Oireachtas Joint and Select Committees

Thursday, 6 December 2018

Public Accounts Committee

2017 Annual Report of the Comptroller and Auditor General and Appropriation Accounts
Vote 29 - Department of Communications, Climate Action and Environment
Chapter 8 - Measures relating to Cyber Security
Chapter 9 - Energy Efficiency National Fund

9:00 am

Mr. Richard Browne:

Precisely. The Chairman said it himself. In the first instance, the responsibility for the security of these companies' systems and data is with them. The companies are responsible for their own systems with regard to the general data protection regulation, GDPR, and network and information security, NIS. Our only responsibility with regard to DSPs particularly is post hoc- after the fact. The directive is explicit that we cannot ex ante audit or assess anybody. There has to have been an incident. Our role is literally to go in and assess. In the regulations we have given ourselves express powers to do exactly that and to issue notices and compliance notices. We have also given ourselves powers and are in the process of procuring external auditors to conduct audits on our behalf in those companies. We are ready now to do assessments if we need to but we will have consultancy firms on hand very shortly to step in and engage with the companies directly on our behalf.

Comments

No comments

Log in or join to post a public comment.