Brian Stanley: Defence and Gardaí Cooperate on Cybersecurity
Brian Stanley questions officials on Ireland's cyber readiness ahead of the forthcoming EU presidency, asking about cooperation with the Defence Forces' Joint Cyber Defence Command and the Gardaí. The speaker confirms a high level of two-way cooperation, discusses the HSE incident response and the regulatory handover under NIS2.
Cooperation across agencies
The exchange details active collaboration between national cyber bodies, the Joint Cyber Defence Command and relevant Gardaí units, including the SDU. The witness explains that exercises are shared and that personnel operate both on-site and from their own facilities, reflecting a reciprocal partnership aimed at strengthening national cyber resilience.
HSE incident and regulatory action
On the HSE attack, the speaker clarifies that criminal investigatory matters remain with the Gardaí while national authorities used NIS1 powers to issue a compliance order in 2022 based on PwC findings. That compliance order has run its course; remaining elements will transfer to the incoming NIS2 regulator later this year as part of the regulatory transition.
Intelligence collection, IoT and new EU rules
The witness frames intelligence collection as a category of cyber risk and stresses practical mitigations for individuals and organisations, such as multi-factor authentication and encryption. They warn that many Internet of Things devices are poorly policed and rarely patched, creating broad exposure. The transcript also flags the upcoming transposition of the European Cyber Resilience Act from September, which will impose security obligations on vendors selling into Europe.
Attribution and geographic origin
On attribution, the speaker explains that tracking tools, tactics and code often allows teams to identify those behind incidents and sometimes provides precise geographic detail; however, attribution varies by case. The speaker notes that the vast majority of attacks observed are from outside the European Union.
Cooperation across agencies
The exchange details active collaboration between national cyber bodies, the Joint Cyber Defence Command and relevant Gardaí units, including the SDU. The witness explains that exercises are shared and that personnel operate both on-site and from their own facilities, reflecting a reciprocal partnership aimed at strengthening national cyber resilience.
HSE incident and regulatory action
On the HSE attack, the speaker clarifies that criminal investigatory matters remain with the Gardaí while national authorities used NIS1 powers to issue a compliance order in 2022 based on PwC findings. That compliance order has run its course; remaining elements will transfer to the incoming NIS2 regulator later this year as part of the regulatory transition.
Intelligence collection, IoT and new EU rules
The witness frames intelligence collection as a category of cyber risk and stresses practical mitigations for individuals and organisations, such as multi-factor authentication and encryption. They warn that many Internet of Things devices are poorly policed and rarely patched, creating broad exposure. The transcript also flags the upcoming transposition of the European Cyber Resilience Act from September, which will impose security obligations on vendors selling into Europe.
Attribution and geographic origin
On attribution, the speaker explains that tracking tools, tactics and code often allows teams to identify those behind incidents and sometimes provides precise geographic detail; however, attribution varies by case. The speaker notes that the vast majority of attacks observed are from outside the European Union.
We publish thousands of recordings to make Irish politics transparent and resistant to manipulation. Spotted an error? Report it — together we are building a reliable archive of Irish politics.
Other speeches
Brian Stanley on civil defence funding, volunteers and frontline gaps
Brian Stanley: Infrastructure is blocking housing in County Leish
Brian Stanley presses for action on Port Arlington school delay
Brian Stanley: Government Enabling Environmental Destruction
Brian Stanley: Private Rentals, Damp and Rising Rents
Brian Stanley: Fix Rural Housing with Village Service Sites
Tego samego dnia All speeches from this day →
Helen McEntee
Helen McEntee: Introduces Bill to Ban Imports from Settlements
Sharon Keogan
Sharon Keogan: IMF Warns AI Could Hit 40% of Irish Jobs
George Lawlor
George Lawlor: Tourism is Rural Ireland's Lifeline
Ann Graves
Ann Graves: Stop Israel Sporting Fixtures - No Games!
Rose Conway-Walsh
Rose Conway-Walsh: Occupied Territories Bill Fails to Include Services
Rory Hearne
Rory Hearne: Why Ireland Must Include Services in the Bill
Transcript
...and the opening statement. Could I just ask, obviously with the forthcoming EU presidency is the big issue and as you outlined that you're expecting in line with what's happened in other states that there would be a high level of, or a higher level of attempted cyber attacks during that period or cyber incidents. I'm just wondering that in relation to the level of cooperation with the defence forces and particularly the Joint Cyber Defence Command, you know, is there a high level of cooperation there in terms of partnership with them? And just in relation to, because it's a bit of an unusual situation in this state, in terms of the SDU, Special Detective Unit, is there a high level of cooperation there as well? I've got a few questions, so I just think, I don't want to be patronising you, we'll just try and keep the question very short. The answer to both is yes, Deputy. We have a very high level of cooperation with all sides of the defence forces and the Gardaí that are relevant, cybercrime and various other parts of Gardaí Síochána. Would it be primarily the SDU, would it? More so than the defence forces? It's both, it goes equally both ways. So for example, you mentioned Exercise Eireann earlier on, we had defence force officers from the Joint Cyber Defence Command playing in the exercise on site, but also playing in their facilities as well. So we work both ways, we play in their exercises, they play in ours. And tell me, just in relation to the big attack in terms of on the HSE IT systems, and I know you're not the investigation authority, but that's more or less reached a conclusion now, is it? I can't... Determinations have been made, would that be right? So in terms of the actual, the criminal investigation, I can't speak to that, that's a matter for the Gardaí. Obviously we have an involvement in it, but we're not central to it. I know. But in terms of the HSE's own response, yes, but it's a process that will likely continue for a very long time, given how complex and multivariate the problem is. I'll just, just one more sentence on that. So we conducted, using our own regulatory powers on, under the NIS1 legislation, we levied a compliance order against the HSE in 2022, based on the outcome of the PwC report and our own assessment of the piece. That compliance order has run its course, but in the context of NIS2, there will be a new regulator taking up the role of regulating HSE, and we will pass the remaining elements of that compliance order to them later on this year, when they take that on and become effective and implemented. And obviously, you know, that in relation to the context of the war in Ukraine and other geopolitical situations and military, you know, there would be obviously a high level of concern about certain countries. But just in terms of that, I recall that about 20 years ago, there was a big, there was a lot of, a lot of information coming out that, that in relation to infrastructure connecting this country to England, and particularly to GCHQ. Do you offer advice on how to monitor that, in terms of, say, the Special Detective Unit and to the, and to the Defence Forces? So the, there was an ongoing, there was an ongoing process for over a period of time. So I mean, the answer to that question, Deputy, becomes complicated very quickly. Intelligence services, the world over, collecting... Sorry, you just left me in, it's very complicated. So the answer to this is levels, and it has multiple different layers to it. So one of our primary roles is to defend people against cyber aggression, to deal with cyber risk. And intelligence collection is categorically a cyber risk. The types of tools used by intelligence agencies, like the one you mentioned, will be vast in their scale, given their budgets. And they operate, as you'd expect, at a very high technical level. There are things that everybody can and should do, generally speaking, as part of their day-to-day lives, that will mitigate many of those kinds of tools, like multiple-factor authentication, using encrypted services wherever possible, and so on. But ultimately, for very high-order threats like that type of activity, it's almost impossible to deny every single avenue of opportunity. Really, really good operators will get information thereafter. It's unfortunately in the nature of things. But more generally speaking, at a national level, the types of things we do to deal with general criminal activity, in terms of advice, guidance, support, our own technical means, the means we use to build resilience, also function against higher-order threats. So if you're making sure that you're dealing with the basics to deal with criminal activity, by default, you're also taking measures to deal with other kinds of intelligence collection and similar activity. I'm going to ask that just in relation to the procurement issue and the origin. I mean, there was concern here in this complex a couple of years ago in relation to the origin of CCTV, the CCTV system. Do you have a role in terms of advising on that, specifically that type of equipment? Right now, we don't. So we have a formal role with regard to telecoms and telecom security. We provide advice, guidance and support, and we've published repeatedly on public procurement. But it doesn't deal with country of origin questions of this kind of order. There is obviously a risk-based question for anybody procuring, and our advice puts this to the vendor, so to the procurer, to ensure that they are properly managing the risks to their own infrastructure and their own privacy and security questions. The specific issue we're dealing with, Deputy, is really a subset of a much larger set of questions about any kind of Internet of Things device. So again, for everybody's information, Internet of Things is the terms used to describe any small-scale IP-connected device. It could be a security camera that brings obvious risks, Deputy, but it could be anything like a DVR that sits on top of your television or underneath your television. It could be a, I don't know, any kind of connected device, a child's toy, anything. Those devices, by their very existence, they're poorly policed, they're very rarely patched, they pose a risk to everybody, and I can explain what those are if you really want. A piece of legislation coming in here starting in September but rolling into next year is the transposition of the European Cyber Resilience Act, which is a whole other piece of legislation. That will oblige vendors selling into Europe to meet certain European security requirements. And that's an example of a really comprehensive approach to dealing with this. Rather than just fixing that one problem, you fix all of the issues at once. And just one short final question. In terms of where you detect that there's a cyber attack, is it difficult to determine, you know, what is the country of origin of that attack or where it might be directed from, where it's directed from? The origin could be Europe, but where it's directed from is the question. Is that difficult? That's a really good question, and the honest answer is it depends, Deputy. So in many cases, so very rarely do we see a cyber attack from which we've never heard anything about it before. So we have an entire team in the organisation that's dedicated to tracking and understanding who's doing what right now and using what tools. So when we see a tool in use, a piece of code, a tactic, a technique, we can then track back from that as to who's using it. That means that for the very most part, when we see an incident, we understand relatively quickly who is ultimately behind it. In many cases, that gives us a geographical location and in some cases, even a building. So not in every case, but in many cases, we can be very precise with where it's emanating ultimately from. Will most of it be outside the European Union? The vast majority is outside the European Union. Outside the EU. Thanks.