We use Google Analytics to see which pages are read and how the site is used, so we know what to improve. This only runs if you accept. See our privacy notice for details.

Joint Committee on Defence and National Security

Building National Resilience in the Context of Ireland’s EU Presidency: Discussion

Summary

The National Cyber Security Centre said Ireland should expect more cyber incidents during the EU Presidency, but mainly as a continuation of existing threats rather than a wholly new wave. It highlighted ransomware, espionage, hacktivism, supply-chain risk and the growing impact of AI on both attacks and defence, while stressing that Exercise Ériu showed the State’s crisis response arrangements are strong and improving. Members raised concerns about resources, legislation, insider threats, critical infrastructure and public awareness; the NCSC said it already has strong powers in key sectors, with NIS2 and related bills set to strengthen this further. The committee heard that Ireland is in a relatively robust position, though more staffing, better coordination and continued investment were welcomed.

Rose Conway-Walsh An Cathaoirleach Sinn Féin

I welcome Dr. Richard Browne, director, and Dr. Deirdre Morris, principal officer, National Cyber Security Centre, NCSC. The format of the meeting is that I will first invite Dr. Browne to make his opening statement. This will then be followed by questions from members of the committee. Each member has a seven-minute slot to ask questions and for the witnesses to respond.

I advise members of the constitutional requirement that members must be physically present within the confines of the Leinster House complex in order to participate in public meetings. I will not permit a member to participate where they are not adhering to this constitutional requirement. Therefore, a member who attempts to participate from outside the precincts will be asked to leave the meeting. In this regard, I ask any member participating via Microsoft Teams that prior to making their contributions to the meeting, they formally confirm they are on the grounds of the Leinster House campus.

Both members and witnesses are reminded of the long-standing parliamentary practice that they should not criticise or make charges against any person or entity by name or in such a way as to make him, her or it identifiable or otherwise engage in speech that might be regarded as damaging to the good name of the person or entity. Therefore, if their statements are potentially defamatory in relation to an identifiable person or entity, they will be directed to discontinue their remarks. It is imperative that they comply with any such direction.

I invite Dr. Browne to deliver his opening statement.

Comment on this
Dr. Richard Browne

I thank the committee for the invitation. I am accompanied by Dr. Morris, who runs our strategic threat analysis team in the NCSC. She is across all these areas as well. My fundamental message to the committee this afternoon is simple. Alongside the Presidency, we are witnessing a rare alignment of an unstable geopolitical environment and frontier AI models that are rapidly evolving independently. Both of these factors are having a material impact on cybersecurity but their convergence opens a door to a much more unconstrained operating environment for threat actors.

The NCSC's mission is to lead Ireland's response to cyber risk. Approaching the Presidency, we are doing this in three ways. The first way is by issuing authoritative advice. We do this is the form of tailored cyber threat assessments, which we issue across multiple channels. These channels include appropriately classified intelligence assessments, which are shared across our natural security structures, as well as more general assessments of threats and risks, which are issued to our constituent groups, including our core groups. We also share advice and guidance publicly, including a version of our Presidency assessment, which has been shared this week - this morning, in fact.

The assessment calls out a range of risks that vary in terms of their likelihood and their impact on the public. These include financially motivated ransomware. This is a primary concern because it can directly deny the availability of essential services to citizens among other long-term effects. Cyber espionage is the low-cost, covert means of intelligence collection by some States, targeting sensitive data held by other governments for political or economic advantage. Much rarer outside war time are destructive attacks, mainly because states do not tend to destroy each other's infrastructure unless they are in an armed conflict or perceive the other to be a primary strategic adversary. The last relevant incident type is hacktivism. The term "hacktivism" is a portmanteau of hacker and activist, and usually involves the use of low-level destructive cyber tools to conduct malicious cyber activity. This is done to promote a central message or geopolitical calls and as such many of these groups exist in an interstitial space, where their association with their state of origin is deliberately vague.

I want to elaborate slightly here because there is a cognitive element to these campaigns that make them hybrid in nature. The primary objective of hacktivism is to generate publicity to affect or influence the media and democratic debate at low cost and low risk to the state of origin. In the vast majority of cases, the damage from these attacks is slight or non-existent, but there have been cases where groups have successfully targeted industrial control systems, which automate and supervise critical infrastructure operations. Then, third actors amplify and exaggerate these attacks online to create an impression of widespread security and to maximise the cognitive impact on the target population.

I will give an example of a typical hacktivist event. Let us imagine a very short denial of service attack on a public-facing website, which is then "claimed" publicly by a pro-state threat actor. This gets picked up by national or even international media because it coincides with a politically significant event. This media coverage is the objective and it demonstrates, on the lower end, how cyberattacks form a key element of infamous operations.

The second way we live up to our mission is operational preparedness. Over the past five years we have developed communities of cybersecurity practitioners across the public and private sectors, which we call co-operation and response or CORE groups. These groups are essential means for sharing threat intelligence to, from and between critical infrastructure operators and wider economic sectors. Maintaining deep relationships with critical partners, including in government, forms a strong foundation for realistic crisis preparedness and, when something does happen, effective incident response.

This brings me to Exercise Ériu. In early May we conducted a full Presidency-themed dress rehearsal of our own internal crisis response framework, escalating to a national crisis affecting critical services, thus activating the national cyberemergency plan. The scenario, which was developed alongside colleagues in the hybrid centre of excellence in Helsinki in Finland, exercised operators of critical infrastructure alongside the NCSC, the Office of Emergency Planning and relevant Departments. Continuous international engagement is critical for situational awareness and readiness. Our teams engage across bilateral, multilateral and exclusive cybersecurity forums. During the Presidency we will chair both EU CSIRTs and EU-CyCLONe networks.

The third way is active defence. To detect and disrupt live threats, our teams watch the global cyberthreat environment and proactively defend the national attack surface. Our national cyberdefence services provide early warning for network owners, Internet service providers and constituent organisations that they have a vulnerability in their systems that face the Internet or in some cases they have already been compromised.

In recognition of the work of the committee I would like to briefly mention our co-operation with colleagues in the defence organisation. We continue to engage with the Defence Forces, including the current joint task force on the EU Presidency. We were glad to contribute a cyberperspective to the development of the recent maritime security strategy, dealing with cross-cutting threats such as those to subsea infrastructure.

We expect to see cybersecurity incidents throughout the Presidency, not just because we see them on a regular basis. We also expect to see incidents specifically related to the Presidency but, critically, not every incident during the Presidency will be about the Presidency. I refer back to our mission – to lead Ireland's response to cyber-risk. The NCSC has primary responsibility for the cybersecurity of the State. We have planned, prepared and exercised for this period with partners inside and outside of government. There are few guarantees around security and there are a lot of contingencies in this particular case but we believe we have put ourselves in a strong position.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

Very good. Gabhaim buíochas. Before I go to members could Dr. Browne outline the main learning from Exercise Ériu?

Comment on this
Dr. Richard Browne

There were quite a few. The exercise was a two-day event. The first day was held in our own premises and had people from a number of large technology companies and critical infrastructure providers in the same room. We essentially took the situation from where we are right this second, where nothing is happening and the situation is nominally calm, and stepped up over the course of two days to a fully fledged national crisis response. One of the main learnings for us was that our national cyberemergency plan, which was published more than two years ago, and our own internal crisis response framework have developed in their own right but so have supporting and aligned response practices elsewhere. In financial services, for example, we have a financial stability group, FSG. There is a similar set of groups in energy and similar groups are emerging elsewhere. All of a sudden, we are not alone in this space. Our response procedures now have to adapt to what everybody else is doing as well. There is a question there for us internally of better co-ordinating nationally in a cyberemergency that has implications more broadly.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

I thank Dr. Browne very much. I will go to Deputy Smith first.

Comment on this

In the context of the EU Presidency, there is a lot at play politically in terms of security and security risk. Dr. Browne speaks to that a little in his opening statement. Have other states that recently held the EU Presidency seen an increase in cyberattacks during the period in which they held the Presidency?

Comment on this
Dr. Richard Browne

I thank the Deputy. The simple answer is "Yes". We conducted a very detailed risk assessment. I say "we", but it was Dr. Morris's team. It looked at the last nine or ten European Presidencies and then we went and spoke to our counterparts in those countries just to ensure that our view was aligned with what they had experienced. In some cases there was an increase but nothing very dramatic. It is more correct to say that their existing geopolitical location and threat surface was more indicative or determinate of the outcome than was the fact of their Presidency. That is why we expect to see more of what we are already seeing, rather than something dramatic and new. Does Dr. Morris want to add anything to that?

Comment on this
Dr. Deirdre Morris

As Dr. Browne said, when we were developing the Presidency threat assessment, our methodology was to first of all look ourselves at incidents that have been publicly reported but then to reach out to our colleagues across our co-ordination network, the EU-CyCLONe network he mentioned in his opening statement.

Comment on this

Is Dr. Morris's mic working?

Comment on this
Dr. Deirdre Morris

It is. I am sorry, I will lean in a little further. I apologise.

Comment on this

It is old age.

Comment on this
Dr. Deirdre Morris

I will start again. When we were developing the threat assessment, our methodology was first of all to do our own assessment of publicly reported cybersecurity incidents during all of the recent Presidencies. We then reached out across what is known as the EU-CyCLONe network, which is an operational network of all the cybersecurity establishments across the EU. We met with counterparts that had dealt with the Presidency in their respective countries. As Dr. Browne said, the learning is that it is not so much that something radically different will happen during the Presidency; it is a continuation of the kind of activity that we are seeing. It is difficult to correlate increases with holding the Presidency because they have their own unique situation such as local elections or a high-profile event that could also drive cyberactivity. What was interesting from all of the people we talked to is the increased focus across the EU on the country that holds the Presidency and the increased interest in incidents that happen. Not every incident is because of the Presidency but other countries are interested because we hold the Presidency.

Comment on this

I think I understand. The NCSC is bracing itself for perhaps heavier traffic. Things will be a bit busier but it is not necessarily the case that something will be specifically designed and targeted at Ireland because we hold the Presidency.

The NCSC is expecting an increase in threats. Will it receive an increase in resources or funding, even for the period of the Presidency? We hear about an increase in resources across Government bodies to cope with increased activity, whether it is hosting a meeting in a hotel or whatever else. Will the NCSC receive an increase or does it need an increase for the Presidency period?

Comment on this
Dr. Richard Browne

We have been, generally speaking, on an upward trajectory of resourcing anyway, as the Deputy would expect. In fact, we are launching another competition for staff on Friday of this week. We are receiving additional resources as a matter of course. That is essentially the answer. There is nothing specific to the Presidency, just our general path of growth in the first place.

Comment on this

I will come back in. I was going to ask about Exercise Ériu.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

Deputy Smith still has three minutes.

Comment on this

I still have three minutes but I will let other speakers in and then I will come back in if that is okay.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

Sure. I call Senator Clonan.

Comment on this

I thank the witnesses very much for their presentation and the very important work they do.

I am curious about something that was said. In the introduction Dr. Browne said that it was unusual for destructive attacks on critical infrastructure to take place outside of wartime. It is my understanding that for at least a decade now, grey zone attacks on neighbouring countries and their infrastructure and operating systems have been routine. We regularly hear contributors on our national airwaves warning us about an escalation of cyberattacks from state actors on things like transport systems and air travel booking systems. Could Dr. Browne comment a little on that?

Comment on this
Dr. Richard Browne

Of course. I thank the Senator. When we use the term "destructive attack" we are talking about something very specific, that is, the use of cybertools that are deliberately designed to destroy infrastructure.

One example is the Sandworm attacks in Ukraine in 2014 and 2015, where infrastructure was actively bricked or destroyed by a cyberattack. That is very rare. Most cyberattacks are disruptive rather than destructive. For example, the use of ransomware is almost always classed as a disruptive attack rather than a destructive attack. While the HSE incident in 2021 might feel highly destructive, it was technically not a destructive attack, if the Senator will excuse the expression. When we talk about destructive attacks, we usually mean the types of things that have been occurring in Ukraine and Russia as a consequence of the ongoing Russian invasion of Ukraine, not something along the lines of anything that has happened in Germany or France or here in the last decade or decade and a half. There is one minor tweak to that. Sometimes we get incidents here that are destructive in nature but that are not targeted here. In other words, things are destroyed by accident or by the overflow from an incident somewhere else. That is always a possibility.

Comment on this

I am sure Dr. Browne is aware that a high-profile arrest has been reported in the media over the last number of days. A person employed in the public service is alleged to have given sensitive data to another jurisdiction. As a layperson, my assumption is that, if one person has been arrested, this is probably a widespread activity. Is that something the National Cyber Security Centre incorporates into its risk assessment? I am asking about the human factor.

Comment on this
Dr. Richard Browne

I am obviously not going to comment on any investigatory process or anything that is subject to judicial processes at the moment. However, generally speaking, what we call "insider threats" are a factor and are included in all our existing governance and compliance processes already. For example, insider threats are included in the standards we use for compliance with NIS1, the existing cybersecurity legislation in this State. NIS2 will do the same. It is in there as a factor or issue throughout.

Comment on this

I am sorry; this is probably a bit of a tough question. I apologise in advance. We are not really capable of monitoring or defending our maritime domain or intervening in it in a meaningful way. In our ground domain, our capabilities have been significantly eroded. In our air domain, we have had a great deal of discussion here about our lack of primary radar. We rely on a NATO member to patrol and control our airspace. How would Dr. Browne characterise our cyberdefence? We are characterised as Europe's weakest link in all of those domains. That is a phrase I coined myself about 20 years ago. How would Dr. Browne characterise us as regards the cyberdefence domain?

Comment on this
Dr. Richard Browne

It is a tough question in some ways because, to answer definitively, you would have to really understand what every other state is doing and much of this work is obviously classified. While we have a degree of insight, we can never claim to have 100% insight into what everybody else is doing. It breaks down into two issues: what we are doing vis-à-vis the threat and what everybody else is doing.

In the last ten years, we have built a certified, publicly recognised and internationally accredited NCSC with a computer security incident response team, CSIRT, that is in the top rank in Europe. It may be in the top ten. It is categorically within the top 12. It is better than the top ten. We have built national response capabilities across incident response planning both collectively within the NCSC and more broadly across the public service. We also have formally regulated critical infrastructure. We have done all of the things you have to do in this space. We are far beyond the baseline in this case. We have also evolved well beyond that in a number of other areas. We published our national cyber risk assessment late last year. This called out a number of things we need to do in future. Legislation is in process to deal with many of these, particularly those regarding visibility.

Right now, we are in a very robust position with regard to our ability to understand. It is about that old maxim: locate, engage, destroy. We can locate, although perhaps not as precisely as we would like. However, by collectively using all of the tools at our disposal, we have a fairly good understanding of how to locate threats. With regard to engaging threats, we now have legal powers to do so in most sectors. In some other areas, we have legal powers in respect of destroying or removing problems. We are in a fairly robust position. As to what others are doing, they are essentially doing exactly what we are. In some cases, they have more visibility than we do but, in other cases, they do not.

Comment on this

I am very reassured by Dr. Browne's response. I again thank him for the work he is doing. I know the centre is coming from a standing start so I appreciate what it is doing. One of the patterns of interference and disruption has related to civil aviation, airports and so on. There was an alleged incident in December. It was confirmed to the committee that industrial or military-grade drones were identified operating along the flight path of aircraft approaching Dublin Airport. Despite this, no notification was given to the civil aviation authorities, to Dublin Airport or to the airlines. Apart from national technical means, in respect of which there are certain limitations on investment or development, is Dr. Browne confident in the command and control and in the capacity of people to respond to threats when informed of them?

Comment on this
Dr. Richard Browne

That is a really good question. There are two components to it. I will not bore the Senator will all of the details but it is essentially a question of whether the immediate victims want or need to be concerned with the threat themselves. In some cases, the victims have not been immediately affected and are therefore not necessarily concerned with doing anything about it. There is also the question of whether we can have immediate visibility of where the problem actually is. It is about means and intent. For the most part, the answer is "Yes" but, from time to time, we still find situations where we know there is an incident in the State but the victim is not minded to engage with us. There is no legal basis for them do so. They may not care that much about it. That is categorically a challenge but it is one that everybody in Europe and across the globe faces.

Comment on this

The irony is that the people who did not seem to be minded to act upon the information were the people who are charged with the security of the State. In terms of national technical means and all the technological developments and expertise the centre is evolving, I wish the witnesses the very best of luck. I thank them for coming to the committee today.

Comment on this

There is phrase that always sticks with me. It is something that was said to me by an organiser in my party, who said that nobody ever gets any credit for the row that never happened. I imagine a lot of the work the National Cyber Security Centre does is that row that never happened, a crisis that was prevented and that we may never hear about. That is crucially important. These precautionary things are sometimes not fully appreciated, whether in this committee or in general.

I will ask my first question. I really appreciated the engagement we had with the centre previously. It seems that an awful lot of what is done to ensure that the State is insulated and that attacks are prevented is on the private sector side. I am referring to supply chains and so on. That obviously relates to services but it may also relate to physical products. I am conscious that the witnesses will not want to comment on geopolitical matters. I will give particular examples but I do not expect the witnesses to engage with them. It is more about the policy. Judges from the International Criminal Court came before the foreign affairs committee yesterday. They spoke about how the court was switching its software. It is moving away from Microsoft. They said they had no difficulty with Microsoft but, because the United States Government has exercised sanctions against them, they wanted to move away from American products. To clarify, they had no complaints about Microsoft per se. The switch is being made as a result of geopolitical considerations. In a similar way, in the energy sector, some people are concerned about purchasing turbines from the People's Republic of China because of potential issues relating to the technology. In the military sphere, with regard to different pieces of hardware and the associate software, there could be a hesitance to engage with certain governments or companies associated with certain governments.

Obviously, it is not really for the witnesses to comment on any particular set of circumstances but I am curious as to the advice the centre gives the Government and the private sector with regard to exercising adequate precaution as to where they purchase from and potential exposure.

Forms of espionage or cyber monitoring by foreign governments and so on is a potential reality.

Comment on this
Dr. Richard Browne

That is a huge question, not even talking about the geopolitical element of all of this. First of all, if we look again at our cyber risk assessment from last year, there is a full section in there on supply chain security and the precise types of risks we foresee in this space, which are manifold. It is not just one country or the other. There are issues around concentration risk. There are issues about downstream implications. For example, we regularly have incidents where a public body that is a critical infrastructure provider is affected by an incident that happens elsewhere. We had a very public one last month in a global software firm, which affected third level institutions in the Deputy's constituency. Students could not submit coursework. This is a classic example of the very wide range of different things that can happen.

What we have done already on supply chain, for example, is that legislation was passed in 2023, which we brought through the Oireachtas, dealing with the critical supply chain issues in telecoms. Again, this is a critical source of risk because it is central to so much of everybody's daily life in private life and critical infrastructure. There are formal legal measures taken to prohibit certain vendors from critical parts of the telecoms infrastructure in the State already. At a European Union level, we have the Cybersecurity Act 2 - the revised CSA - which will be live during our Presidency. A key part of that Act is broadening out at a European level exactly those kinds of tools to all kinds of different sectors. At a global level, therefore, this is very much a hot topic.

One of the things we have done over the years is work with the Office of Government Procurement, OGP, to ensure the procurement rules that Government uses reflect the risks that arise in procuring services for Government. One of the things that will be in our upcoming legislation on NIS2 is the same thing. It is baking into the security requirements for everybody covered by the directive - more than 4,000 entities - that they have to secure their own supply chain and manage those risks. Providing guidance and advice, which we have done repeatedly, and we have published on it over the years, is great but it is only when it has legal effect that it really starts to have effect on the ground and teeth on the ground. We are also working with the OGP in the context of the next national cybersecurity strategy to go further again on some of that issue but, again, that is a downstream question.

Comment on this

This is a shorter or simple question. It sounds from what Dr. Browne is talking about that legislatively he feels the NCSC has most of the powers it needs, but most is not necessarily all. Is there scope for further legislative change that he feels is necessary to enhance the NCSC's power or capacity?

Comment on this
Dr. Richard Browne

The key issue here is the question of risk. Any action that is taken in procurement or supply chain has a consequence. We always have to balance the cost consequences and doing something with the risk. We obviously only really concern ourselves upfront with the risk but for the State as a whole, there is a question of cost and downstream implications. The CSA2 will frame a European response to this and that will be the outcome for us, ultimately, as a State. There are always things that can be done beneath that level, though, which we are already doing in some cases, in driving better practices into Government procurement particularly, but also making people aware in critical infrastructure where there are things they should be doing better. Ultimately, however, legislation seems to be pressing either way. That is the way the world is going in this space.

There is just one minor thing - it is not minor at all and is a huge question - which is the question of European digital strategic autonomy. That phrase has been around more than a decade now. It can mean many things to different people, but what it does not mean is that Europe has the capability in a meaningful way to replace all American technology in any meaningful timeframe. The Internet was invented in America. The large companies that provide all the physical infrastructure and many of the services, including the operating systems for mobile devices and fixed equipment, are largely American. There is no conceivable world in which we can replace all of that, frankly, in most of our lifetimes.

Comment on this

With the Chair's indulgence, could Dr. Browne just say one more thing on that? What is the prudent and sensible balance in that? It is not irrational for European countries to say that they need to have, to the greatest extent possible, capacity and some degree of autonomy, but from what Dr. Browne is saying there are practical constraints in that. What is the sensible balance in it?

Comment on this
Dr. Richard Browne

If we look across Europe, the key issue for many years has been cloud computing, particularly with regard to data sovereignty and cloud. Who has access to our data, ultimately? Some of the issues that have arisen in that space have been as a consequence of legal and legislative provisions in place in both China and America. If we look at what is happening in a number of European countries, they have instituted data sovereignty systems around that, often using American technology but premised entirely in their home country. Those are the types of things that are gaining more prominence around Europe, for example, Google with Thales in France and Microsoft with BSI in Germany. There are things starting to emerge at a European level that address the most meaningful risks in a way that is not overly burdensome or costly for society or for businesses.

Comment on this

I thank the witnesses for their presentation and opening statement. Obviously, the forthcoming EU Presidency is the big issue. As Dr. Browne outlined, in line with what has happened in other states, he is expecting that there will be a higher level of attempted cyberattacks or incidents during that period. Is there a high level of co-operation with the Defence Forces and, in particular, the joint cyber defence command in terms of partnership with them? We have a bit of an unusual situation in this State. In terms of the special detective unit, SDU, is there a high level of co-operation there as well? I have a few questions. I do not want to be badgering Dr. Browne, so he might try to keep the replies short.

Comment on this
Dr. Richard Browne

The answer is both is "Yes". We have very high levels of co-operation with all sides of the Defence Forces and the Garda that are relevant, including cybercrime and various other parts of An Garda Síochána.

Comment on this

Would it primarily be the SDU more so than the Defence Forces?

Comment on this
Dr. Richard Browne

It is both. It goes equally both ways. For example, I mentioned Exercise Ériu earlier. We had Defence Force officers from the joint cyber defence command playing in the exercise on site but also playing in their facilities as well. We work both ways. We play in their exercises and they play in ours.

Comment on this

In relation to the big attack on the HSE IT systems, I know the NCSC is not the investigating authority, but has that more or less reached a conclusion now?

Comment on this
Dr. Richard Browne

I cannot-----

Comment on this

Determinations have been made - is that correct?

Comment on this
Dr. Richard Browne

In terms of the actual criminal investigation, I cannot speak to that. That is a matter for the Garda. Obviously, we have an involvement in it but we are not central to it. In terms of the HSE's own response, yes, but it is a process that will likely continue for a very long time given how complex and multivariate the problem is. I will give one more sentence on that. We conducted an investigation using our own regulatory powers under the NIS1 legislation. We levied a compliance order against the HSE in 2022 based on the outcome of the PwC report and our own assessment of the piece. That compliance order has run its course. In the context of NIS2, however, there will be a new regulator taking up the role of regulating the HSE and we will pass the remaining elements of that compliance order to it later this year, when it takes that on and becomes effective in implementing it.

Comment on this

In the context of the war in Ukraine and other geopolitical and military situations, there would obviously be a high level of concern about certain countries. I recall that about 20 years ago, a lot of information was coming out in relation to infrastructure connecting this country to England, particularly to its Government Communications Headquarters, GCHQ. Does Dr. Browne offer advice on how to monitor that in terms of the special detective unit and the Defence Forces?

Comment on this
Dr. Richard Browne

So, the-----

Comment on this

There was an ongoing process over a period of time.

Comment on this
Dr. Richard Browne

The answer to that question becomes complicated very quickly. Intelligence services the world over collect-----

Comment on this

I am sorry; could Dr. Browne repeat that? It is very complicated and-----

Comment on this
Dr. Richard Browne

The answer to this has multiple different layers to it. One of our primary roles is to defend people against cyber aggression and deal with cyber risk. Intelligence collection is categorically a cyber risk. The types of tools used by intelligence agencies like the one the Deputy mentioned will be vast in their scale given their budgets.

They operate, as one would expect, at a very high technical level. There are things that everybody can and should do, generally, as part of their day-to-day lives like multiple factor authentication and using encrypted services wherever possible that will mitigate many of those kinds of tools. Ultimately, for very high order threats like that type of activity, it is almost impossible to deny every single avenue of opportunity. Really good operators will get information thereafter. It is, unfortunately, in the nature of things. More generally, at a national level, the types of things we do to deal with general criminal activity in terms of advice, guidance, support and our own technical means that we use to build resilience also function against higher order threats. If we are making sure that we are dealing with the basics to deal with criminal activity by default, we are also taking measures to deal with other kinds of intelligence collection and similar activity.

Comment on this

On the procurement issue and origin, there was concern in this complex a couple of years ago in relation to the origin of the CCTV system. Does the National Cyber Security Centre have a role in advising on that, or specifically on that type of equipment?

Comment on this
Dr. Richard Browne

Right now, we do not. We have a formal role with regard to telecoms and telecom security. We provide advice, guidance and support, and we have published repeatedly on public procurement, but it does not deal with country of origin questions of this kind of order. There is, obviously, a risk-based question for anybody procuring. Our advice puts this to the procurer to ensure that they are properly managing the risks to their own infrastructure and to their own privacy and security questions. The specific issue the Deputy is dealing with is really a subset of a much larger set of questions about any kind of Internet of things device. Again, for everybody's information "Internet of things" is the term used to describe any small-scale IP connected device. It could be a security camera, and that brings obvious risks, but it could be anything like a digital video recorder that sits on top of or underneath your television. It could be any kind of connected device such as a child's toy, or anything. Those devices by their very existence are poorly policed, they are rarely patched and they pose a risk to everybody. I can explain what those are if the Deputy really wants. Legislation coming in here, starting in September but rolling into next year, is the transposition of the EU Cyber Resilience Act, which is a whole other piece of legislation. That will oblige vendors selling into the European Union to meet certain EU security requirements. That is an example of a really comprehensive approach to dealing with this, so rather than just fixing that one problem we fix all of the issues at once.

Comment on this

I have one short final question. Where a cyberattack is detected, is it difficult to determine the country of origin of the attack or where it is directed from? The origin could be here but where it is directed from is the question. Is that difficult?

Comment on this
Dr. Richard Browne

That is a really good question and the honest answer is that it depends. Very rarely do we see a cyberattack about which we have never heard anything before. We have an entire team in the organisation dedicated to tracking and understanding who is doing what right now and using what tools. When we see a tool in use, a piece of code, a tactic or a technique, we can then track back from that as to who is using it. This means that for the very most part when we see an incident we understand relatively quickly who is ultimately behind it. In many cases, that gives us a geographical location and, in some cases, even a building. This is not in every case but in many cases, we can be very precise with where it is ultimately emanating from.

Comment on this

Are most from outside the European Union?

Comment on this
Dr. Richard Browne

The vast majority is outside the European Union.

Comment on this

I thank Dr. Browne.

Comment on this

Dr. Browne and Dr. Morris are very welcome, and I thank them for being here. From the first time we met, Dr. Browne has moved to a much higher profile, which is to be welcomed. I believe that he has moved to the Department of justice, but I am not sure if that move is complete or if it is still in transit.

I would like to put a couple of issues out there, and I will put the questions all together if that is okay with Dr. Browne. On legislation, he had an opinion piece, or a report, recently in the Irish Examiner, I think it was, where he was desperately seeking legislation. We are the laggards on this occasion in not meeting this need. Is this going to hamper the NCSC as we move into the Presidency of the European Union? When I look up the National Cyber Security Centre and have it compared to its international peers, I am impressed to see how professionally the centre is regarded. However, the country as whole is regarded as a laggard in the area of cybersecurity. Is there anything that is impeding the centre from being a higher public profile? There is a tendency within this illustrious building to try to avoid questions on national security, defence and security and the like, with the head in the sand and saying, "Sure it will not happen, everybody loves us, and we are great football fans around the world". That worries me.

I note the centre's engagement with the industry, which is hugely important. It is impressive the way the centre is engaging with industry suppliers. It means that there is constant communication between the centre and the people who need to know what is happening. Is there anything that we should be doing to support that better for the centre?

From the attack perspective, have we the capacity to be offensive as well as defensive when it comes to cyberattack, or are we strictly on the defensive side when it comes to it?

The last piece I will throw in for the hell of it is on the SME sector. The Enterprise Ireland system that was in place was, I believe, €3,000 of a grant for an initial overview of a system and then up to €60,000 of a grant to bring a system up to speed. It was confined to Enterprise Ireland clients only and many in the SME sector are concerned that this is the way it has gone. The other suggestion made to me by a number of industry actors was that we should reduce the €60,000 down to €20,000 and allow for a much faster roll out of some of the simple things that would make our SME sector safer, such as software patches etc. I am sorry there is a lot there but I just said I would throw it all out in one go.

Comment on this
Dr. Richard Browne

I will do my very best to cover all of that. To answer the Senator's first point rather than a question, we have changed a lot but it has been a decade and we are now approaching 100 people so we have real scaling capability. That also goes on to answer a couple of other questions.

On the legislation, we already have legislation to deal critical infrastructure. It is not the latest version of the European legislation but that is coming. We already have fairly significant powers to enforce and to compel engagement with us. We are not in a bad position for the really critical sectors in the State. There are systems we have built in anticipation of the legislation that we cannot use fully but when the legislation does pass we can go live extremely quickly thereafter. I am happy to brief the committee more once we are in a position to be public about that.

Is the State a laggard? No, it is not at all. We are in a very lucky position in Europe in the sense that we have a very strong private sector cybersecurity industry. The last time we checked and did a formal report we had more than 8,000 people working in the private sector cybersecurity in the State across a range of different companies, with some large multinational companies and some much smaller Irish companies. There is a very robust sector there. Speaking to colleagues across industry, in the past five years across not just the critical infrastructure sector but in others too there has been a huge increase in capability and understanding, which is really important from our perspective. That is showing up as well in international rankings.

In terms of public profile, I have an unfortunately high public profile. I have no interest in expediting that but at the same time we are utterly clear about the need to be transparent as to the risks, and not to hide behind anything. It is important that people understand what they are and, critically, understand what they are not. One of the key issues in hybrid and dealing with hacktivist-type attacks, including the Presidency, is the tendency to describe everything as being a crisis. Most hacktivist attacks are not. Most cyberattacks are categorically not. They are entirely manageable, small-scale issues that with the right response techniques can be made go away, for want of a better term, and mitigated very quickly. There are issues that are not and this is why we have all the planning and procedures to deal with those things, but that is what it is.

In terms of the offensive component, there is mention in the public domain in the national cyber defence strategy, which is the Global Cyber Defence Centre's own strategy, around offensive capability. That is the only measure and obviously it is a national security issue and I cannot speak more to that.

On the SMEs, last week we published a new website for SMEs for them to literally go and use the tools on that website to assess their own vulnerabilities. It has specific information, guidance and tools for small and medium-size enterprises.

It is a key sector in the economy. It is a hugely vital sector. It employs hundreds of thousands of people, but these organisations often lack the scale or complexity to have the type of cyberdefences that larger organisations have. We are building tools, and there will be more to come on that website specifically for SMEs. We encourage anybody, even larger enterprises, to look at that and see what is there.

To the Senator's specific point on the support scheme, again, for those members who are not aware, we ran a pilot scheme with Enterprise Ireland over the past two years for SMEs, adding on to an existing scheme that it had. The pilot is closed and has fully dispersed all of its funding. There is a commitment in the programme for Government for a new scheme. We have already had a huge amount of learnings from that scheme. The new scheme will be very different when it emerges, and the Senator's comments will be fully met when he sees the final scheme.

Comment on this

I have one quick last question. I know that Dr. Browne is highly regarded in Estonia. I have been out there a number of times. He will be aware of the fact that the Estonians have appointed a full-time cyberambassador working within the country. Would that assist Dr. Browne's organisation?

Comment on this
Dr. Richard Browne

Regarding the idea of having a cyberambassador, the Estonians were one of the first to do this. I am not sure if they were the first. Quite a few European states have one. The simple answer is if I was given a person of that rank, that is not where I would put them. It is great, but for any additional capability, I will find a better home for it. The Department of foreign affairs already does a really good job in co-ordinating our international engagement on cyber. In fact, it has moved more staff into that area recently, not even because of the Presidency - just in general. It also plays a key role in our engagement with the UN. From the NCSC's perspective, we deal with the OECD, NATO and a number of other bodies, but the global piece is the responsibility of the Department of foreign affairs, and it does a really competent job, as you would expect.

Comment on this

I was talking more about internally within the country.

Comment on this
Dr. Richard Browne

We have an engagement team that is led very ably. It does a huge amount of work not just with critical infrastructure, but across the sector. We have international delegations in all the time, including one today, talking about this stuff, so we are in a very strong position.

Comment on this

I thank the witnesses for all they do.

Comment on this

I have a number of questions. What impact is AI having on the nature of the cyberthreats and is there any additional aspect to that in the run-in to the EU Presidency?

Comment on this
Dr. Richard Browne

That is a really pertinent question. I could give the Deputy a long answer, but I promise I will not. There are two things to keep in mind here. The first is that in the past eight weeks since early April, we have seen a series of dramatic technological developments in AI around something called Mythos, which is a tool developed by Anthropic. There are follow-ons by OpenAI called AI 5.5 cyber; the names do not really matter. These new frontier models essentially offer huge capability improvements on both attack and defence and will likely fundamentally change how cybersecurity is done over the next little while. How long is "a little while" is an open question.

We have advice on both of those questions coming publicly from Dr. Morris's team very shortly, and there is also an EU action plan which we are contributing to. We have already contributed and will continue to do so on what the EU as a whole is doing in that space.

However, even before we consider this new generation of AI tools, from early last year it became clear that a number of large criminal cybersecurity enterprises are using AI tools to develop their own systems faster.

We had an incident here in April of this year - it is not public yet, but I suspect it will be fairly shortly - in which a very well-known relatively new Russian-language, but almost certainly Russian, threat actor group developed tools internally in three days using AI tools. In other words, it used AI tools to write code to make its own systems far better. That has allowed it to become far more prolific in its number of attacks. We are already seeing and have seen attacks here that have been potentiated, if not conducted, using AI tools. So, yes, it is a real issue both categorically going forward and already.

Comment on this

Is there anything specific going into the Presidency?

Comment on this
Dr. Richard Browne

No, there is not. That is the simple answer. These ransomware attacks happen on a regular basis. We have seen quite a few of them in the past couple of months. We expect to see more. They happen all the time. It is like the weather, unfortunately.

Comment on this

Have there been many trends emerging in terms of cybersecurity or lessons learned from the last number of Presidencies throughout the EU?

Comment on this
Dr. Richard Browne

Yes, is the simple answer. We have conducted a detailed assessment, a short version of which was published today. A much more detailed version is being shared across government. We went back over the last nine, or maybe ten, European Presidencies to look at what had happened in those cases. In most cases there were incidents that were almost certainly attributable to the fact that the Presidency was in play, but in some cases there were not. The key learning for us out of this entire process was that a country's existing attack profile - the existing type of incident - is what it is likely to see more of during the Presidency. There was nothing dramatic or new in that context.

Comment on this

Is Dr. Browne satisfied that the national cybersecurity Bill, on which the justice committee has carried out pre-legislative scrutiny, has sufficient powers in it for the NCSC to do its job effectively?

Comment on this
Dr. Richard Browne

We played a significant role in drafting the original version of that Bill, and we have seen aspects of it as it goes through. It has to arrive into the Oireachtas and pass through the legislative process, and whatever shape it will be in at the end of that is what we will deal with. It does two things that are really critical for us. The first is that it transposes NIS2 fully. That directive will give us really powerful incident reporting requirements, so thousands of entities will have to tell us what is happening. It will also oblige the same number of entities to take security measures. NIS2 alone is a huge advance. The other element of it around establishing the NCSC and giving us formal roles will allow us a new base to build on going forward. The simple answer is "Yes". The Bill will allow us to do a huge number of things. In reality, it will probably take us several years to fully use all of those powers, which is what you would expect.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

I want to ask the witnesses two quick things. In relation to the NCSC's co-operation with the Defence Forces in the South, are there secondments from the Defence Forces into the organisation and vice versa?

Comment on this
Dr. Richard Browne

We do not have a secondee with the Defence Forces right now. I cannot tell the Deputy off the top of my head, but it is at least four years since that has happened. We have a secondee from the joint cyberdefence command, which was previously known as the communications and information services corps, into us and onwards to the centre of excellence in Tallinn, Estonia. We hold that engagement with that centre of excellence, and the Defence Forces second someone to us, who we then second on to that organisation. It is fitting because many of the people, not all, in that place are in uniform. It allows the Defence Forces access to a global-class community of experts in this kind of military cyberdefence and also allows us that global contact and access to really good training which is invaluable.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

Would Dr. Browne like to see that developed more, or is it sufficient at the moment in terms of what needs to be done?

Comment on this
Dr. Richard Browne

It is sufficient for the moment. For us, the challenge always is making full use of that access, which we are continually trying to iterate on and develop.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

In terms of public awareness, what else can be done to mitigate some of the risks?

Comment on this
Dr. Richard Browne

That is a good question. The real question is the proportionality piece. We have no obvious interest in trying to scare or frighten people. Many of the issues and risks that arise at a personal level are really more related to people's own personal security against fraud and scams. That is an issue for the gardaí, for us and for lots of other people. We provide information, guidance and support around those kinds of issues. For us, the key risks that we deal with are to critical infrastructure, government, services and then society as a whole, and the work we do is largely aimed at those kinds of systemic risks. That is not something that individuals really need to concern themselves with unless they want to, but at the same time aspects of those risks feed back into individual lives. For example, the work that the Office of Emergency Planning does around having people prepared for crises at an individual level, such as the booklets that were recently circulated, also applies to us. The types of incidents we might see could end up in a more general national issue - the word "crisis" is a bit strong. If people are prepared to deal with a transport or weather crisis then, by default, they are more resilient against cybercrises as well.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

Do we have a sufficient number of qualified students coming through the higher education institutions to be able build up our capacity and to have the expertise that we need not only for the NCSC but within Departments as well?

Comment on this
Dr. Richard Browne

I will give the Cathaoirleach a three-part answer to that. Part one is that, globally, there is a huge shortage of cybersecurity skill sets, particularly in the higher order element of all of this, which is the world, unfortunately, in which we exist. There are substantial challenges across Europe and America dealing with these kinds of issues.

On the second part, we have made huge steps forward here in the last five or six years. We now have not just technical cybersecurity courses in most universities and higher education institutions, but also diversified legal, compliance and other associated courses are starting to emerge. We are, almost organically, in a very strong position because of how close our universities are to industry and how adept they are at flexing and adapting what the market demand is.

The third part of the answer is that we have, as part of the programme for Government and in the NDP, a commitment to building a national cyber centre of excellence. The first steering group meeting on that was held this week in our building. We are working on that process, which will be further explained in the next national cybersecurity strategy and will also include measures around skills and those kinds of developmental issues. The good news is it is happening already. What the State can do now is look further ahead at the next generation of skills that we will need. The Cathaoirleach's question about AI is a pertinent one in that context.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

We can take it from today's session that, in relation to the EU Presidency, the NCSC has a high level of preparedness and has everything it needs to be able to do what needs to be done when it has scoped the risks and the incidents that have happened in other member states that have held the EU Presidency.

Comment on this
Dr. Richard Browne

I will give the Cathaoirleach another three-part answer. On the first part, yes, we have heavily evaluated what is happening. We have benchmarked where we are with regard to other member states and we believe we are in a fairly strong position.

On the second part, whether we have all that we need, I will never say that we have. I will always take more, which is what the Cathaoirleach would expect. At the same time, we are in a relatively robust position and we are recruiting again. We will have advertisements in the newspapers on Friday, or maybe Thursday if we are lucky.

The third piece is that the bad guy gets a voice too. While we think we understand the risks in a fairly complete way, there is always a possibility that something unusual will happen and we will get an incident type that we have not seen before or we will have a large-scale incident during the Presidency that is adeptly targeted to cause us particular problems.

We have an exercise ongoing today in the NCSC. We are playing in Cyber Europe, which is the European, EU-led cybersecurity piece. We are playing this as if it was a live incident. We have not cancelled anybody's annual leave. We are running it on the basis of who we have in the building on the day, with a couple of critical infrastructure operators in their own building and people in other parts of the world. We are playing this to test genuinely how we would do in a real-life crisis because we cannot predict what would happen. We can have a fairly good go at it, but we are never going to be 100% precise. We could get something completely out of the blue - a black swan. We have to be ready for that too.

Comment on this
Rose Conway-Walsh An Cathaoirleach Sinn Féin

Yes, the dreaded black swan. On behalf of the committee, I thank Dr. Browne and Dr. Morris for their time and engagement this afternoon. We will now suspend briefly to allow the witnesses to exit. The committee will then go into private session.

Comment on this