Rose Conway-Walsh: Defence Cyber Readiness and EU Presidency
Rose Conway-Walsh questions cyber security officials on defence force secondments, public awareness, skills supply and preparedness for Ireland's EU presidency. She probes links with the Tallinn Centre of Excellence, plans for a national cyber centre, and the limits of readiness against unpredictable attacks.
Rose Conway-Walsh asks about secondees between the defence forces and the National Cyber Security Centre and hears that a secondee from Joint Cyber Defence Command is attached into the Centre of Excellence in Tallinn, Estonia. The exchange highlights practical training and international expert access provided through these links.
The discussion stresses proportionality in public messaging. Officials note that many personal risks relate to fraud and scams and are a matter for Gardaí and public guidance, while the NCSC focuses on systemic risks to critical infrastructure, government services and society.
Speakers outline progress in higher education with expanding cyber, legal and compliance courses and confirm a programme for government and NDP commitment to a national cyber centre of excellence. The first steering group meeting was held this week and skills measures will feature in the next national cyber security strategy.
Preparedness for the EU presidency is described as robust but never complete. Officials explain ongoing exercises, recruitment activity and realistic tests run as if incidents were live, while warning that unusual, large-scale or novel incidents remain possible.
A recurring point is the need to plan for low-probability, high-impact events. Officials refer to the possibility of a 'black swan' incident during major periods such as the EU presidency and describe live exercises designed to test response under imperfect conditions.
Defence forces secondments and international links
Rose Conway-Walsh asks about secondees between the defence forces and the National Cyber Security Centre and hears that a secondee from Joint Cyber Defence Command is attached into the Centre of Excellence in Tallinn, Estonia. The exchange highlights practical training and international expert access provided through these links.
Public awareness and proportionality
The discussion stresses proportionality in public messaging. Officials note that many personal risks relate to fraud and scams and are a matter for Gardaí and public guidance, while the NCSC focuses on systemic risks to critical infrastructure, government services and society.
Skills pipeline and a national centre of excellence
Speakers outline progress in higher education with expanding cyber, legal and compliance courses and confirm a programme for government and NDP commitment to a national cyber centre of excellence. The first steering group meeting was held this week and skills measures will feature in the next national cyber security strategy.
EU presidency preparedness and scenario testing
Preparedness for the EU presidency is described as robust but never complete. Officials explain ongoing exercises, recruitment activity and realistic tests run as if incidents were live, while warning that unusual, large-scale or novel incidents remain possible.
The risk of the unpredictable
A recurring point is the need to plan for low-probability, high-impact events. Officials refer to the possibility of a 'black swan' incident during major periods such as the EU presidency and describe live exercises designed to test response under imperfect conditions.
We publish thousands of recordings to make Irish politics transparent and resistant to manipulation. Spotted an error? Report it — together we are building a reliable archive of Irish politics.
Other speeches
Rose Conway-Walsh: Calls out dereliction as shops lie empty
Rose Conway-Walsh warns medical-card dental services collapse in Mayo
Rose Conway-Walsh urges faster flood works for Mayo
Rose Conway-Walsh Demands Committee Remit for National Security
Rose Conway-Walsh demands answers on insurance and appeals delay
Rose Conway-Walsh: Calls for Action on Cross-Border Third-Level Education
Tego samego dnia All speeches from this day →
Victor Boyhan
Victor Boyhan: Public lands first, no farm severance
Carol Nolan
Carol Nolan: Calls for action as hospitality sheds 20,000 jobs
Sinéad Gibney
Sinéad Gibney: Stop the Game, End Government Inaction
Richard Boyd Barrett
Richard Boyd Barrett: Ban State Funding for Firms Trading with Israel
Gerard P. Craughwell
Gerard P. Craughwell: Bill is Populist and Unworkable
Mary Lou McDonald
Mary Lou McDonald: Condemns Belfast Knife Attack, Demands Justice
Transcript
I want to ask you two quick things, in relation firstly to your co-operation with the defence forces themselves, does the joint cyber, do you have secondment from the defence forces into the cyber and vice versa? Right now we don't have a secondee with them, we have for, sorry I couldn't tell you off the top of my head but it's at least four years, we have a secondee from joint cyber defence command as is now, previously CIS core, into us and onwards to the centre of excellence in Tallinn in Estonia, so we hold that engagement with that centre of excellence and the defence forces con someone to us which we then second on to that organisation, it's fitting because many of the people, not all are in uniform in that place, it allows the defence forces access to a global class community of experts in this kind of military cyber defence and also allows us then that global contact and frankly access to really good training as well which is invaluable. Would you like to see that developed more or is that sufficient for the moment? It's actually sufficient for the moment, for us the challenge always is making full use of that access, which we're continually trying to iterate on and develop. Okay, good. And just in terms of public awareness, what else do you think can be done in public awareness to mitigate some of the risks? That's a really good question chair, I think the real question is the proportionality piece. So we have no obvious interest in trying to scare people or trying to frighten people. Many of the issues and risks that arise at a personal level are really more related to your own personal security against fraud and scams, that's an issue for the Gardaí and us and lots of other people and we provide information, guidance, support around those kinds of issues. For us the key risks that we deal with are to critical infrastructure, to government, to services and then to society as a whole and the work we do is largely aimed at those kinds of systematic or systemic risks. That's not something that individuals really need to concern themselves with unless they obviously want to, but at the same time aspects of those risks then feed back into individual lives. So for example, the work that the Office of Emergency Planning do around having people be prepared for crisis on an individual level, the booklets that are recently circulating, those also apply to us. So the types of incidents we might see could end up in a more general national issue, crisis is a bit strong of an issue and if people are prepared to deal with a transport or weather crisis, then by default they are more resilient against cyber crisis as well. We have a sufficient number of qualified students that are coming through the HEIs to be able to build up our own capacity and to have the expertise that we need, not only for yourselves but within government departments as well. I'll give you a three part answer to that chair. Part one, globally there's a huge shortage of cyber security skill sets, particularly in the higher order element of all of this, which is the world unfortunately in which we exist. There are substantial challenges across Europe and America dealing with these kinds of issues. Second part, however, we've made huge steps forward here in the last five years, six years. We now have not just technical cyber security courses in most universities and HEIs, but we also have diversified legal compliance and other associated courses starting to emerge. So we're almost organically in a very strong position just because of how close our universities are to industry and how adept they are at flexing and adapting to what the market demand is. The third part of the answer is that we have, as part of the programme for government and in the NDP, a commitment to building a national cyber centre of excellence, the first steering group meeting on that was held this week in our building. So we're working on that process, which will be further explained in the next national cyber security strategy and will also include measures around skills and those kinds of developmental issues. But the good news is it's happening already. So what the state can do now is look further ahead at the next generation of skills that we'll need. And the deputy's question about AI is a really pertinent one in that context. Okay. Very good. So we can take it from today's session, really, that in relation to the EU presidency, that you have a high level of preparedness and that you have everything you need to be able to do what needs to be done when you've scoped the risks and the incidents that have happened in other member states that have held the EU presidencies, is that? I'll give you another three part answer, Chair. Part one, yes, we've heavily evaluated what's happening. We've benchmarked where we are with regard to other member states and we believe we're in a fairly strong position. Do we have all that we need? I will never say that. I will always take more, which is what you'd expect. But at the same time, we're in a relatively robust position and we're recruiting again, as in we'll have ads in the paper on Friday, maybe Thursday if we're lucky. The third piece is that I will just say that the bad guy gets a voice too. And while we think we understand the risks in a fairly complete way, there is always a possibility that something unusual will happen, that we'll get an incident type that we haven't seen before, that we'll have a large scale incident during the presidency that is adeptly targeted to cause us particular problems. The question for us, and again, we have an exercise ongoing today in the NCSC, we're playing in cyber Europe, which is the European EU led cybersecurity piece, and we're playing this as if it was a live incident. So we haven't cancelled anybody's annual leave, we're running it on the basis of who we have in the building on the day, with a couple of critical infrastructure operators in their own building and people in other parts of the world. So we're playing this to test genuinely how we would do in a real life crisis, because we can't predict what will happen. We can have a fairly good go at it, but we're never going to be 100% precise. And we could get something completely out of the blue, a black swan, so we have to be ready for that too. Yes, the dreaded black swan. Okay.