Malcolm Byrne
Question:402. Deputy Malcolm Byrne asked the Tánaiste and Minister for Finance the extent to which his Department examines third party supply chain vulnerability when it comes to cybersecurity. [9448/26]
View answerDáil Éireann Debate, Tuesday - 10 February 2026
402. Deputy Malcolm Byrne asked the Tánaiste and Minister for Finance the extent to which his Department examines third party supply chain vulnerability when it comes to cybersecurity. [9448/26]
View answerI wish to advise the deputy that my department implements a risk-based approach to the management of its third-party supply chain, with measures in relation to supply chain addressed within each procurement contract as appropriate to risk.
In relation to ICT, I wish to advise the Deputy that the majority of ICT systems and related associated services are provided by the Office of the Government Chief Information Officer (OGCIO), a division of the Department of Public Expenditure, Infrastructure, Public Service Reform and Digitalisation. OGCIO have advised that it manages third party supply chain cybersecurity through its Information Security Management System (ISMS) framework, which includes certification to the globally recognised ISO/IEC 27001 security standard. This standard governs the assessment and treatment of supplier related risks and requires a systematic approach to identifying, assessing, and mitigating risks associated with supply chain and vulnerability management.
All third-party services are subject to appropriate due diligence, contractual and security requirements, and ongoing oversight to ensure that cybersecurity risks are effectively identified and managed. These measures form part of the Department’s broader strategy to maintain a robust and resilient cybersecurity posture.
In anticipation of the implementation of the EU Network and information Security (NIS2) Directive (Directive EU 2022/2555) transposition, my Department has established a NIS2 supply chain compliance Working Group to ensure that the Department meets NIS2 requirements by evaluating the cybersecurity compliance of its external IT service providers, developing and implementing a framework to assess and manage supply chain risks, and aligning these practices with the Department’s broader NIS2 compliance strategy and Governance Framework. While OGCIO provides most network and information system services to the Department, the supply chain obligations may also place requirements on smaller suppliers who themselves qualify as essential entities under the Directive.