We use Google Analytics to see which pages are read and how the site is used, so we know what to improve. This only runs if you accept. See our privacy notice for details.

Dáil
‹ Questions on Promised Legislation

HSE cyberattack response

Summary

Deputy Kelly seeks urgent preparation for threatened publication of HSE data and asks for public information and a helpline. Minister Ryan outlines a confidential helpline and wider measures, and confirms Tusla and child protection systems are also being addressed.

In the last few minutes, The Irish Times journalist Conor Lally referred to Bloomberg reports that those who have hacked into the HSE system are threatening to publish a mass amount of data online by next Monday, 24 May. The Minister may not be aware of this. What are we doing to prepare for this? The Minister, Deputy Ryan, organised a meeting yesterday with key Departments, and I thank him for that, but we all need to see a plan. What are people who are watching today, or those working for the HSE, to do when they have questions? We need an information line and we need information online. This is rapidly turning into a national security crisis for our country. What is the plan?

I presume that a vulnerability assessment and penetration test, VAPT, is being done by the National Cyber Security Centre, NCSC, or is being organised by the NCSC across all State bodies and Departments to ensure they are not hacked also.

Comment on this

I ask the Leas-Cheann Comhairle for a slightly longer time to respond to this question, because it is an important issue, and to give me a bit of time to explain. A lot of people are concerned.

Comment on this
Catherine Connolly An Leas-Cheann Comhairle Independent

It might come up again.

Comment on this

I very much appreciated the meeting we had yesterday where Deputy Kelly and other Deputies were briefed by An Garda Síochána on the cybersecurity system issue, which is of huge consequence for our health system, for individuals and for families. Subsequent to yesterday's meeting, the Minister for Justice, the Minister for Health and I had a meeting yesterday afternoon. We took up some of the suggestions from our earlier meeting. We will establish a helpline, which will be a confidential crime-line type system, for people if they are in any way approached. We must be careful about some of the rumours around this, which is full of subterfuge and all sorts of unknowns. If a person is approached by anyone claiming to have medical or other relevant data, we will provide a crime-line type confidential system where the person can get safe advice on what he or she needs to do. The Government Information Service will provide details on this later on. That advice line will also help to give us information on the information being published. I will come back to the issue if there are further questions.

Comment on this
Catherine Connolly An Leas-Cheann Comhairle Independent

Each topic is equally important to the Deputy tabling it. There are other ways of dealing with the more serious issues or those issues that need more time.

Comment on this

Tusla and its systems have also been shut down as a result of this cyber attack. I welcome the discussions the Minister is having about the HSE but it feels to me that Tusla and child protection issues are being forgotten in this debate. Concerns have been raised by social workers in the media today that the shutdown means child protection risk issues and the risk of very sensitive child abuse documentation being breached and leaked to the Internet. I tried to get the Business Committee to bring in the Minister, Deputy O'Gorman, next week to discuss this, but it refused to allow that, which is very unfortunate.

As the Minister with responsible for the cybersecurity centre, has he been specifically briefed on child protection risks and the impacts on Tusla? When does the Minister believe the Tusla system will become active again?

Comment on this

Yes is the answer to that. We have engaged constantly since last Friday morning. There is a whole range of different issues of real concern. Absolutely centre stage in that is Tusla and its information systems that were connected to the HSE networks.

To go further in response to Deputy Kelly, our second measure is to contact our media and social media companies to say that if anyone propagates any information, some of which is most sensitive, and which is a real possibility, on the dark web or other such sites, that we do not further propagate it or share the information and that we do no further damage or increase any harm that would be done. If someone has the data it is impossible to stop the release of it completely. There is a range of different sites and one cannot completely stop it. However, we can minimise and protect to the best of our ability by reducing the sharing of that information. That is one of the further elements we need to do.

Comment on this