Results 261-280 of 2,990 for speaker:Ossian Smyth
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: In the next few weeks.
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: Our current funding is approximately €7 million, including pay and non-pay for this year. This is a considerable increase on last year. The €50 million figure quoted is, I believe, based on a per capitacomparison with the UK. Clearly, the UK is in a completely different situation. It is a nuclear power, it has a different type of security apparatus, it has the Government...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: This is exactly why we carried out a capacity review beginning at the start of the year. An external consultancy looked at what we are spending, to compare it with other countries and to tell us how much we should be spending ongoing over the next five years. I have not seen the report yet and I will have a lot more information about that when I do see it.
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: Yes. The cybersecurity budget was tripled last year and I would imagine that it will go up again next year. This reflects increasing threats and increasing numbers of people going online. It also reflects the increasing difficulty in trying to deal with cybercriminals. It is an increase in budget and it is an evolving market. Certainly, we will see an increase in this years' budget. Of...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: One of the reasons the budget was increased was a projected increased capital spend, which is to provide a new headquarters for the National Cyber Security Centre. They have identified a location for that and are working with the OPW in that regard. This will provide a joint security operations centre, which is where the CSIRT-IE incidence response team can be gathered together when there...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: That is a good question. On EU legislation there is the directive on security of network and information systems, NIS, which has been transposed into Irish law. There is a new NIS directive, NIS 2, coming. That is part of the legislative agenda. We also planned in the 2019 strategy to have primary legislation to deal with cybersecurity. That is being developed at the moment. That is on...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: I thank the Senator. One of the things the capacity review does is that it benchmarks Ireland against other countries, particularly against those of similar size, to see how we stack up. That is going to be of interest. Second, every country obviously has different needs. They are protecting different things. I understand approximately one third of European data is stored in Ireland. We...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: We do. It is a normal part of security practice to, for example, send an email to everybody in an organisation and see what proportion of them click on the link in an email that is trying to phish or store information. Typically the results of that, even in software companies that are very advanced, is between 5% and 10% of staff members still click on the link. One’s security team...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: I thank the Senator for his question. As I understand it, a voluntary hospital is an independent body, separate from the HSE, although greatly funded by the HSE. The Mercy University Hospital Cork had some systems that were tightly integrated with the HSE systems and that the attack spread into their systems,as a result. I do not think they were specifically targeted. There was no...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: Some hospitals were almost untouched. From talking to the IT staff in St. Vincent’s University Hospital, they never had to stop any of their systems. They managed to continue. I cannot imagine that they are going to be joining into any future injunctions. It is really a legal question for those hospitals. If the hospital is a separate, independent legal body and finds ransom notes...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: It does.
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: I believe Deputy Ó Murchú has experience in the HSE and in IT so this is an area about which he knows something. He asked if the HSE is particularly at risk. It is a very large body. Whole hospital groups are at risk and part of the reason is that, by their nature, there are life-and-death situations going on all the time. There is a pandemic going on, staff are running around...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: Offensive capability.
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: The NCSC has no mission to carry out offensive counterstrikes. That is not part of its function. It is there to provide advice, research, risk assessments and incident response. It is not going to hack the hackers back, if that is what the Deputy is asking. That would not come under my remit.
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: The Garda and the Defence Forces both have a position within the NCSC. They have staff seconded into the NCSC so there is a connection between those organisations, which is very useful. I understand the Garda National Cyber Crime Bureau has doubled its numbers and now has around 140 staff. A huge amount of cybercrime goes on. As everything is moving online, because life is moving online,...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: All of these organisations are required to carry out risk assessments, although not all of them were complete. Some organisations were engaging with the NCSC and explaining how far they had gotten. It is a co-operative thing. It is not about catching them out and clamping down on them; it is about us helping them to fill in those holes. All of those organisations would have been involved...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: The Deputy's first question was about whether the NCSC audits Government agencies. It does not. It also does not issue compliance orders against other Government agencies, on the basis that one Minister does not tell another Minister what to do. However, that does happen for organisations providing essential services, such as gas or electricity services. The operators of essential...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: I thank the Deputy for his questions. I know that he has experience in this Ministry. The first point I would make is that in respect of recruitment, the NCSC has told me that it has not had any difficulty in the past. It is recruiting both from the private and public sectors. There is an attraction to working in such an important and key role in defending the country in that way and...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: The Senator asked whether the data collected as part of vaccination was at risk, and he named some of the various data fields collected. To put the Senator's mind at rest, my understanding is they are collected by a system in the cloud developed very recently by IBM and they have not been affected by the hack and all of those data are safe. On the question as to whether we are at war, I...
- Joint Oireachtas Committee on Transport, Tourism and Sport: National Cybersecurity: Discussion (Resumed) (26 May 2021)
Ossian Smyth: Certainly people consider more than money. We do have to pay good and adequate salaries but people are proud to work in the NCSC. They are protecting their country and their vital infrastructure, and they are co-operating with the security apparatus of other countries throughout the world. It is a high-status job and a job people are proud to do. There are more factors than just money...