Skip to main content
Normal View

Cybersecurity Policy

Dáil Éireann Debate, Tuesday - 10 February 2026

Tuesday, 10 February 2026

Questions (932, 933)

Malcolm Byrne

Question:

932. Deputy Malcolm Byrne asked the Minister for Children, Disability and Equality the number of staff directly responsible for cybersecurity, as distinct from IT, within her Department; if a threat analyst, vulnerability manager and a cyber infrastructure engineer are employed; if not in-house, if this work is outsourced; and if she will make a statement on the matter. [9424/26]

View answer

Malcolm Byrne

Question:

933. Deputy Malcolm Byrne asked the Minister for Children, Disability and Equality the extent to which her Department examines third party supply chain vulnerability when it comes to cybersecurity. [9442/26]

View answer

Written answers

I propose to take Questions Nos. 932 and 933 together.

The Department's general ICT services are provided by the Office of the Government Chief Information Officer (OGCIO). The provision of ICT security forms a key part of that service. In addition to this, the Department also has staff who are appropriately trained and qualified in cyber security matters. In this regard, we engage closely with the OGCIO, the National Cyber Security Centre (NCSC) and a number of Cross-Government groups on work to ensure best practice is followed as it relates to all aspects of cyber security.

The Department is also currently working on a number of initiatives to ensure full readiness in respect of the requirements of EU Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, and the draft provisions of the related National Cyber Security Bill.

With regard to the specific arrangements raised by the Deputy, for operational and security reasons the NCSC has advised not to disclose details of systems, funding and processes which could in any way compromise those efforts, in particular, information which might assist criminals to identify potential vulnerabilities in departmental cyber security arrangements. Therefore, it is not considered appropriate to disclose any of the arrangements in place in relation to cyber security measures and services, or their cost, or to comment further on operational security matters.

Question No. 933 answered with Question No. 932.
Share