Executive Summary Ireland ranks among the leading EU Member States in terms of the uptake and use of digital technologies. Like the rest of the developed world, these technologies have come to play a central role in supporting and facilitating economic and social life. Ireland has also gained very significantly in economic terms from development of a global data ecosystem; our geographic position, open economy and EU membership have ensured that we have become host to a significant amount of data and economic activity. However the progressive development and deployment of the internet and its constellation of connected devices has been accompanied by an increasing dependence on these systems. This dependence has created a complex and evolving set of risks, some of which flow from flaws in the design or operation of systems, leading to unexpected loss of service. Others exist as a consequence of deliberate actions by organised groups, including Nation States, seeking to subvert or compromise these systems for a range of reasons. These compromises can take the form of theft or destruction of data or money and the physical disruption or destruction of services or infrastructure. In turn, these risks have a complex and interrelated set of consequences for States, ranging from the protection of citizens data, to the protection of key infrastructure and services. Cyber Security is often defined as the means of ensuring the confidentiality, integrity, authenticity and availability of networks, devices and data. However, as network and information systems become more embedded and complex, securing these becomes simultaneously more important and difficult. While these responses have evolved quickly in an attempt to keep pace with technological and market developments, this process is made vastly more challenging by the extremely dynamic nature of developments, both in terms of technology and in terms of the global strategic environment. Ireland’s first National Cyber Security Strategy was agreed by Government and published in July 2015. It set out a road map for the development of the National Cyber Security Centre (NCSC) and a series of measures to better protect Government data and networks, and critical national infrastructure. This period since that time has seen the NCSC grow significantly in scale and capacity, and the introduction of EU Network and Information Security Directive 2016/1148 (NIS Directive), a significant set of measures to support Government Departments and Agencies in managing their systems. Furthermore, approximately 70 critical national infrastructure operators have been legally designated as such, and have been made subject to binding security requirements and to a binding incident notification requirement. Together, these mean that the State and critical 3

Select target paragraph3