I thank the Minister for taking this critical issue. As he knows, we all live in a digital world. It is one where computing in general has made our lives better and easier and we are far more interconnected. Artificial intelligence, quantum computing and other technologies have the potential to deliver ever more effective and efficient public services. However, as cyberspace becomes more critical to all of our lives, the risks and threats are also increasing exponentially. Our society depends on a free, open and secure cyberspace. Ireland should do everything to support those values at a global level. In our engagement in multilateral efforts, we need to ensure international law applies in cyberspace as much as it does on the ground. In that regard, we have to support the work of the United Nations, the European Union and others in this field. Like other countries, there are challenges to Ireland in the cyberattacks we face, including those from other states or malign actors aligned to those states, as well as those who want to hack State infrastructure systems for financial, political or ideological reasons. I commend the work of the National Cyber Security Centre, NCSC. As the Minister knows, it needs to continue to expand. In one of its most recent reports, it talked about 2023 as being its busiest year. At that time, it received 5,200 cyber reports and while many were minor, it identified 721 cyber incidents that represented a threat to a network and required a response. The National Cyber Security Centre has now found there is enough evidence and information in a number of those cases to attribute activity to specific foreign intelligence and security agencies. We know that businesses are regularly hit by cyberattacks, but I want to talk about the potential impact on critical State infrastructure. Everyone will remember May 2021, when the HSE faced a major ransomware attack. We know that the costs to date have been more than €150 million, not to mention the many lives that were undoubtedly lost as a result of the attack, as well as delayed appointments and the impact on people's health outcomes. For security reasons, we often cannot discuss cyberattacks. When I put a question to every Department as to how many cyberattacks they faced in recent years and how much they were spending on cybersecurity, a lot of them replied that they could not answer for security reasons. Interestingly, some of them were able to provide details on how much they were spending on cybersecurity. Given the amounts involved, it shows most are taking it quite seriously. It is important that we know the State has a plan in place to combat any major cyberattack we face in the future and to address situations where critical infrastructure may be brought down. This could be in health, transport, financial services, Government payments or energy. We need to have an all hands on deck approach if this is to happen, similar to what we have seen with major weather events. I hope we have learned from the experiences of the HSE attack and that we are constantly learning from efforts to attack critical State infrastructure. The Minister will also be aware of the risk of destabilisation to the State when there is a malicious cyberattack. The spread of misinformation and disinformation represents a threat to democracy. Trust in Government and our provision of services can also be damaged when critical infrastructure is brought down. Our sense of freedom to enjoy certain rights can also be under threat. This issue needs to be taken seriously and I am glad the Minister is here today to take the question.
Sentiment score: 0.10
Like the Minister, I welcome the fact that the NCSC is now within the remit of the Department of justice. I welcome the fact that he is giving priority to the cybersecurity Bill, but he might provide an outline as to when he envisages it coming before the House. While I welcome the fact that the NCSC regularly carries out assessments of cyber risk, I wonder if an assessment has been carried out as to exactly how vulnerable some of our critical infrastructure happens to be. For instance, how easy might it be for a malign actor to knock out the traffic lights in Dublin, with the ensuing chaos that would result, or stop all bank payments to public servants or social welfare recipients? What systems do we have in place to seek assistance from or offer assistance to like-minded states if a cyberattack were to happen here? We need to co-operate, particularly with our EU partners. Similar to Storm Éowyn, where we sought assistance from overseas, I believe we will need to seek and offer assistance where like-minded countries are attacked. This is a global issue and, therefore, when it comes to overseas aid, we should be offering to help developing countries to build their cyber resilience, given the expertise in this country. They are often subject to attacks by some of the rogue states in this area. We need at an international level to start demanding accountability, particularly from the four states most responsible for cyberattacks around the world: Russia, China, Iran and North Korea. They are engaged in or sponsor cyberterrorism, cyberespionage and the spreading of misinformation and disinformation, which represent threats not just to this State, but to others that share our values. In the same way we rightly hold countries to account for actions in wars on the ground, we need to hold them to account where they act in a malign way in cyberspace.
Sentiment score: 0.02