We use Google Analytics to see which pages are read and how the site is used, so we know what to improve. This only runs if you accept. See our privacy notice for details.

Joint Committee on Artificial Intelligence

Artificial Intelligence, Defence, Security and Cybersecurity: Discussion

Summary

The committee examined how AI is changing defence and cybersecurity in Ireland, with witnesses stressing that AI is both a tool and a threat. The NCSC said AI is already speeding up phishing, malware, disinformation and vulnerability discovery, while the Defence Forces outlined their cyber role, limited current AI use, and the need for human accountability and ethical controls. There was a sharp exchange on governance, with concern that AI Act delays and weak regulation leave states exposed to tools like Anthropic’s Mythos, though officials said criminal and state actors will use such tools regardless of rules. The session also covered incident response, dark web monitoring, staffing pressures, and the need for stronger national resilience.

Malcolm Byrne An Cathaoirleach Fianna Fáil

Everyone is welcome to this morning's meeting. As there are other committees on, some of my colleagues will be coming in and out during the course of this meeting. We look forward to a very important and interesting session today on artificial intelligence defence, security and cybersecurity. I thank Senator Murphy O’Mahony who is substituting for Senator Ryan. I am sure the representatives here are aware of both the constitutional requirement that they must be physically present and the evidence of witnesses.

I am grateful to everyone for coming along today. When we saw so many senior people in uniform arriving in so early this morning, I remarked that the conspiracy theorists would have all sorts of notions as to what was going on. We are discussing this very important topic. We are pleased to be joined from the National Cyber Security Centre by Dr. Richard Browne, director, and Ms Imelda Casey, who I think it is fair to say was largely responsible for the national strategy on cybersecurity; from the Department of Defence by Mr. Jason Kearney, director, Mr. Liam Morrow and Mr. Derek Byrne, principal officer in the information and communication technologies branch in the Department. The communications and information services corps of the Defence Forces is represented by all three branches of the Defence Forces. We are joined by Brigadier General Mark Staunton, commander of the Defence Forces joint cyberdefence command, Commander Brian Matthews and Lieutenant Colonel Michael Cullen, both of whom are JCDC communications and information service specialists.

I welcome all our witnesses today. Our committee is looking at the impact of AI on defence and cybersecurity. It is trying to see what are the challenges facing Ireland, how we should respond, if there are specific opportunities, and to make recommendations to the Government in that regard. There is an agreed order in which people will speak. I invite the witnesses to deliver their opening statements.

Comment on this
Dr. Richard Browne

I thank the committee for the kind invitation here today. I am accompanied by Imelda Casey. She was largely responsible for the creation of the national cyber risk assessment document, which is perilously out of date at four months old but it is the basis of a lot of our work on AI and cybersecurity. The mission of the NCSC is to manage cyber risk to Ireland. We do this by conducting operations across a number of fronts, including defending systems and networks in the State and monitoring, detecting and responding to threats in the cyber domain.

We as a society are all used to coming to terms with everyday technological developments. For years it has been the case that something comes along and rapidly becomes part of our lives in a relatively seamless way.

Artificial intelligence is not one of those everyday developments. It is genuinely revolutionary. It is a generational change that will affect every other digital technology that has gone before and, because of the universal nature of Internet-connected devices, it has had immediate and widespread adoption.

The implications of all of this for cybersecurity are, therefore, vast and inherently unpredictable. The latest national cyber risk assessment, which was published by the Minister, Deputy O'Callaghan, in December of last year, outlines how AI is a driver of systematic risk, increasing the speed, scale and sophistication of cyberattacks. The challenge before us as a state is not whether to adopt AI, but how best to do so safely and securely, how to manage the ongoing incorporation of AI into the widely used defensive toolsets we rely on collectively to protect IT systems, and also how we adapt to these tools being used by attackers.

The simplest way of considering this is on the three Ts basis - on AI as a tool, AI as a threat and AI as a target in and of itself. AI technologies offer huge promise in improving and automating cyber resilience and defence tasks, particularly in improving response capabilities, automating vulnerability identification and enabling the real-time detection and even response to threats. The cybersecurity industry is being revolutionised by a rapidly developing swath of agentic AI solutions on the response side. Some of these are entirely new, and others are embedded in existing offerings. Furthermore, the traditional task of identifying and fixing vulnerabilities is being revolutionised. Recent announcements by Anthropic about Mythos are a case in point, and I am sure we will come back to that in great detail.

However, this is not entirely a good news story. Threat actors are already heavy users of AI tools across our familiar spectrum of hacktivist, criminal and state actor. There are limitations at present to the effectiveness of AI tools for conducting every stage of a cyberattack autonomously. Just to break that for a moment, that was the case when this was written last week, but this week, the situation is already slightly different. However, these limitations are waning as the technology develops.

Thus far, the primary use case of AI has been as a force multiplier or enabler that allows attackers to optimise existing methods and increase the scale of their operations, thus lowering the cost of action or the cost of entry. This, in turn, has effectively democratised access by collapsing the technical and even linguistic barriers to conducting an offensive AI action. However, this is likely just a waypoint in a much longer journey. AI tools, particularly the agentic technologies referred to above on the defence side, are allowing for greater automation of the attack processes. There is some evidence that this is already appearing in the wild, and in the hands of state actors.

Our third priority involves the need to secure AI systems themselves as they are deployed. AI deployments expand the attack surface and are increasingly embedded in the critical infrastructure that must be protected. Recent reports of AI supply chain breaches underscore these vulnerabilities. We cannot afford to treat security as an afterthought. No matter how promising an AI system is, its value depends on how securely it is built, deployed and, critically, managed.

What does this all mean? So what? It means we are in a race, whether we choose to accept it or not. The technical frontier is moving ahead, week by week, and the role of managing cyber-related risks to society and the economy is becoming far more dynamic. It also means that we have the potential for an AI gap to emerge between those organisations, or potentially states, that can adapt to these new environments and those that cannot, or at least not quickly enough. At EU and national level, the system is adapting to these emerging realities. The Government published a new national digital AI strategy in February that brings these two strategies together for the first time. It sets out a comprehensive national approach to managing this transition, and cyber is embedded throughout this strategy, both in the AI part and the digital elements. More specifically, the Department of Justice, Home Affairs and Migration will shortly start a consultation process on the next national cybersecurity strategy. That will set out in a more specific way how we propose to manage these risks at a national level. From an NCSC perspective, we will shortly publish a new AI risk assessment, and that will be followed, in turn, by revised guidance on the secure deployment of AI in the public sector.

Comment on this
Mr. Jason Kearney

I thank the Cathaoirleach and members of the committee for the invitation to appear today. I am the director of the emergency operations and infrastructure oversight division within the Department of Defence. I am joined today by Brigadier General Mark Staunton, the commander of the Defence Forces joint cyberdefence command centre. He will present on the Defence Forces’ role and functions in the AI and cybersecurity field. I am also joined by my colleagues, Derek Byrne, principal officer with responsibility for IT operations and cybersecurity, and Liam Morrow, who is also responsible for business applications and overall AI policy.

As the committee will be aware, the rapid evolution of digital technologies, especially the rise of accelerated generative AI, has raised significant new opportunities, and also presents new challenges for the Department. The new digital AI strategy, referenced by Richard earlier, was launched in February. It recognises the potential of the digital and AI revolution to deliver effective and modern public services. To this end, the Department is committed to the adoption of new technologies while also continuing to prioritise ICT security and develop a culture of cybersecurity awareness to improve our resilience as an organisation.

In the area of cybersecurity, AI is fundamentally changing the threat landscape and is increasingly being used in both cyberattacks and cyberdefence. In this area, the Department is working with our ICT partners to enhance our security posture and protect our digital assets while also supporting our colleagues with appropriate training and policy advice to ensure adherence and the responsible use of AI. The response to cyber threats remains a whole-of-government challenge, as referenced by Richard earlier, with the Department of Justice, Home Affairs and Migration taking the lead role, through the National Cyber Security Centre, NCSC, and with inputs in the security domain from An Garda Síochána, the Defence Forces and the National Security Analysis Centre, NSAC.

Colleagues in the Department and the Defence Forces work closely with the Department of Justice, Home Affairs and Migration and the NCSC to support measures to deal with cyber challenges. The Department’s core IT infrastructure is provided by the Office of the Government Chief Information Officer under the "build to share" managed desktop applications. We work closely with that office to improve a multilayered, defence-in-depth security strategy.

The Department is well advanced in the implementation of its five-year technology strategy and roadmap for 2023 to 2027. Adoption of new technologies including AI, leveraging data as an enabler, embedding high-quality cybersecurity tools and procedures and developing ICT skill sets across the Department is one of the key strategies of the document. The Department has established an AI working group that is responsible for guiding the responsible use of AI across the Department's functions, identifying potential use cases, supporting staff with upskilling and ensuring that AI practices adhere to ethical and governance requirements.

The Department has implemented an AI policy that is guided by national and EU regulations and the guidelines for the responsible use of artificial intelligence in the public service. Our policy defines acceptable and prohibited uses of AI, and outlines colleagues' obligations in the use of AI and the development of AI systems. The Department has rolled out AI training for all colleagues and completion of training is mandatory before access is granted to AI tools. In recent months, Microsoft Copilot in Teams has been rolled out as an AI assistant for staff. We have also introduced the first pilot AI project with the introduction of a retrieval-augmented generation tool to support staff in answering questions on internal departmental documents.

Building and maintaining public trust is critical to the Department as it adopts emerging AI technologies. I thank the committee again for the invitation to attend today. I will now hand over to General Mark Staunton for his opening remarks.

Comment on this
Mr. Mark Staunton

I am the commander of the Defence Forces' joint cyberdefence command, JCDC. Following on from directors Browne and Kearney, I too wish to thank the members of the committee for the invitation and welcome the opportunity to give the Defence Forces' perspective on AI, defence, security and cybersecurity. I am joined today by two colleagues, Commander Brian Matthews and Lieutenant Colonel Michael Cullen, from the Naval Service and the Air Corps, respectively, both of whom are JCDC communications and information service, CIS, specialists.

Acknowledging the policy mandates of the Departments of Defence and justice, and the leadership responsibilities of An Garda Síochána and the NCSC for security and cybersecurity within the State, the Defence Forces are responsible for the military defence of the State across all military operational domains, namely, land, sea, air, space and cyber. One of the key challenges in delivering military effects across operational domains is the maintenance of command, control, communications, computers and intelligence, known as C4I, in the command and control of Defence Forces operations.

Inherently, JCDC, in the provision of C4I systems to enable the command and control of Defence Forces operations, also provides communications and information services to underpin the efficient administration of the Defence Forces. Additionally, JCDC is charged to conduct full spectrum cyberspace operations in support of Defence Forces operations at home and overseas, to enhance national cyberdefence resilience and to provide a contingent capability.

JCDC employs an extensive range of CIS solutions and technologies which can be characterised as military, tactical or business enterprise, and Defence Forces cyberspace can be conceptualised as encompassing IT and digital, electromagnetic and cognitive elements. The Defence Forces JCDC CIS digital and cyber solutions currently include limited integration and employment of machine learning and embryonic utilisation of AI to date, although as commander of JCDC, I am charged with continuously assessing emerging trends across the cyber domain and to advise the Defence Forces Chief of Staff and deputy chief of staff operations accordingly.

In that context, JCDC remains proactive in considering the appropriateness of incorporating AI into military capabilities, as an essential enabler but also in understanding the layered utility of AI in protecting Defence Forces networks. I appreciate I have only had a very short opportunity in this opening statement to touch on a small number of issues but I look forward to any questions members may have. I hope I will be in a position to answer any questions that fall within the remit of the Defence Forces. I thank the Chair.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I thank the brigadier general. I am conscious that we have many acronyms and titles, so if individuals are happy using first names, there will be no disrespect if anyone gets a title wrong. Members who are here have seven minutes for questions and answers. I know Senator Clonan is not a member but he is welcome to join.

Comment on this

I feel a bit weird using first names for now so I will stick with titles, if that is okay.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

That is okay.

Comment on this

I thank the witnesses for being here and for the work they all do. I apologise in advance as I will have to leave soon after asking my questions but I will watch the full session later. We are having such an important discussion today. I want to touch on a few issues, whether or not I get the time to cover everything. Starting off, the brigadier general spoke about the joint cyberdefence command. One of the things he did not touch on in his opening statement is something that has been reported about the function of the JCDC, which will be offensive cyber operations. What does that look like? Can he briefly give me a little bit more information on the transition from communications and information systems to the JCDC?

Comment on this
Mr. Mark Staunton

In relation to offensive cyber operations, in NIS2, one of the key tenets is calling out member states of the EU to deploy active cyberdefence measures. A range of functionality is associated with that call, including detection tools for deployment, the whole area of takedown measures that can be employed and, additionally, the whole area of threat intelligence sharing. They are all called for by NIS2, which is about to be transposed into law in the Irish jurisdiction.

Comment on this

They are what the brigadier general is talking about in terms of offensive cyber operations?

Comment on this
Mr. Mark Staunton

These are active cyberdefence measures that are mandated from an EU perspective, which are about to be transposed into Irish law in the national cybersecurity field.

Comment on this

Are they offensive cyber operations?

Comment on this
Mr. Mark Staunton

They are active defence measures.

Comment on this

Are they offensive cyber operations?

Comment on this
Mr. Mark Staunton

It depends on the Deputy's interpretation of active defence versus-----

Comment on this

That is what I am looking for. Even if it is not the specifics, what does offensive cyber operations mean to Mr. Staunton? How can he define that for me, as quickly as he can, because I have a couple of other issues I would like to raise?

Comment on this
Mr. Mark Staunton

Take-down of a command and control server in another jurisdiction.

Comment on this

That would be an offensive cyber operation.

Comment on this
Mr. Mark Staunton

That would be an offensive operation.

Comment on this

I refer to the transition from communications and information to the JCDC.

The brigadier general touched on this a little. I ask him to flesh it out a little further.

Comment on this
Mr. Mark Staunton

JCDC has three pillars, in effect. They are communications information services, cyber and digital. I have teams operating in all three pillars. None of them are mutually exclusive; they will complement each other in terms of service delivery. The CIS networks we typically deploy depend not only on CIS specialists to deliver the networks but also cyber specialists to secure those networks. This also applies to digital SMEs in respect of some of the applications we deploy and the transformation measures we are employing in the context of delivery of Defence Force operations and the efficient administration of the Defence Forces.

Comment on this

That is very helpful. I thank Mr. Staunton.

I will move to the Department and the other two groups. They touched on Anthropic's Mythos, which is a complete game-changer and is putting fear into a lot of people right now. It raises serious concerns about governance. Where I go to in all of this is the governance of AI. Reference was made to safe implementation and usage. Governance is how to make sure implementation, usage and regulation is done in the appropriate way. Why are we not pressing for the rapid application of the AI Act provisions on high-risk systems? Why instead are we as a State supporting the delay of those AI Act provisions for another year until August 2027? Has the State been in discussions with Anthropic over any of this? Dr. Browne and the Department can comment.

Comment on this
Dr. Richard Browne

The long and the short of it is that the AI Act is a matter for the Department of Enterprise, Trade and Employment. That is not our remit and we cannot comment on it specifically. To be clear, Mythos is not a cybersecurity-oriented model. Rather, it is a model that happens to have very specific capabilities when applied to certain cybersecurity problems. What the company has done, and very wisely in this context, is that it has not just released Mythos, but has allowed access to a small number of very important companies to test their systems using Mythos to remove vulnerabilities. The issue is not necessarily that Mythos exists. Rather, it is the fact that it demonstrated this capability is possible.

Comment on this

I refer in particular to governance. Does the Department have any answer on AI risks?

Comment on this
Dr. Richard Browne

I will finish on that. The issue is not necessarily about Mythos.

Comment on this

I know. I am coming at this from a more cynical perspective because I do not believe in the goodwill of the company. I believe it is engaged in a PR exercise in doing what it is doing right now in raising the profile of the system.

Comment on this
Dr. Richard Browne

The Deputy is not being cynical enough. The problem fundamentally-----

Comment on this

That is fine, but Dr. Browne cannot answer on the AI Act in which I am particularly interested. Does the Department have any position on the Act? Why are we not pushing for the high-risk provisions in the Act and its implementation?

Comment on this
Mr. Jason Kearney

We do not have a position on that principally because the primacy of this area comes under the remit of the Department of justice and we are on Dr. Browne's side of the house. I am not ducking.

Comment on this

Even though it has such a profound implementation, the Department does not have a position on this.

Comment on this
Dr. Richard Browne

Just to jump in, the Department of Enterprise, Trade and Employment owns that risk so we cannot comment on it.

Comment on this

I am aware of that, but I am kicked around between Departments and this is of direct relevance because Anthropic poses a cybersecurity risk to this State.

Comment on this
Dr. Richard Browne

Anthropic is not the risk fundamentally.

Comment on this

Mythos is a risk. The existence of that product and the use of it by hackers is a risk to this State.

Comment on this
Dr. Richard Browne

That is the fundamental point. This is really important. The issue is not that Anthropic has created this. Rather, the issue is that Anthropic has demonstrated this is possible. I can show the Deputy all of the graphs she wants.

Comment on this

The issue is that it exists and we do not have a governance framework within which we can control it as a State or as a globe. That is my issue. That is why I am seeking some kind of answer as to why we as a State are not pushing for the immediate application of the provisions of AI Act for high-risk systems. If nobody can tell me that, I will move on to my next topic.

Comment on this
Dr. Richard Browne

Criminal actors in this space do not care about governance.

Comment on this
Dr. Richard Browne

The fundamental point is that this technology exists and it is possible to use it. It is in the hands of a company now. In five or six months, it will be the hands of an active state or criminal actor. Governance is great and very important, but it does not stop criminal actors or active states using this against us.

Comment on this

It can if it is done properly. My time has run out and I did not get the answers I am looking for.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I will allow Dr. Browne to answer.

Comment on this
Dr. Richard Browne

Quite frankly, we have a vast amount of criminal and international law around the use of cyber tools.

Criminal actors and state actors do not care. They use them all the time. Governance only binds the hands of those companies that are legally constructed in a way that means it applies to them. For most entities, it simply does not apply. The issue here is the principle that this exists and how we use it to defend ourselves, not the fact that you can apply it to a certain company or not.

Comment on this

Dr. Browne is immediately saying that the governance does not work. However, my point is that if we had a higher level of regulation within this State and across the European Union, even though everybody at the moment is pushing for deregulation at European level, we would be able to control those companies to prevent them making such announcements or declaring that such technology exists, and to prevent them from releasing such unsafe products into society where they can be deployed in a way that is a threat to our security. That is my issue. The governance is not there yet. The AI Act is heralded as this promise of a governance system which will allow us to defend against that. All our politicians are doing is pushing back against it. That is my issue.

Comment on this

I thank all the witnesses for their presentations this morning and for all the important work they do for the State. I was struck by the description of AI as a tool, a threat and a target. It was mentioned in one of the opening statements that we are in a race. I presume we are in a race to get up to speed on AI but also in a race with other countries to stay competitive and be able to defend ourselves.

I have a number of questions. I will direct them to whoever wants to come in, particularly Brigadier General Staunton. I do not know enough about this, which is why it is a great conversation. The general public probably does not have a huge awareness of our capabilities in terms of dealing with cyber-incidents. I want to get Mr. Staunton's perspective on what he sees as the top threats to our cybersecurity and who the actors behind them might be. If there was a national incident - an attack on large infrastructure such as energy grids, communications or undersea cables - what would the response to that look like? Obviously, this is a public forum. Who is in charge? How does it work as a response initially? How does our policy and our plan in relation to this fit into our overall military neutrality? That is my initial, broad question.

Comment on this
Mr. Mark Staunton

From an AI perspective, there is a panoply of different threats that could be AI-generated in effect. In terms of the mandate of the Defence Forces to defend our own networks, we are seeing quite an uplift in terms of AI-generated phishing into our mailboxes, etc. We are seeing a large increase in vulnerability scanning, much of which is AI-generated. We are seeing enhanced social engineering associated with enhanced phishing. We are seeing sophisticated malware that has been developed via AI and, in effect, is leveraging potential zero-day vulnerabilities across our architecture. There is a range of other threats from a cyber-operational perspective in terms of information operations, influence operations, deepfakes, fake news, election interference and sowing division within states etc., that is all party to the cognitive element of cyber. We are seeing enhanced surveillance, on occasion. We are seeing target identification and use of autonomous vehicles from an AI perspective. The threat landscape is quite extensive. We are seeing elements of that.

In terms of calling out who the actors are, I am reluctant in this forum to attribute these acts publicly to any individual nation state. From the perspective of the Defence Forces, I would draw a distinction between cybercrime and state-sponsored cyber-activity. Our focus is purely on the defence of our own networks and trying to protect those.

The Senator asked about critical national infrastructure and who is in charge. The mandate in terms of critical national infrastructure is very explicit. The NCSC has primacy for national cybersecurity within the State. However, the Defence Forces provide a contingent capability to the NCSC in the event of in extremis. We also contribute to national cyber-resilience.

On the neutrality issue, I was not quite sure in terms of how that question was framed.

Maybe the Senator could reframe it for me; apologies.

Comment on this

It is about the balance between defensive and offensive. Does this fit into our overall framework on maintaining our neutrality as a country, when we deal with these threats? Do the witnesses have a view on that? Is it being considered overall?

Comment on this
Dr. Richard Browne

I will jump in because that is part of the larger question. I thank the Senator. To rehearse really quickly, I agree with Mr. Staunton's perspective on the actual live AI threats. We count them as five. One is AI phishing. It is happening and is a real thing. One is AI-powered malware, which is much less of a thing but it is becoming more pertinent. Then there is AI-powered disinformation and then, probably most importantly of all in the current environment, is autonomous AI-powered attacks. That is five types of general vectors but it is obviously more complex than that.

On the threats, speaking specifically to who is using these at a state level, other states have. The Poles, in their recent attack in December of last year, have pointed to Russian state actors as using large language models, LLMs, as part of attacks on their energy infrastructure. Anthropic itself has pointed to a number of different Chinese state actors in different attacks. That is who is using this in the wild right now, at least according to other states. We have never formally attributed.

The third question on this - and this is to Mr. Staunton's point - is around how the State responds to large-scale cybersecurity incidents. The NCSC has that role and has had for 15 years. The way we do it is published; we have a national cyber emergency plan that is in the public domain. It is being rehearsed and repeated. We rehearse using exercises very regularly. We have two more substantial exercises; one next month and one the month after which, again, will lead to a revision of that plan and all that goes with that. Underneath that, there is an internal crisis response framework that we use. We have used it twice this year already for incidents, including a couple of times last year. Again, we refresh that regularly to ensure it is coherent with our learnings from other experiences, from exercises and from best practice. That is how we do it.

On how it ties to neutrality, the simple answer is that every state, neutral or otherwise, has a plan that is akin to this. We were one of the first but it has become much more common now. States have, as part of their sovereign capability, a range of different things they can do in an incident. We do and the Defence Forces do. Most of those that we deal with are transparent and public. Some are not and that is in the nature of things.

Comment on this

I have one final question. Is there a challenge in relation to recruitment of specialists on AI? How does the NCSC find that in terms of recruitment and retention? Do we need to up our game on that?

Comment on this
Mr. Mark Staunton

In short, is it a challenge? Yes. It is about recruitment and retention within the Defence Forces but not only the Defence Forces. The public sector in general is a challenge and obviously, in regard to salaries, we cannot compete with industry. However, there are an awful lot of positives in terms of what personnel applying to the Defence Forces, for example, would gain. The whole public sector ethos is very positive. There are opportunities within the Defence Forces for education and training and also from an operational perspective. Some of the areas that people are typically employed in such as some of the exercise programmes we deploy on - I refer to offensive and defensive cyber operations or red-on-blue teaming exercises on international cyber ranges - are quite unique and a great opportunity for people to grow a skill set.

From a staffing perspective, we have got quite a hybrid model in how we build out our cyber capabilities. We have got Permanent Defence Force members and Reserve Defence Force personnel. We also have civilian employees from the Department of Defence, all of whom are integral to our cyber capability development. We are recruiting actively for direct-entrant technicians, hopefully, with specific mandates in AI capability development. On our general service recruitment, we are trying to point it more at specific technician groupings or IT professionals. Then we have got managed service providers and contractors, who all complement our capability development. It is not as challenging as people may think. I am quite optimistic about the trajectory we are on.

Comment on this

I thank the witnesses for coming. It is very interesting. I will start with the NCSC. In recent months, Microsoft Copilot has rolled out an AI assistant for staff here in the Parliament. Is the NCSC confident that Microsoft Copilot is the best and safest AI assistant? Have other options been explored?

My next question is to the Defence Forces.

What safeguards are in place to ensure that AI systems used by the Defence Forces remain strictly decision support tools with clear human accountability at all stages?

Comment on this
Mr. Mark Staunton

On Microsoft Copilot, we do not currently employ any AI solution on the administrative side of our house. We do not employ Copilot at the desktop currently. In terms of AI implementations within the Defence Forces, there are three broad use cases we are typically engaged in. One is in the maritime domain around operational data processing. We have an implementation across our security architecture in terms of our defensive posture and defending our own networks. Then we have an advanced data analytics environment we are building out, and we are going to sit an AI solution in that. I would be pretty confident about the gates we have around the governance of those three use cases. We have a C2 solution, which I alluded to in my opening statement, from a command and control perspective. Ultimately, all technology take-ons, going back to Deputy Gibney's point, in relation to CIS, cyber and digital, are channelled through me and there are a variety of gates thereafter for decision-making. I think the human in the loop and our governance structures do provide a level of assurance around the safety of the AI solutions we currently employ.

Comment on this
Dr. Richard Browne

To answer the Deputy's question on the Oireachtas, every Government Department and entity makes its own decisions on its IT and the Oireachtas has made a choice. That is up to them. Our role really is twofold. One is advice, guidance and support. We have published guidance on the use of generative AI in the public service and I am sure the Houses of the Oireachtas are abiding by that. The other role we have, to be aware, is that we are about to have a compliance role around the public sector. We cannot make any definitive statements about where Departments are or are not.

However, I would point out that these tools are hugely effective in the right hands. They can be hugely useful in improving everybody's productivity. Their safety and their security are matters for the usual regulatory approach in the agency, the Department and so on, and for the vendor itself, Microsoft in this case. There is a really positive story to tell here as well. These tools are hugely effective and people should not be afraid to use them. Copilot is widely used as an enterprise model. It is very useful for lots of people in lots of organisations. On that basis, I would not raise any red flags over it so long as it is properly managed internally.

Comment on this

Recently the Cathaoirleach, Deputy Malcolm Byrne, and I attended a county council meeting in Wexford. The council had had something like 4,000 cyberattacks within a couple of minutes. How many cyberattacks occur in the Defence Forces and in our national system per day or whatever? For the public out there, what exactly happens when an attack is discovered? Can the source be traced and is it held to account?

Comment on this
Dr. Richard Browne

I might jump in first from a national perspective. What is defined as an attack is a very variable question. If the council is saying there were 4,000 in a couple of minutes, that is almost certainly scanning or activity hitting the outside of the network----

Comment on this

Phishing and all that.

Comment on this
Dr. Richard Browne

----much of which is AI-generated. It is just volumetric rubbish. In terms of significant incidents, we deal with between 300 and 400 significant incidents every year. We have a six-point rating scale for significance. Most of the incidents we see are a 5 or 6; they are low on the scale. We get maybe ten 3s every year and the odd 2. We have had one scale 1 ever and that was the HSE attack. That gives the Deputy an idea of the type of metric we have. We get incidents all the time but few of them are really significant.

On the second part of the Deputy's question, whether we can work out who is responsible for an attack, in the vast majority of cases, yes. I am conscious the Deputy does not have that much time. We engage at EU and international level all the time on information sharing, on a day-to-day, live basis, trying to understand and map what threat actors are doing - nation states, criminal actors and so on. Very often we can use that threat intelligence to identify not just the country of origin but often the building of origin and the individuals involved. That is where we are at. Can we hold people to account? Yes, if it is a criminal actor. If it is a criminal actor, this goes into the law enforcement world and colleagues in An Garda Síochána, the FBI, the NCA in the UK and so on can use that information to prosecute criminal actors by whatever means. States are obviously much more complex.

Comment on this

Thank you. My last one is for the Defence Forces again.

How are ethical considerations, international humanitarian law and Ireland's policy of military neutrality reflected in how AI is evaluated and governed within the Defence Forces?

Comment on this
Mr. Mark Staunton

I will come back to that in a moment, if I may. I am sensitive to the fact that the Deputy had two silos of questions.

The catchphrase we use in the Defence Forces in terms of cyberattacks is consistent with what Dr. Browne has just outlined. AI scanning of ports is a feature that we engage with routinely. We get about 80,000 port scans per day. We get about 25 slightly more sophisticated cyberattacks per week. Do we categorise them in the same manner as the NCSC? No, we do not but we leverage those statistics for a reason. We get about 500,000 emails per month, 90% of which are straight and 10% of which are spam. We get about 750 viruses hitting our mail filters and so on. The reason I cite those statistics is to try to confront any degree of complacency from a cyber hygiene perspective within the defence community. The argument is that there is no room for complacency.

To come back to the Deputy's second point in relation to ethical and human rights considerations in terms of our cyber posture and how we govern cyber within the Defence Forces, the ethical use of AI is fundamental and is something that the Department of public expenditure has called out. In terms of NATO and the EU, a number of different principles are applied to the responsible use of AI in the defence domain. Just for the record, we would be sensitive to these and would try to lean upon them in terms of any AI proofs of concept, POCs, within the Defence Forces. Specifically, the principles are lawfulness, responsibility and accountability, explainability and traceability, reliability, governability, and bias mitigation while, at the same time, hitching itself to a human rights-based approach to the military use of AI. We are very mindful of those core principles around the utilisation of AI in defence and we rely on them in terms of our AI implementations.

Comment on this

I thank the witnesses for being here today. Dr. Browne spoke about significant incidents in relation to the categorisation of cyber threats or cyberattacks. Has he seen a percentage increase in the number of cyberattacks in the past two or three years, particularly using agentic models or AI? Could he give an indication of the percentage increase he has seen on a year-to-year basis?

Comment on this
Dr. Richard Browne

The numbers have gone up in the last number of years and we are talking about somewhere in the order of 10% to 15%. In February, we had 60 incidents that we categorised as incidents, of which half were category 6 and the rest were between category 3 and 4. That is where we are at currently. In terms of those that are AI powered, we do not have figures on that because it is very difficult to determine how much of an incident was AI generated or how much AI was used. The types of indicators of compromise, IOCs, that we see are often not predictive of whether AI was used or not. In some cases they are but in others they are not, so we cannot tell.

Comment on this

Dr. Browne also mentioned that agentic solutions are being leveraged on the response side. What agentic models has the NCSC created itself and what models has it purchased in order to help on the response side?

Comment on this
Dr. Richard Browne

This is a really important question and it is an issue on which the next national cybersecurity strategy will have a lot to say, I suspect. We have experimented with and used large language models and AI tools for many years. We actually took a step back two years ago because we realised from our experimentation that a lot of our systems and processes were not amenable to the use of agentic solutions. We needed to essentially repay a technological debt and go back in order to go forward. What we have been doing is preparing everything we do for the application of AI or AI-like solutions into the future. There is a decision to be taken about exactly where in our ecosystem we will use these process. We have multiple different use cases for it but we are in pre-procurement processes right now in order to understand where we should put it.

Comment on this

Where is the NCSC experimenting or where has it been experimenting with those particular agentic pieces or with software in general? Does the centre have its own sandbox?

Comment on this
Dr. Richard Browne

Yes. We have multiple different independent systems, including a variety of different sandboxes for different operating systems and different types of malware.

We have a malware lab that has all that equipment. The material point for us is that we have experimented with AI everywhere, in TI particularly, in cyber threat intelligence analysis, and not only in the reverse engineering of malware but also, particularly, in the collation of large amounts of data. We have a huge data lake with more than ten years of threat intelligence-----

Comment on this

Briefly, where is that stored? Where is that data?

Comment on this
Dr. Richard Browne

That is all-----

Comment on this

It is all in-house, is it?

Comment on this
Dr. Richard Browne

It is all in-house, and that data-----

Comment on this

Sorry. Is it cloud-based or is it-----

Comment on this
Dr. Richard Browne

It is all on prem. That data centre is one of the key projects we have to rebuild. That is done now and live. We have used AI particularly in parsing that TI data. We do not use it right now. We have experimented with it because there are limitations, given the way the data was stored and categorised previously. We are trying to get past that point. As regards the use cases for us, for example, we have a Noupe platform which will be called Tobar. It is built and ready to go. It is waiting on the legislation to go live. That will be our premise for operating NIS2, but it will also operate something called the national cyberdefence services, NCDS. Mr. Staunton mentioned active cyberdefence, ACD. NCDS is our national cyberdefence programme. It sits around the outside of all our networks and allows us to scan for vulnerabilities live, potentially using AI solutions in the future, which we do not do right now, and then to use that data to provide directly to constituents on their live vulnerability. Right now there is a vulnerability there. We do that now but we do not have an automated way of doing it. Those are the types of solutions we are looking at into the future.

Comment on this

As regards the NCSC's on-prem data lake, without telling us where it is, I assume the NCSC has physical security systems around that on-prem solution.

Comment on this
Dr. Richard Browne

Yes.

Comment on this

That is fine. That is that question asked.

I know Dr. Browne says there is a lot of phishing and there are a lot of malware threats, but are there any types of new threats that the NCSC is starting to see and that may not have been as prevalent two, three or even five years ago?

Comment on this
Dr. Richard Browne

The most pressing issue we face right now is in vulnerability management. Again, I do not want to burn too much of people's time explaining how we do vulnerability management, but every software system or IT system is shipped with vulnerabilities. It is inevitable. It is in the nature of software development. There is a series of global processes in place to manage those vulnerabilities using CVEs or co-ordinated vulnerability scores, and we have a range of programmes in place which we have run for years to manage that at a national level. For us, the issue is the speed at which those vulnerabilities can now be discovered using AI tools, like Mythos and others. The challenge, which I referred to in my opening statement, is that we can now manage vulnerabilities in a timely way and keep ahead of the threat actors. We now see the potential, and it is a real issue as of this week in terms of some of the reporting, that we might have to dramatically increase the speed or the velocity of our response processes to allow our constituents to stay ahead of those types of incidents. We have seen some of that scanning here - it is part of what we have all been referring to - but not much. It is clear, however, that it is coming. This goes back to my comments to Deputy Gibney. The issue is not what Anthropic or any other commercial firm does. The issue is that once these tools exist, and they already exist in criminal hands, it is proven that they can and will be used for criminal or nation state activity. For us, therefore, the issue is to understand exactly what the risk is - again, that is why Mythos is so useful in terms of its construction - and then to take those learnings and apply them in a policy and operational context as quickly as we can. That speed piece is the question for us.

Comment on this

I have limited time so I will ask just one final question about the dark web. We know that a lot of nefarious characters and a lot of these threats on online forums, on Tor, etc., are being discussed on the dark web. Is the NCSC actively monitoring the dark web for potential threats and potential cyberattacks?

Comment on this
Dr. Richard Browne

Yes.

Comment on this

That is enough for me, unless anybody else wants to add to that.

Comment on this
Mr. Mark Staunton

In terms of the dark web, absolutely. We have a broad range of TI solution providers, both commercial and military, and many of the components of that TI engagement would incorporate routine scanning of the dark web as well.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I will come back to Senator Clonan because Deputy James Geoghegan - the real James Geoghegan - is in now.

Comment on this

It is a good thing you are protected by parliamentary privilege, a Chathaoirligh.

I thank the witnesses for being here for this important discussion. I might start with Mr. Staunton. Am I right in saying that a conference was hosted by the Defence Forces and the NATO Cooperative Cyber Defence Centre of Excellence back in December. Is that correct?

Comment on this
Mr. Mark Staunton

No. In fact, it was the National Cyber Security Centre that hosted a conference, and I attended that conference. The Defence Forces did not host a CCDCOE conference per se.

Comment on this

There was something where the Defence Forces gamed scenarios involving critical infrastructure.

Comment on this
Mr. Mark Staunton

There was an exercise.

Comment on this
Dr. Richard Browne

Locked Shields is the NATO large-scale cyberdefence exercise, which is run largely by CCDCOE. To be clear, the State is a member of CCDCOE through us. The Defence Forces have had an officer based in Estonia for many years, but seconded through us. We hold the ring on that relationship. We have played in Locked Shields in the past two or three years.

Comment on this

There was some reporting last December of something taking place in Ireland where-----

Comment on this
Mr. Mark Staunton

I am sorry to interject. I think the Deputy is talking about the Cyber Coalition. The Defence Forces did participate in that.

Comment on this

The reporting of that talked about gaming certain scenarios related to attacks on critical infrastructure. I am ringing bells here.

Comment on this
Mr. Mark Staunton

Yes.

Comment on this

In the last couple of weeks, we have seen the impact of what the physical blockading of critical infrastructure can do to this country. What kinds of scenarios were the Defence Forces gaming in that scenario when it comes to the grid system or subsea cables? I do not know if oil refineries are part of that. Can Mr. Staunton give us an indication of the types of scenarios that were being gamed for here in Ireland?

Comment on this
Mr. Mark Staunton

First, we had about 60 personnel engaged in that exercise. It is NATO's premier cyberdefence exercise. The 60 personnel we had participating were a combination of NCSC personnel plus Defence Forces personnel. I alluded to Permanent Defence Force personnel and reservists. Additionally, we had SMEs from industry but, most importantly, we had members of the ESB, a CNI practitioner, in effect, as a utility provider within the State.

Comment on this

I do not mean to slow Mr. Staunton down, but I only have a limited amount of time. Blockaders stood in front of oil refineries. The oil could not be transferred to filling stations, and the country slowed down. What scenarios at a cybersecurity level were being gamed? Can Mr. Staunton spell them out to us?

Comment on this
Dr. Richard Browne

This is more in our space. The NATO exercises are done on-----

Comment on this

There was a conference where this was gamed out. Am I not right?

Comment on this
Dr. Richard Browne

We-----

Comment on this

Just a second. I am just curious as to what took place at that conference. What can Dr. Browne tell us about the types of things involved? Were the Defence Forces gaming somebody attacking the grid system, such as a foreign actor? What did that look like? Did the grid system stop for a couple of days or weeks? Can Mr. Staunton give us some of that type of information?

Comment on this
Mr. Mark Staunton

Yes. I will let Dr. Browne jump in because, obviously, primacy for CNI rests with the NCSC. In this instance, we had a team of about 12 operating on a particular storyline. It was a CNI storyline and in this instance, it was a power generation station. In effect, nefarious actors gained access to the subnet - the network that was controlling that power generation plant. There was a combination of operational technology, OT, and ICT - an IP-based network solution. In effect, there were attacks against OT but also against ICT. Multiple attack vectors were employed by the attackers. The ESB team, in collaboration with the Defence Forces and the NCSC, was in effect trying to monitor that network, detect any intrusion into it, isolate any compromises and, ultimately, eject them from the network and recover. How that manifested, in effect, was that the power grid was coming offline routinely throughout. I think the exercise was a week-long or five-day exercise. How the attacks manifested was invariably that the power plant was shutting down, and our personnel were then immediately engaged with finding how they got in, what we were going to do about it and how we would eject them.

Comment on this

There was a discussion about offensive tools. In that kind of scenario, what are the offensive tools available to us as a state? Is it the Defence Forces or the National Cyber Security Centre that uses those offensive tools?

Comment on this
Mr. Mark Staunton

The Defence Forces' remit is purely to defend our own networks. In this instance, it was a CNI attack. The ESB was, in effect, leading on that particular storyline, in collaboration with the NCSC. Our primary role in that instance was to bring the power plants back up and maintain services. In terms of offensive operations, I will ask Dr. Browne to come in on that. I can talk around the TTPs that were employed in terms what we did and did not do, but from an offensive perspective, Dr. Browne might want to contribute.

Comment on this
Dr. Richard Browne

We must go back to go forward.

Comment on this

I only have a minute and a half. I ask him to go to that point.

Comment on this
Dr. Richard Browne

I will speak very quickly. The response to critical infrastructure incidents, the planning and resilience is all us. That is what we do. Native exercises are set at a collective level. The State did not choose the scenario-----

Comment on this

Will Dr. Browne deal with this specific issue?

Comment on this
Dr. Richard Browne

The State has published its positional paper on what states can do-----

Comment on this

I know all that. Will Dr. Browne spell out what would happen in this scenario? The Brigadier has made it very clear. The ESB has a responsibility. What does the NCSC do in that scenario in respect of offensive tools? Will Dr. Browne deal with that specific issue?

Comment on this
Dr. Richard Browne

First, this is deep into a national security issue. I am not going to tell the Deputy what we will do. We have a range of roles in the defensive and planning space, which we can talk about. The offensive piece is in national security territory.

Comment on this

Right, but is it the NCSC as the entity that is deploying those tools? Is the NCSC telling An Garda to deploy those tools? Does the NCSC tell the Defence Forces to deploy those tools? Is the NCSC telling the private entity to deploy those tools? What can Dr. Browne tell us?

Comment on this
Dr. Richard Browne

Any defensive capability, the ability to help defend the network, the information, support and guidance and teams we put on site are all us. Offensive capabilities are a sovereign capability. It has to be the State. I am sorry, but we do not talk about that in public.

Comment on this

Who is the entity that has the responsibility for carrying out those offensive actions? That is my question.

Comment on this
Dr. Richard Browne

The State does.

Comment on this

Who? Is it the Garda or the Defence Forces?

Comment on this
Dr. Richard Browne

The only public information on this is contained in the national cyberdefence strategy, which refers to the Defence Forces' capability in this space. That is the only public statement on this, to my knowledge.

Comment on this

It was mentioned that the dark web is monitored. The Brigadier mentioned he monitors the dark web. When we had the Garda here, it stated it did not monitor the dark web. For the public and our own sense, how often is it monitored? Do they keep records of those files? Would they refer information to An Garda Síochána for the specific purposes of carrying out a criminal investigation?

Comment on this
Dr. Richard Browne

We do not monitor in the sense of someone sitting and looking at a screen for a text, message or a discussion about something. We are looking for key words and phrases and things that relate to cyber in Ireland. Outside of that, it is out of our remit. We cannot look for non cyber-related issues.

Comment on this

It is the way I phrased the question. What I am trying to understand is, in the course of their work, like what Deputy Mythen was asking, where criminality or perceived criminality has been identified in an Irish sense, and perhaps the source could be identified and the Garda could have responsibility in that situation, how often do the witnesses refer information to An Garda Síochána for carrying out those types of criminal investigations?

Comment on this
Dr. Richard Browne

We refer information to the Garda all the time, but how much of that comes from the dark web scanning versus anything else-----

Comment on this

I am not looking for that distinction. Would they be referring quite regularly? Would the evidence they have gathered form part of evidence that appears in courts as parts of criminal prosecutions?

Comment on this
Dr. Richard Browne

In some cases, yes. A member of An Garda Síochána is seconded to us who sits in our response team. In terms of handover of information, it is seamless because they are there. Importantly, they are there as a garda, with powers of arrest. They are not seconded to us in the sense that we own their contract in any meaningful sense. They are a garda who happens to sit with us. They have live access to all of our systems and they can then take anything they deem to be criminal to the Garda.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

We will have time for a second round. I welcome Senator Clonan to the committee.

Comment on this

I thank the Chair for indulging me. First, I thank the witnesses for the presentation. I came here today to try to learn. It is an area I am completely ignorant of. I will ask a couple of questions. I will give a health warning before I ask them. Forgive me if they are stupid questions because I am a complete layperson. I raise the questions that Deputy Ó Cearúil was asking on emerging threats. Clearly we are in a time of geopolitical turbulence. We know that one State actor may or may not have been involved in a cyberattack on our health service.

There could be a link there. If I recall correctly, I think there was some kind of cyber event involving the aviation sector before Christmas that caused havoc with flights. I think it was more logistical than a safety issue but now we have a second state actor that has been provoked. I will not name any names but, as my eldest fellow said, he is just another orange man and we have dealt with them before. I would be concerns about the risks to aviation, because aviation has traditionally been targeted by both state and non-state actors in the past. For example, you are talking about the energy grid. After Canary Wharf, I know the Provisional IRA had planned to physically interfere with power generators all around London but that operation was intercepted. Now, they do not do it physically; they do it virtually.

My concern as a layperson is that we had an allegation of an attempt to interfere with civil aviation before Christmas, during the visit of President Zelenskyy, although it was by use of a physical intervention, with what were described to us as industrial-grade drones. We have two airlines here. One of them operates a fleet of Airbus aircraft. I understand that Airbus aircraft are entirely automated, for both navigation and the actual physical manipulation of the aircraft, which happens through software and automated systems that cannot be physically or mechanically overridden. I think Ryanair operates Boeing aircraft that have those automated systems, but again, as a layperson, my understanding is that if things go wrong, the pilots can physically intervene and retain physical control of the aircraft with actual levers, wires, cables or what have you. Given that aviation has been a target in the past, are aircraft discrete systems that are immune to external manipulation and this emerging AI threat or what is the situation there? Is that an area that the witnesses wargame, storyline or assess? That is for anyone. Forgive me if it is a stupid question.

Comment on this
Dr. Richard Browne

I will answer that and I will be as brief as I can. It is not a stupid question but it is a question with a long answer. To go back, the incident we had late last year was actually two incidents that happened around the same time and which were bound up together. They were both essentially ransomware in aviation companies, that is, companies providing services to airports. It is a classic example of a supply chain attack. It was mentioned in great detail. These attacks both occurred in the US. The company that was affected was affected in the US, and it had implications globally, but particularly in a couple of airports in Europe, here, Belgium, the UK, Germany and so on. That is an issue we face. Aviation is a target, but everything is a target. The aviation industry has lots of money so criminal actors love it. We have a number of different roles with regard to aviation security. There is obviously a bespoke aviation security committee run by the Department of Transport, which has its own remit, and the IAA has a really important role in that space.

We have had a regulatory responsibility in the NCSC around aviation since 2018, where we have termed, legally, a number of aviation entities in the State. Both airlines the Senator mentioned are obviously covered by it, as the operators of essential services. They have a legal obligation, in addition to everything relating to safety, to be cyber secure. The services, infrastructure and aircraft they purchase are all covered by that to a greater or lesser extent. Aircraft are heavily secured. For safety reasons, they have to be. From memory, both Airbus and Boeing aircraft are fly-by-wire now, which is what the Senator is referring to, which is the same thing in material terms. To jump ahead, the legislation we referred to earlier, the cybersecurity Bill which is forthcoming, will transpose the revised NIS directive, NIS2, into Irish law. A key part of that is to federate those cybersecurity compliance responsibilities to sectoral regulators, so in aviation, the IAA will become the aviation cyber regulator, thus ensuring that safety, cybersecurity and operational resilience are all aligned in one very competent regulator. Essentially, we will retain our incident response management capability. It is our role, but it will become the regulator in an aligned comprehensive way. The State is moving to anticipate many of these threats. If the Senator wants to look at emerging threats and what we think, it is in our national cyber risk assessment. I can go into that in any detail the Senator wants.

Comment on this

I raised the question of whether there is a difference between Boeing and Airbus.

I do not know if the Mr. Cullen can answer that. Regarding the new generation of 747 max or whatever they are called, can the fly by wire systems on them be physically overridden?

Comment on this
Mr. Michael Cullen

I am not an aeronautical engineer but I am quite aware of the ICAO and EASA regulations The International Civil Aviation Authority and European Union Aviation Safety Agency direction is towards human teaming.

With regard to safety, it is my understanding that one would not have a situation whereby a machine would be in the lead. It is ultimately always about having a human involved. It is moving towards human teaming with the human always being responsible. My understanding is that the machine would not be allowed to take over.

Comment on this

When I am in seat 7C with my gin and tonic, I will be able to relax and enjoy it. I thank the witnesses for the reassurance and all of the work they are doing.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

The Senator might be served the gin and tonic by an AI-enabled server. That is a challenge.

Comment on this

Will those AI servants will try to sell raffle tickets as well? I apologise for being late. I thank all of the witnesses. I listened online. I am not sure who mentioned the top five AI risks earlier. It was mentioned that one of the major risks is the ability of AI actors to sow division in society. Could the witnesses provide some examples of that? A lot of citizens are unaware of how they are being manipulated. How can we tackle that?

Comment on this
Dr. Richard Browne

We mentioned this in passing. We are now talking about the various different kinds of hybrid warfare that are applied by nation state actors and non-state actors in a variety of different ways. We do not have a formal role in countering foreign disinformation, but we report on it from time to time when we come across it as part of our reporting. We are in that space to a limited extent.

We have seen AI being used repeatedly in generating false content. That includes deep fakes, that is, videos that look like the real thing but are not. There has been some reporting on that relating to events late last year. There is also the use of general graphic imagery such as comics, etc. It is used in disinformation and information operations in a widespread way already. The issue for us is that the same tools can be used to generate lures as part of fishing to persuade people to click on links, open documents or whatever it might be. It bleeds into our specific world very readily, but it is also a much broader societal problem that needs to be addressed.

Comment on this
Mr. Mark Staunton

To complement that from a Defence Force military cyberdefence strategy perspective, one of the pillars we have is cyber awareness training. This area is routinely addressed in the military defence community on the island around the potential dangers of deep fakes. We provide a certain amount of training for analysts in our security operations centre around the likes of deep fakes, etc., to try to alert people to the dangers. It is something we are very sensitive to and trying to stay abreast of.

Comment on this

There are deep links, graphics, images and fishing links. Are bots in online spaces and chats included when discussing sowing division or does that refer more to graphics and links? A large number of people stir up conversation in chats, but when we look, a fake profile and person can generate conversations at the speed of light or even faster. Is that a concern or is the concern more about graphics and clicks?

Comment on this
Dr. Richard Browne

That is outside of our remit to an extent. It is categorically happening but we do not have a formal statutory basis to engage on that. The Defence Force may have a broader perspective.

Comment on this
Mr. Michael Cullen

A senior officials group is led by the Department of Foreign Affairs and Trade around the hybrid space. This is an element of that. It is being addressed nationally. We have personnel who attend that forum. It is more appropriately addressed at that forum.

Comment on this

It was mentioned that we are in a race and AI defence is a race. Where is Ireland in that race? What do the organisations here need to get ahead in that race?

Comment on this
Dr. Richard Browne

I mentioned that . This is very complex to explain because we need to go back and understand how the vulnerability management process works and what it means for society. I will reduce it quickly

What we have now is the arrival of tools that can scan the entire global IP address structure and find vulnerable systems. Until recently, as in last week, there was no AI system around. It had not been proven that it go autonomously from "Here is a vulnerable system. I am going to hack that" and then do it by itself. There were tools that could do part of the process. Of a 30-stage process, they could do stages seven to 15, for example, but there had to be people in the loop. Now it seems likely, given the research published as recently as last night, that it is theoretically possible to do it. The tools exist. This has huge ramifications. We could spend the rest of the week talking about how that might play out. There is lots of uncertainty. However, at the very least, it is clear that we are likely to see a lot of vulnerabilities being detected and fixed quickly. That is a problem in the first instance because the ability of organisations to do all that fixing quickly will be stretched and that is a challenge for society, not just us. Second, there is a real possibility that it is happening already with threat actors, and we had multiple cyber-enabled attacks late last year, who will start looking for the same vulnerabilities.

We are now in a race as to how fast we can fix versus how fast the bad guys can find and exploit. That is the race we are in, in the short term. In the longer term, we are in a longer and much more complex race where some organisations and entities can fix these structural problems in a much more adept way. Large organisations can take on these tools, procure the necessary services and products and fix their vulnerabilities, but smaller, less well-off and less capable organisations will not. I referred to the potential for an AI gap to emerge between the cyber haves and the cyber have-nots. Some people will be, for want of a better term, fine or even better than fine and more secure than they were before this started. However, some entities will not be because they just cannot keep up. From a national perspective, that is an issue. It is one of the types of issues we hope the next national cybersecurity strategy will have measures to identify and fix. We have a role in that catch-up space.

Comment on this

In simple layman terms, if there were an exam tomorrow on AI defence, what percentage would Ireland score in our readiness?

Comment on this
Dr. Richard Browne

To extend the metaphor briefly, if this were an exam, the exam questions have not been written yet. In fact, no one even knows what the subject really looks like. We are starting from a fairly strong position in that we have existing programmes that essentially have done the same things for years. We have new services already procured, which we cannot launch yet because we do not have the legislative basis, that deal with exactly the uses we are talking about. We are in the 60 percentile. We are getting a strong 2.1. However, the problem is-----

Comment on this

I was not sure if I was going to get a number there but 60% sounds-----

Comment on this
Dr. Richard Browne

The problem is that a 2.1 will not cut it two years from now. Everybody needs to get a first or they fail. That is the problem. It is not "good enough is good enough". You have to be very good or else you are nowhere.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I thank the Deputy. It now falls to me to again thank the witnesses for their contributions and the work they do. As legislators, our obligation and one of our most important roles is to ensure the safety of the State and the safety of all our citizens and those who reside here. The witnesses' role is critical in that regard. Mr. Staunton mentioned that the Defence Forces have responsibility across a number of fields. Would it be fair to say that the greatest threat the State now faces is in terms of a cyber threat? It follows on from some of the hybrid attacks the State has faced in recent times that we talked about. We heard about the attacks we are facing from actors and non-actors. I will come to Mythos and the impact in that space now. However, where we have a state actor engaging in a cyberattack, how would Mr. Staunton define what is an act of war, so to speak?

Comment on this
Mr. Mark Staunton

Without calling out which threat is more pre-eminent or more dominant, the cyber domain is actively contested 24-7 and 365 days a year. Any IT practitioner will tell you that. I alluded to there being no room for complacency. I use statistics to try to underpin that and deliver that message within the defence community. I do that very intentionally because the personnel we have employed in securing and trying to defend our systems are actively engaged 24-7. Is it an extant real threat? It absolutely is.

It is not just for the Defence Forces; it is across the State.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

How vulnerable are we?

Comment on this
Mr. Mark Staunton

I can only really speak about the Defence Forces in terms of the mandate I have, which is to defend military networks. I am always very coy around making any kind of declaration around an absolutist position. We do everything we can to try and make the Defence Forces a less attractive target than perhaps other ICT infrastructure. It is back to the complacency issue. All we have to do is be unlucky once and we are compromised but we do input quite a sophisticated defence-in-depth model in place with very sophisticated microsegmentation of our networks. We have got a very layered defensive posture with multiple different technologies from the edge, through our switching architecture, outer firewalls, demilitarised zones, DMZs, inner firewalls, defense-in-depth, etc. I do not regard us as particularly vulnerable. It is challenging.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I will come to Dr. Browne in a moment. The State is being subjected to cyberattacks on a regular basis. We cannot necessarily control non-state actors but we know state actors are involved in some of the cyberattacks. It is undermining the State in many ways. How is it defined when we are experiencing a cyberattack, particularly one that may be AI-driven, into the future? How are those attacks defined as acts of aggression against the State?

Comment on this
Mr. Mark Staunton

With respect - and I am not trying to duck the question - from a military perspective, I am charged with defending my own networks but from a national perspective, that is really in Dr. Browne's space from an NCSC perspective in regard to state-sponsored cyber activity.

Comment on this
Dr. Richard Browne

I thank Mr. Staunton and I warn everybody that there is Latin in their future. To start on the war question, bluntly, this is an obvious place to start for lots of people but it is really important to understand that cyber is not the last argument of kings. In an Ultima ratio regnum and Louis XIV sense, it is the first argument of kings. Cyber tools are much more closely related to espionage, subterfuge, intelligence collection, distortion and disruption. They have a use in warfare but it is actually limited. Cyber does not kill people; artillery kills people. That means we are much more likely to have types of incidents that are far below the threshold of warfare, like we have had for decades, frankly, than we are to have an act of war. It is possible for a cyber act, under international law as it is currenty interpreted using the so-called Tallinn manual, to amount to an act of war but it is difficult. That is where the Article 5 discussion at NATO is really important because that is setting international law.

What can we do? To answer the question specifically, unless we are willing to declare war on someone, which seems unlikely in most contexts, relatively little. However, there is a huge amount of work at UN and international level on establishing globe-over norms of responsible state behaviour. There is what states can do, and espionage is a "can do". Espionage is kind of allowed under international law but destruction of civilian infrastructure is not. That is a "cannot do". These kinds of global norms, soft as they might be, are essentially the best chance we have of establishing a rules-based international order in cyberspace. It does not look great right now but hopefully it will come back.

Beyond that, a key part of this is our engagement with peers and partners around Europe, both within NATO and outside it, to ensure we maintain the same defensive capability they do. If we are a soft touch and easy target, we are more likely to be targeted, particularly since we do not have the Article 5 protection that many European countries do. We need to be as good as or better than they are to remain somewhat secure in this domain. The Chair is right, of course, in that cyber is an obvious way of getting at countries like us. We are highly connected, we have a lot of digital infrastructure and a lot of very valuable digital real estate here, and we are a target. There is no doubt about that but the work we have been doing and that we have in the offing now is designed to ensure we remain secure - better than average, if you like - into the future.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

Dr. Browne was right in regard to Mythos and the challenges that are there. It is not that Anthropic has developed it but the fact that that product is there. In regard to the challenge it will pose to some of our cyber resilience, the question is, how ready are we and what more do we need to do, whether it is that product or another product, and more importantly, who deploys it?

Comment on this
Dr. Richard Browne

That is the question. The problem we have right now is that Mythos is only accessible to a very small number of researchers.

Research coming out as late as last night in the US, or this morning here, is suggesting it is an extremely powerful tool. In some ways it does not matter. We know it is coming, whether it is this, the next one or the one after. It is now beyond reasonable doubt that we are going to have autonomous AI capability. That means essentially two things for states. We have to have the same capability to defend, maybe not today, but we do not have forever to get there. That is a really important point.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

How long do we have?

Comment on this
Dr. Richard Browne

In reality, for key systems, it would happen autonomously because they buy the systems from vendors who are already secure. Of the ten companies that are in that Mythos-Project Glasswing piece, Microsoft, AWS and so on are in there, as is Apple. Their products are being secured already. The real issue is everybody else outside of that. For us, driving the vendor is a regulatory problem. The EU Cyber Resilience Act, which is coming into place in September and into next year, will do that automatically. It will happen by itself. The issue is around the outside and that is where we have a role. We have 12 months, maybe 18 months at the outside, to be fully ready for that. We already have a lot of the tools built and ready to go to do that but the problem is we do not know what the future looks like six weeks from now, let alone six months from now.

Comment on this

To take up what Dr. Browne was saying on his last point, does his centre have a sense of the level of cybersecurity defences of, let us say, a data centre? This is not about the ones that we own, but one of the mega data centres. Does he have a sense of their level of cybersecurity defences versus our grid system or the ESB and how the two things compare? Is there a big gap?

Comment on this
Dr. Richard Browne

It is a good question. The answer is we have a compliance system in place right now. We are the regulator for electricity. We conduct ongoing assessments of the cyber resilience of the electricity system, like aviation and others. That will shift again to the utilities regulator very shortly. We go on site and conduct audits, so we know. We do not have precisely the same role with regard to data centres but we have an approximately similar one. Data centres are cloud environments. They are just large stores of data in lots of ways. They have hugely complex arrangements around their security that are not perfect but are continually evolved and managed at a global level. A DC sitting in a part of Dublin on the M50 somewhere is not managed as a cybersecurity entity in and of itself. It is managed as part of a global cyber cloud. That cloud environment is secured at a very high level.

The Deputy mentioned energy. On domestic critical infrastructure, similarly, the major energy providers, the operators of the infrastructure, are directly regulated by us. They have invested very significantly in their cybersecurity over the last decade. We have worked with them for nearly ten years now on their security. That is on the compliance side. We also work with them via a system we called COREs, which are co-ordination and response groups. This allows us to share best practice, threat intelligence, information, developments, etc., and in an incident co-ordinate with all of these critical infrastructure sectors. We have eight COREs, soon to be nine, across Government, local government, energy, transport and so on. That allows us to directly engage with them. We have a compliance role which is shifting off to somewhere else, but we also have a very close relationship with them to understand what their risks are and how we can best protect them. We can link them directly with their peers globally on best practice, for example, if there is an incident in Poland, what EirGrid needs to know and here it is.

Comment on this

At a very basic level, for critical infrastructure, if their defences break down and an attack has penetrated of the type that Brigadier General Staunton was gaming in terms of a grid system, coming in and coming out, what is the State's response in that moment?

Comment on this
Dr. Richard Browne

It is written and published. It is in our national cyber emergency response plan. Beneath that, in our own internal crisis response framework and in the energy sector, there is also a whole layer and series of response capabilities and frameworks. The national cyber emergency plan, NCEP, which is the cyber framework, is aligned and sits with the Office of Emergency Planning process. If there is a large-scale emergency, in a similar way to transport issues last week, we will be sitting in the Government task force on emergency planning. I will be in the chair, because that is my role, running the national response process to a cyber emergency. However, because it is an energy issue - it does not matter whether it is gas or electricity - the relevant officials in the Department of energy and the relevant officials from the energy sector, depending on who we are talking about, will have their own response capabilities.

This is all exercised very regularly, including what is called a black start, which is the nightmare scenario where the electricity transmission grid falls over. It is regularly exercised to start that from nothing, literally from a black grid and to first of all to start the transmission grid and then the distribution grid that sits under that.

Comment on this

It is not that the State has some amazing weapon hidden over here, that it comes in and saves the day. It is that we are constantly working with these utilities around when it breaks down and when it does not break down. It is all about working with them, essentially-----

Comment on this
Dr. Richard Browne

Yes, and ensuring the best practice is met and investment decisions are taken properly. This is a really important point. There is no magic here. There are no super weapons or magic anything. This is just work. In a lot of the cybersecurity incidents we have seen recently, we have seen attempts at our energy infrastructure. That is not a secret; it is in the public domain. They do not happen just like that and they are not binary, or at least, not in the sense that we are talking about now. They are slow burning, complex attacks and involve slow burning, complex and layered defences. It is not a case of breaking through the outer crust of a thin, defensive shield and then an attacker is into the network. Attackers have to break through multiple different processes to get into a network like that and we can map and manage that risk as it develops.

Comment on this

Finally, Dr. Browne mentioned that a seconded garda is working with the NCSC. Is that just one member of An Garda Síochána or is there more than one?

Comment on this
Dr. Richard Browne

We have Garda liaison from multiple parts of An Garda Síochána, for obvious reasons. We also have an on-site secondee from cyber crime who sits with us.

Comment on this

The NCSC is not on a statutory footing yet. Is that correct?

Comment on this
Dr. Richard Browne

We do have a statutory basis to do incident response, coming from SI 360 of 2018, which is the NIS1 piece but the separate statutory basis for the NCSC will be forthcoming in the new Bill.

Comment on this

Does the NCSC anticipate that it will become something like the Corporate Enforcement Authority? I know it is a totally different world but the Corporate Enforcement Authority has 12 or 13 gardaí seconded to it. Does the NCSC anticipate having more gardaí seconded into it? If so, what is the function of the Garda in the NCSC currently and what will the function of gardaí be in that entity into the future?

Comment on this
Dr. Richard Browne

To an extent we cannot determine what we are going to become. That is a policy and political decision, ultimately. Looking at our peers around Europe, it is clear that all of them have seconded police officers but none have become largely policing organisations. We do not prosecute anybody. We do not deal with crime in that way. That is a matter for the gardaí and that is what they do. We work very closely with An Garda Síochána, even in incident response, to ensure that its members have what they need to conduct any criminal prosecution thereafter. In that sense, I do not expect us to take on-----

Comment on this

There are no member of the Defence Forces seconded to the NCSC. Is that right?

Comment on this
Dr. Richard Browne

We have a member of the Defence Forces seconded to us and then onwards, to Tallinn, to the CCDCOE but we have no person from the Defence Forces sitting in our office right now.

Comment on this

Is that something that the NCSC envisages taking place in the future?

Comment on this
Dr. Richard Browne

It has happened in the past and it will happen again, I am sure. Right now there are lots of changes happening in the Defence Forces with the establishment of the joint cyberdefence command and it will come back.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

Does Senator Clonan have anything to add?

Comment on this

No, I just want to say thanks. This meeting has been very informative. I want to thank the witnesses for being so frank because that, in and of itself, is very reassuring. To quote the man, there are known unknowns and unknown unknowns and things have to be dealt with on a case-by-case basis.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

Senator Clonan should come to our committee more often. We are always open and frank at this committee in exploring the issues. Senator Dee Ryan could not make it to today's meeting but asked me to ask a question on her behalf. Has Ireland has developed a position on the European Commission's Cybersecurity Act proposal that was published in January? Will that position be published before the EU Presidency in June?

Comment on this
Dr. Richard Browne

I can take that really quickly. The answer is that the process is under way. This is the CSA II, the revised Cybersecurity Act, which has three major components to it, all of which are very complex. We are involved in all of them in various different parts of the NCSC and Ms Imelda Casey is centrally involved in one of them. That process will go on and whether the position is published will be a matter for the Department. I suspect it will not be published because we are in the EU Presidency from the middle of the year and the CSA II will be the major legislative brief on the table in Brussels for that period.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

Okay, thank you. I have some questions myself in the final round, the first of which relates to the Defence Forces. Obviously one of the areas we have looked at is how AI helps with decision-making and transforms work. Within the operational structures of the Defence Forces, do the witnesses envisage AI being used for Defence Forces recruitment, for example?

Staff officers within the Defence Forces also do a lot of the back office planning. Can Mr. Staunton see a situation whereby a lot of that is replaced by AI programming, allowing Defence Forces personnel to spend more of their time on strategic planning and long-term thinking?

Comment on this
Mr. Mark Staunton

Within the operational space I have alluded to, and as regards some of our utilisation of AI, I am sensitive to the fact that Commander Matthews is here. He may want to come in on the maritime domain and our utilisation of AI in terms of the maritime domain because there may be some interesting threads.

Comment on this
Mr. Brian Matthews

We have a vast maritime domain to patrol with a few assets. The level of traffic through our waters is quite large. Gathering large volumes of data and then sifting through it to try to find vessels of interest, anomalous behaviour and unusual patterns is something for which we are using AI as a tool, but that is the support to the analyst. We will never have enough analysts to do that level of work. As we explore the move towards the subsea domain awareness programme, we will gather an inordinate level of data. We will never have enough analysts to do the work we need to do. I do not see it as a threat. AI and other technology will be critical to our developing a rich understanding of what is going on in our maritime domain, which is vast. I do not see AI as a threat to potential employment in the Defence Forces. I see it as a critical enabler to our having a rich understanding of what is happening, in my case in the maritime domain, but it would be the same across other domains.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

It is quite interesting because one of our challenges at the moment is that we are aware of certain vessels operating in our waters and the Defence Forces have a huge area to cover in terms of the waters for which Ireland has a responsibility. At present, some analysts are basically using that to track vessels or to predict where those vessels may be travelling.

Comment on this
Mr. Brian Matthews

Yes, exactly. We use different technologies to do that, but it is a matter of trying to understand what activity is taking place, what we need to respond to and what is just bad data. There will always be analysts making those decisions and briefing a higher authority on what they understand is happening through the assistance provided by different technologies such as artificial intelligence, which is doing that data mining of the very large data sets.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I do not want the witnesses to compromise any information or data, but how is it able to help in terms of the work those analysts are doing? Are there specific examples as to what has been happening in recent times?

Comment on this
Mr. Brian Matthews

If a vessel that might normally take a more economically advantageous route to go from A to B does not do that, then we ask why that vessel is going the long way around or why it is coming down the west coast. If we have never seen that vessel before, we might deploy a maritime patrol aircraft to go and see first of all whether the information on that vessel is accurate and then try to understand where it has been. Then, through engagement with our regional partners and with other nations, we try to understand more about where that vessel has been before and what activity it has been engaged in. It is just a matter of building that pattern-of-life analysis.

Comment on this
Mr. Mark Staunton

I am sensitive to the fact that we might be back into the operational space to some extent and perhaps not in too much detail-----

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

And I do not want to compromise-----

Comment on this
Mr. Mark Staunton

Notwithstanding that, however, as regards some of the Chair's other points about staff officers' utilisation of AI solutions to free them up, for example, or the replacement of personnel through the enhanced utilisation of AI, I do not envisage a scenario where that will be the case. Certainly, the incorporation of AI across our security posture, for example, is rapidly changing the speed at which we are identifying anomalies and confronting specific challenges. In effect, it is enhancing the pace of our triage across the threat environment, and that is freeing up analysts' time, but we are more efficient through the utilisation of AI from a defensive perspective.

We have no plans currently to employ AI from a recruitment perspective, but I did mention an advanced data analytics environment, and we will incorporate AI. We are building out a robotic process automation, RPA, with a number of different functions, and we will sit AI over our RPA environment and our advanced data analytics environment.

Ultimately, that will speed up decision-making within that administrative space. It will certainly help the classic decision support system. It will enhance decision-making in that area.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I thank Mr. Staunton. We were just wrapping up but I will allow Senator Higgins two minutes.

Comment on this

I am substituting for Senator Ruane. I probably have five minutes' worth of questions but I will go with the priority. In terms of lethal autonomous weapons systems, Ireland was a co-sponsor of a resolution at the General Assembly in December 2023. It is a growing area of concern. Autonomous weapons systems have a potential role in the targeting or destruction of human life or infrastructure by weapons without human control or with original human input but without decisions driven by that. Ireland has called for greater regulation and possible prohibition of these systems. Can I have an update on where Ireland is at the moment and where the Government and armed forces have been in engaging on this area?

Comment on this
Mr. Jason Kearney

I will have to go back and establish exactly what the position is on that, if that is okay, just to be entirely accurate, unless Mr. Staunton has something to offer.

Comment on this
Mr. Mark Staunton

No. In terms of a formal policy position, it is probably best the Department promulgates that. The Senator was not here earlier. In terms of our approach to the ethical use of AI within the defence sector, I pointed at a number of principles recommended by NATO and the EEAS. In our deployment of AI solutions within the operational domain, we are always sensitive to those principles. I can outline-----

Comment on this

I am looking for it on a wider level. Ireland has a strong record on national usage of and regulation of weapons systems. We are original signatories of the nuclear proliferation treaty. We led the negotiations on the cluster munitions. Autonomous weapons are a huge ethical issue that is being debated at European and UN levels. I am not looking at the ethics and usage in the Army. In a discussion in AI, this is one of the big uses of AI and one of the big ethical dilemmas. I am a little surprised the Government is not coming to a discussion on defence and AI with clarity on how the use of artificial intelligence in targeting and killing people, potentially, is to be approached. I have read through previous positions Ireland took two, three or four years ago. I would love an update on it.

Comment on this
Mr. Jason Kearney

I would probably be prudent for me to come back because I will also have to consult with foreign affairs on where we are in terms of the international domain on that. I will come back through the Chair with an update, if that is agreeable.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I thank Mr. Kearney.

Comment on this

I had a last question, which was a very small one. From a cybersecurity perspective, the Data Protection Commissioner has made rulings against, for example, the Department of Social Protection on the large-scale consolidation of personal data of citizens in one area, including special categories of personal information. Is that a cybersecurity risk? They call it the honeypot idea. Creating a large consolidation of citizens' data, potentially including biometric data, in one location would seem to be, as well as the data protection breach it has been identified as, a cybersecurity risk. Is that being examined, especially given WannaCry and the previous attacks on health systems?

Comment on this
Dr. Richard Browne

The challenge for us is we are about to become the regulator of public sector cybersecurity thanks to NIS2, so it is challenging for us to make a statement on how secure or insecure something is. This is primarily a data protection issue, by its very nature. Any examination of whether it engenders a greater degree of risk is dependent on the protections put around that system. If the unified system is more secure than before, it may actually be lower risk. You are into that kind of space.

Right now, today, we have no statutory responsibility or role with regard to overseeing any Government Department or agency on its cybersecurity. We will very shortly, but right now we do not.

Comment on this

There was a major breach of health information by WannaCry in the UK. At the time, there was a discussion about strengthening. A lot of cybersecurity is within the civilian piece, and those are the targets that are most vulnerable and precious. What were the actions following that breach in the UK?

Comment on this
Dr. Richard Browne

That is a really interesting question. WannaCry and NotPetya were two incidents that occurred in 2017. We were spared significantly from the effects of those incidents, which were global issues. The incident in the HSE in 2021 is probably more pertinent and is not wildly unrelated to what happened in the UK.

Comment on this

The failure to act based on what happened in 2017 left us open to that.

Comment on this
Dr. Richard Browne

Without getting into any operational detail as to exactly what happened, immediately after that incident, there was a whole series of activities at the Government level. The board of the HSE commissioned a report from PwC, which was conducted out of PWC London, primarily. It is a really detailed report, trying to understand exactly what happened in the HSE. We contributed significantly to that, so our findings are buried in that piece. We took the findings of that report, added to it ourselves and then levied what is called a compliance order on the HSE. We used our legislative tools under SI 360 of 2018 to compel the HSE to take a series of different actions around the protection of the network, the segmentation of the network and a lot of other organisational and technological developments. That compliance order has since closed. The findings of the final report on that will be passed to the new federal regulator under the NIS2 legislation.

Comment on this

We do not want to wait for social protection to have a similar breach before we start responding.

Comment on this
Dr. Richard Browne

One of our first COREs was the Government CORE, working across government to understand where the risks were and where people needed to be. With GovCORE, but essentially based on our NIS framework, we developed a baseline framework for cybersecurity in the public sector about five years ago. That is what people now use to ensure they are benchmarked and secure. That will be followed. We have a number of different pilot programmes already in place, with a certification framework called CyFun, or Cyber Fundamentals, which is a formal certification framework we co-own with our colleagues in Belgium. Government Departments are now heavily advanced, and we have pilot projects in four Departments to implement that. That is how we will do this. There is a formal certification scheme, and Departments will get a detailed analysis of their systems to ensure their security.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I am sorry, Senator. We are already at seven minutes.

Comment on this

I will request it in writing. I would like to get something on the use of Microsoft in the public sector. Has that been analysed? Can I ask for that in writing?

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

That is fine.

Comment on this

Could we have some analysis of the use of Microsoft in the public sector, given that we know there are issues with Microsoft in relation to the US and other places? We have seen what happened with the International Criminal Court, and we know that a number of jurisdictions have stopped using Microsoft.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

My desire is for an AI tool for timekeeping among Members of the Oireachtas. I call Deputy Geoghegan.

Comment on this

There was an exchange with Deputy Gibney earlier about the AI Act. For absolute clarity, does the AI Act have any application in the area of cybersecurity?

Comment on this
Dr. Richard Browne

It is related to and ties in with NIS2, but it is not a cybersecurity piece of legislation.

Comment on this

The NCSC is not a competent authority under the AI Act.

Comment on this
Dr. Richard Browne

No.

Comment on this

Does the AI Act have a regulatory function in relation to anything the NCSC does?

Comment on this
Dr. Richard Browne

In theory, we could be bound by the AI Act under certain high-risk systems.

Comment on this
Dr. Richard Browne

As an entity.

Comment on this

But not in terms of the work it carries out.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I thank all of the witnesses for coming here today and for their work more generally. If they have a last sentence, I will allow that. The role of this committee is to make recommendations to the Government. It can either be a very specific recommendation that the witnesses would like to hear us make, or perhaps there is something they think Ireland in general needs to be concerned about. For me, this is one of the most important sessions we have had to date.

Comment on this
Dr. Richard Browne

I just want to thank the Chair and the committee for their time and attention, and for the invitation in the first place. This is a rapidly changing and evolving situation. As I said, we were getting new information last night and this morning on developments with Glasswing and Mythos. We are very happy to come back and discuss this with the committee at any point in the future. This is as important as the Chair suggests, and it is not going to go away.

Comment on this
Mr. Jason Kearney

I thank the Chair and the members for engaging with us this morning.

As per our earlier discussions on the automated weapons system, we will come back to the committee.

Comment on this
Mr. Mark Staunton

On co-ordinating a national response and putting a framework in place to deal with AI threats, there could be some utility in perhaps having a more formalised framework, perhaps under the AI office, with engagement between the NCSE, An Garda Síochána, the Data Protection Commissioner and the Defence Forces. It is food for thought.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I suggest that we have a session on those issues down the line, perhaps when the new chief executive of the AI office has his or her feet under the table.

Comment on this

Does Dr. Browne share the brigadier general's view?

Comment on this
Dr. James Browne

On a joint session with the AI office? Absolutely. We talk to the future AI office and the Department all the time.

Comment on this

I think the brigadier general was suggesting a more formalised role. Is that not what he was saying?

Comment on this
Mr. Mark Staunton

I think there is product. I think formalising some sort of framework on AI threats is worthy of consideration, as is bringing the key stakeholders together under the auspices of the AI office for at least engagement or discussion. There could be utility in that from a national cyberdefence perspective.

Comment on this

My former colleagues among the visitors to this committee will observe that we are still on Zulu time and that needs to be automatically updated. Just a small point.

Comment on this
Malcolm Byrne An Cathaoirleach Fianna Fáil

I thank all our witnesses for coming along.

Comment on this