For operational and security reasons, my Department does not disclose specific information relating to cybersecurity tools, expenditure, resources, or the detailed strategies employed to counter cyber threats. The Department recognises the importance of maintaining a strong cybersecurity posture, which includes having a dedicated cybersecurity function in place. My Department ensures staff stay up to date on evolving cyber security threats including malware, ransomware, phishing attacks and social engineering.
My Department has implemented an Information Security Management System (ISMS) framework, which includes certification to the globally recognised ISO/IEC 27001 security standard. This framework underpins our approach for managing and mitigating cyber risks. Core capabilities such as threat analysis, vulnerability management, and cyber infrastructure support are delivered through an appropriate combination of resources and skillsets.