My Department’s core IT infrastructure is provided by the Office of the Government Chief Information Officer (OGCIO) under the 'Build to Share Managed Desktop' shared service.
My Department, working with the OGCIO, implements a multi layered defence-in-depth security strategy which is achieved through the effective combination of People, Processes, and Technology to support the implementation of appropriate security measures and provisions. This defence-in-depth security strategy includes the implementation of an extensive Information Security Management System (ISMS) comprising of many security policies and controls, which is aligned and certified to the industry security standard ISO 27001:2022 to address risks from cyber security attacks. These security controls ensure that a consistent and effective approach is adhered to in the management of cyber security threats and incidents.
As a result, my Department nor any agency under its aegis was defrauded as a result of a cyberattack in any of the years 2021, 2022, 2023, 2024 or 2025, or to date in 2026.
Accordingly, the amount lost as a result of such incidents was nil in each of those years, and the amount recovered was also nil.