The disclosure of information relating to cyber security measures or incidents, including the nature of attacks, affected systems, financial impacts, detection methods or security controls, could prejudice the security of departmental systems and services by providing malicious actors with insight into vulnerabilities, defensive arrangements and operational responses. For this reason, it would not be appropriate for my Department or its agencies to disclose such details.
I can assure the deputy that my Department and agencies under its aegis maintain a range of technical and organisational measures to protect its networks, systems and data against cyber threats. These measures are kept under ongoing review and are informed by recognised cybersecurity standards, risk assessments, threat intelligence and evolving best practice.
My Department also works closely with the National Cyber Security Centre (NCSC) and other security partners and follows relevant guidance, alerts and advisories issued to strengthen the resilience of its information systems and to respond appropriately to emerging threats.