Menu
VideoParliament
VideoParliament Irish politics in one place — download the app
Get app
VideoParliament
VideoParliament for Windows Get the desktop app — notifications about new speeches
Get app
Gerard P. Craughwell presses cyber chief on SME support

Gerard P. Craughwell presses cyber chief on SME support

Senator Gerard P. Craughwell questions Dr Brown, director of the National Cyber Security Centre, on legislation, offensive cyber capacity and support for SMEs during a committee session. The exchange focuses on whether Ireland is meeting its cyber protection needs ahead of its EU Presidency and how SMEs will be helped to improve basic cyber resilience.

Legislation and EU Presidency


Gerard P. Craughwell opened by asking whether the absence of updated legislation will hamper the National Cyber Security Centre as Ireland prepares for the Presidency of the European Union. Dr Brown responded that legislation for critical infrastructure exists and the next European-aligned update is coming, with systems already built and ready to scale when the law is in place.

Defence, offence and public profile


The senator pressed on whether Ireland's posture is strictly defensive or whether there is offensive cyber capability. Dr Brown referred to the National Cyber Defence Strategy but noted offensive capability is a national security matter and largely not for public discussion. Both speakers also discussed the public profile of the NCSC and the need to be transparent about genuine risks without inflating routine incidents.

Gerard P. Craughwell — frame from remarks: Gerard P. Craughwell presses cyber chief on SME support (10.06.2026)

SMEs and practical support


Craughwell raised concerns about the reach and size of Enterprise Ireland support for small firms and relayed industry suggestions to reallocate funds for faster, wider rollout of basic protections. Dr Brown highlighted a new SME portal with tools and guidance, confirmed lessons from a recent pilot with Enterprise Ireland, and said a different, improved scheme is committed in the program for government.

We publish thousands of recordings to make Irish politics transparent and resistant to manipulation. Spotted an error? Report it — together we are building a reliable archive of Irish politics.

Tego samego dnia All speeches from this day →

Transcript
Chair Crawford. Thank you very much Cathaoirleach. Dr Brown, Ms Morris, you're very welcome and thank you for being here. I have to say from the first time we met, Dr Brown, you have moved the National Cyber Security Centre to a much higher profile and that's to be welcomed, so it is. I believe you've moved to the Department of Justice now. I'm not sure if that move is complete or if you're still in transit as it were. Just a couple of things I'd like to put out there and I'll put them all together if that's okay with you, Dr Brown. So, legislation, you had an opinion piece recently or a report in the Irish Examiner, I think it was. You're desperately seeking legislation and I think we're the laggards on this occasion, not meeting your needs. Is this going to hamper you as we move into the Presidency of the European Union? When I look up the Irish National Cyber Security Centre and have it compared to your international peers, I'm actually extremely impressed to see how professionally your centre is regarded. However, the country as a whole is regarded as a laggard in the area of cyber security. Is there anything that is impeding you from being a higher public profile? There's a tendency within this illustrious building to try and avoid questions in relation to national security, defence and security and the like and head in the sand, it won't happen, sure, everybody loves us, we're great football fans around the world and that sort of worries me. So, I note your engagement with the industry and that is hugely important and extremely impressive the way you are now engaging with industry suppliers, which means that there is a constant, if you want, communication between you and the people who need to know what's happening. And is there anything that we should be doing to support that better for you? The other thing is, from the attack perspective, have we got the capacity to be offensive as well as defensive when it comes to cyber attacks? Are we strictly on the defensive side when it comes to it? And the last piece I'll throw in for the hell of it is the SME sector. The Enterprise Ireland system that was in place, I think it was 3,000 of a grant for an initial overview of your system and then up to 60,000 of a grant to bring your system up to speed. It was confined to EI clients only and a lot of the SME sector are quite concerned that that's the way it has gone. The other suggestion that was made by a number of industry actors to me was that actually we should reduce the 60,000 down to 20,000 and allow for a much faster rollout of some of the simple things that would make our SME sector safer, such as software patches, et cetera, et cetera. Sorry, there's a lot there, but I just said I'd throw it all out in one go. So thank you. Thank you, Chair. I'll do my very best to cover all of that. So I suppose to answer the Senator's first point rather than question, yes, we've changed a lot, but it has been a decade. And we're now approaching 100 people and have real scaling capability. That also goes on to answer a couple of other questions. On the legislation, we already have legislation to deal with critical infrastructure. It is not the latest version of the European legislation, but that's coming. But we already have fairly significant powers to enforce and to compel engagement with us. So we're not in a bad position for the really critical sectors in the state. There are systems we've built in anticipation of the legislation, which we can't use fully. But when the legislation does pass, we can go live extremely quickly thereafter. And I'm happy to brief the committee more once we're in a position to be public about that. Is the state a laggard? No, it's not at all. So we're in a very lucky position in Europe in the sense that we have a very strong private sector cybersecurity industry. Last time we checked and did a formal report, we had more than 8,000 people working in private sector cybersecurity in the state across a range of different companies, some large multinational companies, some much smaller Irish companies. So there's a very robust sector there. And speaking to colleagues across industry, in the last five years alone across not just the critical infrastructure sector, but others, there's been a huge increase in capability and understanding, which is really important from our perspective. That's showing up as well in international rankings. In terms of public profile, I think I have an unfortunately high public profile and no interest in expediting that. But at the same time, we are utterly clear about the need to be transparent as to the risks and not to hide behind anything because it's important that people understand what they are and critically understand what they're not. One of the key issues in hybrid and dealing with hacktivist type attacks, including the presidency, is the tendency to describe everything as being a crisis. Most hacktivist attacks are not. Most cyber attacks are categorically not. They're entirely manageable, small-scale issues, which with the right response techniques can be made, go away for want of a better term, and mitigated very quickly. There are issues which are not. That's why we have all the planning and procedures to deal with those things, but that is what it is. In terms of the offensive component, there is mention in the public domain in the National Cyber Defense Strategy, which is the GCDC's own strategy around offensive capability. That's the only measure, and obviously it's a national security issue, and I can't speak more to that. The other thing on SMEs quickly, so last week we published a new website for SMEs, for them to literally go and use the tools on that website to assess their own vulnerabilities and has specific information, guidance, and tools for small and medium enterprises. Because it's a key sector in the economy. It's a hugely vital sector. It employs hundreds of thousands of people, but these organizations often lack the scale and complexity to have the type of cyber defenses that larger organizations have. So we're building tools, and there will be more to come on that website, specifically for SMEs. We'd encourage anybody, even a larger enterprise, to look at that and see what's there. To the Senator's specific point on the support scheme, again, for those of you who aren't aware, we ran a pilot scheme over the last two years for SMEs with Enterprise Ireland, adding on to an existing scheme that they had. The pilot's closed. It has fully dispersed all its funding. There's a commitment in the program for government for a new scheme. So we've already had huge amounts of learnings from that scheme. The new scheme will be very different when it emerges. And I think the Senator's comments will be fully met when he sees the final scheme. Just one very quick last one. I know you're highly regarded in Estonia. I've been out there a number of times. And you'll be aware of the fact that the Estonians have appointed a full-time cyber ambassador working within the country. How does that assist your organization? The idea of having a cyber ambassador is actually the Estonians were one of the first. I'm not sure if they were the first. Quite a few European states have one. And the simple answer here is that if I was given a person of that rank, that's not where I'd put them. So, great. But for any additional capability, I'll find a better home for it. Foreign Affairs here already do a really good job in coordinating our international engagement on cyber. They have, in fact, moved more staff into that area very recently. Not even because of the presidency, just in general. And they also play a key role in our engagement with the UN. So we deal with, from an NCC perspective, with the OECD, with NATO, with a number of other bodies. But the global piece is Foreign Affairs, and they actually do a really competent job, as you'd expect. I'm talking more about internally within the country. We have an engagement team led very ably. And that does a huge amount of work with not just critical infrastructure, but across the sector. We have delegations in internationally all the time, including one today, talking about this stuff. So we're in a very strong position. Thank you for all you do. Thank you.