I propose to take Questions Nos. 220 and 225 together.
My Department takes the issue of cyber security very seriously. The Information Communications Technology Unit, within my Department, takes a whole-of-team approach to protect my Department's data and IT systems. Departmental staff are supported in this function by IT security vendors and third-party support companies.
The National Cyber Security Centre (NCSC) is an operational arm of the Department of Environment, Climate and Communications (DECC), and is the primary cyber security authority in the State. The NCSC provides a range of cybersecurity services to operators of Critical National Infrastructure, Government Departments and Agencies.
My Department's cyber security protocols are supported by the work of the NCSC and the national computer security incident response team, CSIRT, which provides early warnings, alerts, announcements and dissemination of information about risk and incidents to my Department.
My Department has previously been advised by the National Cyber Security Centre (NCSC) that, for security reasons, not to disclose details of its cyber security operations (including details of commercial relationships, audits/exercises and expenditure) which could in any way compromise the Department’s information security posture. In particular, it is not considered appropriate to disclose any information, which might assist malicious actors to identify potential vulnerabilities.