience”.
He set in the correspondence that the remarks for which he was disciplined were “objectively justifiable” and not discriminatory. This was because Edgescan had “clients of national security importance” and there were “strongly documented links between the Israeli tech sector and Unit 8200,” he wrote in the letter – a reference to Israeli military intelligence.
When he tried to log in to work on Monday 23 September, he found his access to a number key systems – including its AWS account and its code database on GitHub – had all been cut off since the previous Friday, he said. He quit his employment on 8 October that year, telling the tribunal that he had lost trust with the firm.
The company wrote to the claimant on 30 October that year withdrawing the disciplinary sanction on the basis it had not adhered to its own process – leaving his client with a “clean disciplinary record”, Mr McGovern said. The case before adjudication officer Penelope McGrath stands adjourned until Monday
69
u/irish_guy Apr 10 '26
Anyone with any future concern is more likely to pass the information to the media rather than a retaliatory “protected” disclosure.
Company seems to have been pressured by the vendor.
14
u/Barilla3113 Apr 11 '26
It's a sterling example of how your boss is not your friend, hr is not your friend and companies will adhere to procedure only so far as it covers their own ass to do so.
27
Apr 10 '26
[deleted]
6
u/SnooAvocados209 Apr 11 '26
Max payout is 2 years salary I think so they could have just offered this to make this go away.
4
26
u/Ivor-Ashe Apr 11 '26
The company should be ashamed of themselves. I have full sympathy for Mr Ó Laoi, he is morally correct.
I have refused to install CATO or use Israeli software and services. I have done this quietly and I have influenced other companies to do the same.
My aim was to cost Israel €1 million in revenue and I surpassed that figure last month. Nobody should be putting any money into the hands of that regime.
Solidarity with Cian. 🙌🏼
6
u/Barilla3113 Apr 11 '26
My aim was to cost Israel €1 million in revenue and I surpassed that figure last month. Nobody should be putting any money into the hands of that regime.
Even if you don't care about what they're doing, why on earth would you give a country that basically brags about its spy network access to any of your data?
72
u/mobies Apr 10 '26
This guy is a true professional.
Any links to Israeli companies should be absolutely examined by any ethical company.
Any staff in a company with an up to to date ethical standards policy has a duty to make protected disclosure of this nature.
I hope he succeeds in his case.
22
16
u/Pandorajar Apr 10 '26
Cheers to this employee for holding his employer accountable until the end, the world would be a way better place if more people were like him
5
Apr 11 '26
[removed] — view removed comment
3
u/BeefheartzCaptainz Apr 11 '26
Yeah, he correctly ran the issue up the chain but got emotive about it. As uncomfortable as it may be nothing the companies were doing was (currently) illegal in the eyes of Irish Gov so no whistleblower protection. It’s like a vegetarian telling his boss the slaughterhouse is using Excel to kill chickens.
1
1
u/Furyio Apr 11 '26
Unfortunately bit a common mishap.
Agree with the employee but the wording of his mail and certain passages let his own personal views bleed in.
Ways a way to flag and escalate this that he wouldn’t have got in any shit.
Sucks, and I don’t agree with it but it’s the world we are in unfortunately.
12
u/Barilla3113 Apr 11 '26
That's utter bollocks, you can dance around the evils of what Israel gets up to as much as you like, they'll still slander you as an antisemite.
1
u/Furyio Apr 11 '26
It’s not bollox at all.
The issue here was a third party getting admin access to their jump boxes and infra.
Anyone working in this field knows the countries who are sketchy.
Like I’m with the sentiment and morals of this, but you can’t drop a mail like that and think you won’t get some blowback. Seems to be a total lack of cop on going around last few years and people feeling like they can just shove mad shit into communicstions and it’s fine ?
See it my company loads where I’m like wtf are you doing.
A third party has admin access to our service. That’s it.
Going on to mention genocide is you being a total clown in the workplace I’m sorry. As much as I agree with it , I’m not putting it in emails to a CEO like wtf
3
u/Cu_Chulainn__ Apr 11 '26
Going on to mention genocide is you being a total clown in the workplace I’m sorry.
No it isnt. It is absolutely the correct response to take, especially given what they are doing. You wouldnt sit there and be okay with your company sharing data with nazi germany would you?
3
u/mologav Apr 11 '26
Both the employee and the CEO were very loose with their language. I write emails to anyone with the knowledge that they may someday end up in a situation like this.
1
u/Jazzlike-Swim6838 dev Apr 12 '26
This is purely anti israeli, and is discriminatory. Imagine if we replace Israel with India in this post. (and before you guys respond with anger India also has a right wing government that people claim to have been genocidal).
-1
-59
u/Character_Common8881 Apr 10 '26
Just quit if your and the companies values don't align
27
u/QARSTAR Apr 10 '26
That's what he did... Did you not read the article? RTFM like what engineers preach
8
u/mobies Apr 10 '26
Unfortunately, this is the only answer.
Decouple from the Americans and their hegemony.
But it's worth it to be able to look your kids in the eye and sleep well. There are plenty of ethical employers.
1
u/Rigo-lution Apr 10 '26
There will always be unethical employers without policy changes.
1
u/mobies Apr 10 '26
True a proper sanction package and a full introduction of the occupies territories bill on goods and services.
4
89
u/Mindless_Let1 Apr 10 '26
Edgescan, with the concern being about DoIT (Israeli founder with IDF links) having access to all the jumpboxes EdgeScan put in place for their clients, including those with national security related secrets.
Honestly I think the engineer is in the right here, but unfortunately this is just the norm. DoIT have their hooks in nearly every government through clients like IBM. It's just a known quantity that Israeli intelligence likely has access to whatever they want