Senator Gerard Craughwell- speech from 22 Sep 2021
We publish thousands of recordings to make Irish politics transparent and resistant to manipulation. Spotted an error? Report it — together we are building a reliable archive of Irish politics.
Other speeches
Senator Gerard Craughwell-- speech from 17 Nov 2022
Gerard P Craughwell - speech from 18 Apr 2019
Senator Gerard P. Craughwell - speech from 26 Sep 2019
Gerard P. Craughwell: Amend Dáil Formula for a Modern Parliament
Senator Gerard Craughwell- speech from 6 Jul 2021
Senator Gerard Craughwell- speech from 18 Jan 2023
Tego samego dnia All speeches from this day →
Mattie McGrath
Mattie McGrath brings 11,000-signature petition for St Bridges Hospital
Paul Murphy
Paul Murphy Challenges Investor Court System in CETA Debate
Paul Murphy
Paul Murphy warns CETA lets corporations sue over data centre bans
Matt Shanahan
Matt Shanahan presses minister on data centres and energy security
John McGahon
Senator John McGahon - speech from 22 Sep 2021
Carol Nolan
Carol Nolan Calls to Scrap Hospital Parking Fees for Cancer Patients
Transcript
Thank you very much, Chair and Minister. Thank you for being here today, Minister. At the outset, I want to compliment you for taking on board the issue of cyber security, but I believe that we need to start taking this from a much more macro perspective. We should compliment the Gardaí for reversing the or at least some of the damage that was done with the HSE. But, Minister, I want to put to you a few moments ago you said money was a bit of a red herring. I am absolutely appalled to hear you say that. I see Malta is scheduled to spend £1.9 billion on cyber security over the next six years. That is Malta, one of the smallest countries in the EU. So, to say that it is a red herring, I am afraid it really does not go down well with me. I want to compliment the chairman and my colleagues for agreeing to bring in a human resource expert here because the money that you were offering for the director of cyber security that your department was offering was a joke. No serious professional would come anywhere near this country, which suggests to me that security, and I have said this many times, security in this country, whether it is cyber security or internal security or external attacks, it is a joke. We do not take it seriously. Now, you are trying to change that, but Minister, if you are going to change that, you are going to have to see a budget that will support it. Now, as we move forward, we need, and I have said this a hundred times, we need an integrated intelligence agency under a director of intelligence that would bring together all of the different intelligence gathering agencies of the state. That includes Gardaí, Defence Forces, Department of Social Protection, Department of Communication, we need them all under one umbrella where they are sharing information, and that we need to know what is happening. We take issues like cyber security with a grain of salt. We had, in the last few weeks, word of a minister's phone being hacked, and it just sort of breezes past everybody, and church was nothing really to get too excited about. Are your phones, Minister, and maybe you cannot answer this today, but are your phones protected properly? Do you have encrypted telephones? And if you do not, we should have encrypted telephones. We are a central location for foreign direct investment, and we control some of the largest volumes of data in Europe. And we are talking about 30 people in cyber security? There should be hundreds in cyber security, working in cyber security. When you look at the United States, with almost a million people working in cyber security, when you look at Estonia, which we would be looking down our nose at a few years ago as a much poorer country than Ireland, and their reputation in cyber security. My colleague, Deputy O'Muricu, spoke about the issue of defence forces, and the issue of legislation, and we see last night on the TV how the Graeme Dewire case may limit the capacity of the Gardaí to actually get involved in counter-espionage or counter-intelligence. We see that we have ships sailing up and down the Atlantic coast, coming very close to the 12-mine limit, where they are capable of intercepting data that is travelling from the United States into Ireland. Now, look, there are 3.5 million positions open in the world in cyber security. With 3.5 million positions open, Ireland is going to have to compete, and to compete we are going to have to put billions into cyber security. We will not have foreign direct investment here in a few years' time if we start seeing cyber security attacks. I can not understand it, but I have my own beliefs on it, but since we all started to register for the pandemic and Covid on our mobile phones, we are inundated with attacks from all sorts of crazy attacks. I get a dozen phone calls a week from the Department of Social Protection, and I no longer answer them. I will not answer any number now where I do not recognise the caller, because I am sick to the teeth of it. But, Minister, I want to ask you, you are going to be going in front of Minister McGrath and the Cabinet in the next few days. Do they fully understand the impact on foreign direct investment if they do not invest in cyber security? There is clearly a lack of understanding of what is required. In fairness to you, Minister, after you saw the HR expert Blonnet Carolyn talk about a salary structure of £220,000, you clearly fought the battle and got as close to that figure as you possibly could. Hopefully, we will get somebody really good into it. The problem we have with 3.5 million vacancies in the world, are we going to become a training centre for people who are paid poor money, who will move to higher paying economies as soon as they are trained? I am really concerned about this. I know this committee has taken a huge amount of time to debate these things, and I thank the chairman for it. Minister, I thank you for being here, but, Minister, is cyber security and security in general a joke? Would you agree with me that we need a director of intelligence and that we need one single intelligence agency? I am shocked to hear that we have only one Defence Force member in the National Cyber Security Centre. It should be run by the military, like most cyber security organisations in the world. So, I will throw that over to you, Minister, and I might come back with one or two supplementaries. Thank you. Thank you very much, Senator Crockwell. I will just start by saying I am not aware of any cyber security centre in the world that is run by the military, and ours is not run by the military, although it does have military assistance, which is very valuable as input. The salary, I think, to talk about the director and, you know, is there enough money to pay the person, the director who is to be appointed on a salary of 184,000 euros, that job is not directly equivalent to a chief information security officer working for a big tech company. It is a different job, because it has different responsibilities, it is, you know, it will have a different day-to-day working, and they are not directly equivalent. There are different benefits to that job, and there are different responsibilities. There is a lot of diplomacy, organisation skills. Minister, just at that point, will you bring in experts in recruiting for people in cyber security to assist in the recruitment process? Because it is such a specialised post, not in any way, probably a councillor does its work well, but on this particular one, will you be bringing expertise in, in terms of the recruitment process? Thank you for having that in the chairman. Yeah, in short, we will bring in experts, and that was the plan, we will bring in experts to this process, and the board itself also has expertise, but we will bring in external experts to that area. To go back to, can I go back to answering Senator Crockwell's question? Yes, yes, absolutely. So, he, Senator Crockwell mentioned the idea that we should have some kind of overall head of all the different parts of cyber security, cyber defence, across the different branches of the government, military, police, and so on, and some kind of coordinating role. And we, in fact, we do have that, it's called the National Security Analysis Centre, and it's based in the Department of the Taoiseach. So, I, let's see, let's see what else we have here. Senator Crockwell asked if my, if my phone is encrypted, it is encrypted, and I think that is a, that is a basic security measure to make sure that phones are encrypted, so that when they're, if they're stolen, that they, that the data can be taken off. If I interrupt you there, there, in that case, Minister, if phones are encrypted, cabinet members' phones are encrypted, and we've had one hacked, does that not create a massive national security question? We were talking here about the HSE for the last half an hour or thereabouts, and the impact that has had. If you can hack a cabinet minister's phone, just think, off the top of your head, the number of people's telephone numbers you'd have, not just nationally, but internationally. The text messages that would be exchanged between cabinet members, the text messages that would be exchanged between ministers across the EU. I find it absolutely beyond belief that we've had a minister's phone hacked, and that absolutely nobody seems to mind about it. Sure, this is grand, it is all fine. I just can't, I, I, we take security as a joke in this country. So, Senator Crockwell, in, in terms of the, um, security incident with, uh, with Minister Kovny's phone, uh, his phone, uh, was encrypted. Uh, the, the security incident was reported to the National Cyber Security Center. I can assure you they took it extremely seriously as a matter of national security, because he, he is the Minister for Foreign Affairs. So, there, there is absolutely no, there's, in no regard was this treated as a trivial matter, um, and it, you know, all the, all the correct statutory things were done to respond, to respond to that incident. Uh, and, um, you know, I think, uh, that, that's really all I have to say about, to say about that, I think. Um, I'll move on then to, uh, the question about the, the Graeme Dwyer case and the implications for, uh, you know, the legal implications for, for intelligence gathering and for rules about. Minister. Minister. Sorry. Just not to, just be careful about any live legal case, just in terms of your comments, just, just by way of, of, of, um, of observation, okay? Minister. Thank, thank you for the reminder, Chair. So, just to say about that, that, that is, that, in fact, what I was going to say, Chair, was that that is a live case and that the, that the case has not yet been decided, uh, and the implications of it are unknown as yet. Uh, I can tell you that scenario planning is, is of course done, but that there, that, you know, it's, it's a live case and I can't comment on it and I don't know how it is going to, going to turn out is the, you know, is the reality. Yeah. In, in fairness, Minister, I wasn't asking you to, to comment on the Dwyer case. It was the concept that, um, when we're talking about security, you'll know this. We, for example, in the development of antivirus software, we are always chasing the criminal. In, in the interest of consistency, yeah, I'll ask you to be guided that it is a likely. Yeah, no, and I, I wasn't going to go there, uh, Chairman, but we're always chasing the criminal when it comes to, uh, um, virus software. We're always chasing the criminal when it comes to any sort of criminal behaviour, uh, just as we're tracing, chasing, uh, hardware when we're trying to develop the latest software. So, these are serious, serious issues and things like ethical hacking and things like that need to be proactive in the country if we're to be sure and safe. And that would apply to the schools. My former colleague, uh, Deputy Crowe was talking about, you know, they should be, uh, in, in the college I worked in, in Black Rock. And I know, I know, you know, they, they place well. We spent anything up to a hundred thousand a year on computer hardware, antivirus software, cyber security systems. I know every school wouldn't have that advantage. By the way, mine was a VEC school, not, not a private school. So, uh, from that point of view, look, I've taken enough time. No, no, I just, Minister, if you have concluding remarks for Senator Crockwell's questions. Yes, certainly. I mean, one of the questions that Senator Crockwell asked was whether the Cabinet, uh, uh, understood the seriousness of, um, taking, of cyber security with reference to FDI. And, uh, you know, this is an issue that they do. This is an issue that the American Chamber of Commerce and that other lobby groups for, uh, for, for multinationals bring up is that, uh, they, they want to have a secure environment, uh, in, you know, in which to locate their data and do business. And, uh, so that, that is, that's completely understood. So, um, you know, in, in general, um, I wanted to say, I think, I think the gist of, of, uh, of what Senator Crockwell is saying is that he is, uh, concerned that, uh, cyber security is not being taken seriously. That there aren't adequate resources being given to us and that it isn't understood within government how, how important it is. And I, I, um, I'd like to reassure him that, uh, that none of that is true. That, that, that, that everybody understands how incredibly important it is to protect our, uh, our, our national assets and our critical infrastructure. And that there are huge costs to being attacked and that we have to do everything we need to do to have the best in class of cyber security protection. Thank you very much. Minister, there was a ransomware attack on the UK health, health system on the 12th of May 2017. It beggars belief that we were still operating within our health service with machines that were so out of date with software that was so out of date that they were an easy target. Uh, which brings me back to the point I've been trying to make all along. We don't do security seriously in this country. Now, you've outlined the various different agencies that are involved under the, uh, security umbrella, if you want. There are too many goddamn cooks, so there are. There needs to be a director of cyber security who has his or her staff placed in every government agency in the country reporting directly to him or her, not to the secretary general of a department or not to some principal officer in a department who might write a report at some stage that may finish up in the department of the Taoiseach. There is a terrible lax attitude to security here. Now, you said that you engage with the high tech companies. I've met high tech people or people from high tech companies at various functions around town, and they tell me they have been screaming for years about the state of security and cyber security in this country. I would like to have an audit, if we could, of the current state of all state agencies with respect to cyber security. What steps have they taken since the HSE was attacked to protect their own systems, and are they reporting directly to you so we know where we are? I am deeply concerned that with all of the cooks that are involved in this organisation of security in this state, we will find ourselves attacked time and time and time again. Thank you, Senator Crockwell. The 2017 attack on the NHS was the WannaCry virus, which was not a ransomware attack. It really was. It did cause great damage to the NHS's systems, and it also attacked the HSE. Luckily, the HSE was protected to an extent that they had a much lower level of damage caused. The question about centralised cyber security, I think Senator Crockwell was suggesting that every cyber security lead in every government department should report to the NCSE cyber security director, which is a centralised model and is the opposite of what we were discussing with Deputy Crow, where this idea that you need to have a distributed model, that people need to be able to control their own cyber security and their own organisations. We are not proposing, and the review of our cyber security capacity does not suggest that we should centralise all of our cyber security and have it run by the Department of Communications and that everybody should report to them. The question, Senator Crockwell raised the question of the reporting of cyber security events and the information about what's that transparency around those. I agree with this. I think that many, usually, every cyber security attack that happens, every incident that happens, they're not reported and they're not well known to the public. The assumption is then that the staff are doing nothing or something or that nothing is happening, there's nothing to defend. I would like to see in the future a framework for better reporting to the Oireachtas and to the public of the cyber attacks that are happening and how they're being defended against. Mr. Minister, on that point, if someone has a cyber attack in their business or a school or a public, what is the current recommendation as to who they should report it to? What is the current recommendation? Do people know about this and can you come up with such a framework now that can be put in place where you have a structured approach, but people being able to report and equally that we get transparency around publications, the numbers that were reported and our general state of being? It gives you a signals map of where we are at. Who do people report at the moment? Mr. Chair, I would just add that anecdotally, and I have heard it a number of times, of just an awful lot of companies that aren't declaring and are just paying the money and getting the key and telling nobody anything because they are afraid of reputational damage or whatever. Mr. Chair, taking that on board, obviously, so that people are unwilling to report for whatever reason, what can we put in place? Who do they currently report to? Is it the National Cyber Security Centre? That is who they are supposed to report to? Yes, it is the National Cyber Security Centre. I would say to any organisation that is attacked to look at the National Cyber Security Centre's website, and they give information for how to report an incident. In the last year, to give you an idea of the volume, 3,000 such incidents were reported. That is to give you an idea of what is going on. Deputy O'Muraku, what was your question? Deputy O'Muraku, the question was basically that you have ransom. People are paying ransoms rather than reporting, and your perspective on that? Yeah, so we do want people to report what happens. We don't want them to pay ransoms. Paying ransoms just creates more attacks. It is the business model of the people who are there. I would ask anybody who is attacked to contact the National Cyber Security Centre for assistance and for help. The staff there have great experience dealing with people who have been attacked all the time, and the actions that you take when you are attacked are really critical to what happens later on, to your success at being able to protect yourselves from these people. Even if you pay the ransom, you may still have your data published. You may never get a key back to unlock your data. Whereas, you know, with the HCC attack, of course, we didn't pay a ransom. We got the key back and we didn't have any data published. So I would advise anybody who is attacked to contact the National Cyber Security Centre, any organisation that is attacked. using the NDI? People, we're here. People, we're at the National Cyber Security Centre, people, they don't have any data published. Let's getkom увидеть their data. It's a huge data collection that's been upgraded to us. Don't ask him at the National Cyber Security Centre. Which is something that I can envision? Oh, he can see? The National Cyber Security Centre. That's a huge data collection. The National Cyber Security Centre is a huge data collection who's a large part of this planet. So he's realized what's going on in a space within us. And, then, to the National Cyber Security Centre Centre is a huge data collection. And, to the National Cyber Security Centre Centre, that's a huge data collection is a huge data collection.