8 Measures relating to national cyber security

8.1 The term ‘cyber security’ refers to the full range of measures designed to protect information and communications technology (ICT) systems and ensure the confidentiality, integrity and availability of data services. It encompasses the body of technologies, processes and practices designed to protect networks, devices, programmes and data from attack, damage or unauthorised access.

8.2 Disruption to critical information infrastructure and networks has been noted as a discrete strategic risk in the annual National Risk Assessment since 2014. In 2017, the assessment noted that “the fact that Ireland is home to a large number of international data centres means that a serious attack or cyber-security failure could have a damaging impact not just on our reputation, but also on our economy”.1

8.3 Cyber attacks on critical systems are an ongoing threat globally. Such attacks include the December 2015 Ukrainian power grid attack and the May 2017 global cyber incident caused by the ‘WannaCry2’ worm. The former impacted 230,000 people who were left without power for up to six hours. The latter affected ICT systems globally; in the UK, the National Health Service was reduced to running emergency-only services in some locations as a result. In Ireland, a HSE-funded facility in Wexford was affected by ‘WannaCry2’.

8.4 The Department of Communications, Climate Action and Environment (the Department) is responsible for cyber security policy in Ireland. It is also responsible for coordinating the governmental emergency response to any national-level cyber security incidents. The Department discharges these responsibilities through the National Cyber Security Centre.

8.5 The Department published the National Cyber Security Strategy 2015-2017 in 2015. The strategy presents a framework for ensuring “safe, secure and reliable” interactions within cyberspace.

8.6 In July 2016, the European Union adopted a directive — the Directive on Security of Network and Information Systems (the Directive) — with a view to achieving a high common level of security within the EU. The Directive requires that the laws, regulations and administrative provisions necessary to comply with the Directive be adopted and published by 9 May 2018. The Minister for Communications, Climate Action and Environment (the Minister) gave effect to the Directive on 18 September 2018.2

8.7 This examination reviews the progress which has been made since the establishment of the National Cyber Security Centre.

National Cyber Security Centre

Pages 1–2 · View in original PDF