Jim O'Callaghan

Overall sentiment: 0.19
Back to Debate

I thank Deputy Byrne for raising this important issue. The reason I am here is because of the importance of it. Deputy Byrne is well aware that cybersecurity threats pose a major risk to essential services and critical sectors in Ireland and throughout the world. One of the consequences of being a modern, successful economy is that this is the type of threat to which the country is exposed, I regret to say. I therefore welcome that Deputy Byrne has raised this issue. It is important for me to outline, not just to Deputy Byrne, but to the House, the measures taken by my Department to ensure the State’s cybersecurity resilience and preparedness are where they should be. Deputy Byrne referred to the 2021 ransomware attack on the HSE. That was a very significant event from the point of view of the country and our preparedness for such cyberattacks. Since then, the National Cyber Security Centre has had a significant increase in its resources. It is essential that those resources have increased very significantly. Back in 2011, the NCSC only had four staff. At the end of 2024, it had 75 staff and an annual budget of €12 million. There is also a commitment in budget 2025 that the number of staff will increase by a further 30, bring it to more than 100 people working in the NCSC. The continued growth of the NCSC reflects the constantly evolving threat landscape and the importance of a resilient national network. It is appropriate, and I welcome the fact, that the NCSC has come within the jurisdictional control of the Department of justice. Considering the threat posed to the country, it is appropriate that the Department of justice should have departmental and ministerial responsibility for issues concerning cyber threat attacks. Deputy Byrne will also be aware that the European NIS2 directive also provides a major step forward for overall European cybersecurity and resilience. It will enhance cyber risk management in Ireland, including generating significant improvements in our capacity to protect against and respond to major incidents. Last July, the Government gave its approval to the priority drafting of the national cybersecurity Bill, which is currently being undertaken by my Department. That Bill will transpose the NIS2 directive into Irish law. It will also enhance the role of the NCSC, which will include national cybersecurity monitoring, resilience building, information sharing and the national incident response. It will give the NCSC specific powers to engage in a range of scanning-type activities to identify systems vulnerable to specific exploits. The national cyber emergency plan was published in May 2024, and it sets out the national approach for responding to serious cybersecurity incidents that affect the confidentiality, integrity and availability of nationally important information technology and operational technology systems and networks. The NCSC is currently working on the national cyber risk assessment for 2025, which will take into account the changing international threat landscape. As Deputy Byrne mentioned, it is regrettably the case that some of the attacks taking place on national cybersecurity networks are emanating from malign state actors. It is important that we be prepared in order to respond to and deter that. Deputy Byrne referred to a number of international agreements. I am pleased to say that Ireland is an active participant in a number of UN and other international processes where issues of cybersecurity arise. Among these is the UN open-ended working group on security of and in the use of information and communication technologies, which was established to develop norms, rules, and principles for responsible state behaviour in cyberspace. Ireland also participates in the Organization for Security and Co-operation in Europe, in particular as regards cybersecurity, conflict prevention and crisis management. It is important to emphasise that we are prepared, but this is a constant risk and it is inevitable that we will be subject to further attacks in the future.

Sentiment score: 0.10

I have had frequent meetings with the Garda Commissioner and the head of the NCSC in respect of the threats to which this country is exposed as a result of malign actors seeking to attack our cyber technology. It is important that I am updated on a continuing basis. I regret to say that the Deputy is correct, in that the threat does exist. It is a threat not just to our national State-owned infrastructure, as he has indicated, but also to private enterprise within the country. The NCSC is to the forefront in this matter, as am I. There is an obligation on State agencies to ensure that each State agency has measures in place to ensure that it can withstand whatever form of cyberattack is forthcoming. I know it will be impossible for all cyberattacks to be withstood, but if we have preparedness and measures in place in State agencies, that at least will increase and strengthen our resilience. The Deputy also indicated issues in respect of private sector companies. They all have an obligation to ensure, particularly if they are providing services to the public at large, that they have measures and protections in place so that, be they banks, communications providers or other agencies, their customers are protected in this respect. One of the reasons Ireland is an attractive location for malign State actors or persons who are involved in trying to extract data from private and public enterprises via ransomware is the important link between Europe and the United States. That is a very significant role, one that is now more apparent because of the success of the Irish economy, and we really need to defend it. The cybersecurity Bill was approved for priority drafting and I hope it will be introduced in the not-too-distant future, but I will get back to the Deputy specifically on that.

Sentiment score: 0.27