A combination of internal resources and external supports, as appropriate, are used to deliver cyber security functions within my department. This approach is informed by guidance from, amongst others, the National Cyber Security Centra (NCSC) and the State’s Computer Security Incident Response Team (CSIRT-IE). For security reasons and in line with previous advice from the NCSC, it is not considered appropriate to disclose detailed information regarding cyber security roles, delivery arrangements or supply chain considerations. The disclosure of such information could compromise the Department’s information security posture by assisting malicious actors to identify potential vulnerabilities. My Department continues to keep its cyber security arrangements under ongoing review, having regard to evolving threats, Government policy and guidance issued by the NCSC and others.