Executive Summary
Ireland ranks among the leading EU Member States in terms of the uptake and use of digital
technologies. Like the rest of the developed world, these technologies have come to play a
central role in supporting and facilitating economic and social life. Ireland has also gained
very significantly in economic terms from development of a global data ecosystem; our
geographic position, open economy and EU membership have ensured that we have
become host to a significant amount of data and economic activity.
However the progressive development and deployment of the internet and its constellation of
connected devices has been accompanied by an increasing dependence on these systems.
This dependence has created a complex and evolving set of risks, some of which flow from
flaws in the design or operation of systems, leading to unexpected loss of service. Others
exist as a consequence of deliberate actions by organised groups, including Nation States,
seeking to subvert or compromise these systems for a range of reasons. These
compromises can take the form of theft or destruction of data or money and the physical
disruption or destruction of services or infrastructure. In turn, these risks have a complex and
interrelated set of consequences for States, ranging from the protection of citizens data, to
the protection of key infrastructure and services.
Cyber Security is often defined as the means of ensuring the confidentiality, integrity,
authenticity and availability of networks, devices and data. However, as network and
information systems become more embedded and complex, securing these becomes
simultaneously more important and difficult. While these responses have evolved quickly in
an attempt to keep pace with technological and market developments, this process is made
vastly more challenging by the extremely dynamic nature of developments, both in terms of
technology and in terms of the global strategic environment.
Ireland’s first National Cyber Security Strategy was agreed by Government and published in
July 2015. It set out a road map for the development of the National Cyber Security Centre
(NCSC) and a series of measures to better protect Government data and networks, and
critical national infrastructure. This period since that time has seen the NCSC grow
significantly in scale and capacity, and the introduction of EU Network and Information
Security Directive 2016/1148 (NIS Directive), a significant set of measures to support
Government Departments and Agencies in managing their systems.
Furthermore, approximately 70 critical national infrastructure operators have been legally
designated as such, and have been made subject to binding security requirements and to a
binding incident notification requirement. Together, these mean that the State and critical
3