Support from readers like you keeps The Journal open.
You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.
If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.
AN OFFICER IN the Irish military’s response to cyber threats said the State must maintain momentum to prevent future online attacks.
Commandant Frank Hickey is a senior officer in the Irish Defence Forces’ Communications Information Services Corps (CIS).
Hickey said that attacks such as the HSE ransomware incident shows the importance of continuous growth in Ireland’s cyber defences.
The CIS and the wider Defence Forces are not the primary agency – the responsibility for running the response to threats is owned by the National Cyber Security Centre (NCSC).
The Defence Forces, and their expertise in the area, was called upon during the health service crisis.
Hickey spoke to The Journal this week to reveal how the State’s response to cyber threats has changed since the HSE hack, the threats currently faced and how the Commission on the Defence Forces could see his team grow to better confront future attacks.
The military’s cyber defence capability is contained within the CIS Corps, and Hickey also spoke about the behind the scenes efforts of dozens of CIS teams.
CIS are tasked with many jobs in the Defence Forces, including the operation of radio systems and IT networks, and have a number of cyber defence specialists. The soldiers and technicians in the unit were key to getting HSE systems back online after the hack.
CIS personnel working to restore HSE computer systems. Irish Defence Forces
Irish Defence Forces
Primary role
Hickey was eager to stress that the primary agency is the National Cyber Security Centre, and that CIS only becomes involved when called upon to assist in the response.
In any incident, Hickey said, his unit’s primary role is to ensure that the Defence Force’s systems are secure. The Commandant explained that the role for the Defence Forces during the HSE hack was to participate in the “recovery process” of HSE data and to get computers back working.
He said one key to the response was that there already was a very good link between the HSE and the Defence Forces as both responded to Covid-19. He said this helped to make the response a much more rapid deployment.
The task force dealing with the pandemic was not the correct command and control structure to deal with the cyber attack, so that was changed and CIS specialists developed a strategy to deal with the problem.
Some in CIS were advising while other members were dispatched to begin the process of getting the HSE computer systems back online. Hickey said that there were an estimated 12,000 HSE centres affected across the State, with a list of 49 critical locations that needed an immediate response.
To achieve that, Hickey and his team devised a strategy which saw their core response team within the CIS augmented by other teams from the various Defence Forces elements across the country.
The specialists pivoted from managing the internal communications of the Defence Forces to the frontline of a fight to save the HSE in a very short period of time – travelling across the State to find the locations to help.
“I think it was a great source of pride to be honest. A number of people would have commented it was probably one of the highlights of their career,” he said of that urgent time.
It had real world consequences beyond just an IT system, it meant that people’s health care was delayed, maybe didn’t go ahead, maybe they got sicker because of this.
You could see when the teams went down to the various hospitals, the relief on people’s faces when they have somebody coming in to support them.
“Then from our own perspective people were jumping into vehicles to go down to support these locations. It was a great sense of pride, because everybody just wanted to help.” He said they even had people coming from Galway to Dublin “because their family members were treated in a particular location that we were supporting. And they felt obliged, it was a sense of duty”.
Hickey said that the CIS Corps’ experience in the HSE cyber attack was a major learning opportunity for the unit. It was a huge opportunity to test their skills in a real world major incident.
Recent attacks
Away from the HSE, Hickey said that recent cyber attacks on Okta and Microsoft show the level of activity of criminals and bad State actors across the internet.
Advertisement
Okta is a US based company specialising in managing secure access – it was hit in March. The same South American group of hackers thought to have targeted Okta were also suspected of being behind a cyber infiltration of Microsoft.
While Russian hackers were suspected of the HSE ransomware shutdown, Hickey said that the threat is multi-dimensional, with many groups operating in states where they are enabled by rogue Governments.
“It is a mix of state actors and just criminals. But there is a grey area in the middle and there are actors who are operating within nation states, known to the governments of the states and allowed to conduct their business within the state uninterrupted,” he explained.
“(The state-backed actors) are the ones that have the most resources behind them; are the ones most persistent; and most coordinated. So from that perspective they will be one of the biggest worries, but I’d say the most realistic and most common type would be criminals that are just looking to get a payday.
“They are then targeting organisations’ networks and using ransomware and flipping their network, ransoming them looking for payments – they would be the most widespread, but then state actors would be, from a world perspective, the most persistent and most likely to do major damage,” he went on.
Hickey said that generally the method for cyber criminals is the same as that used in the HSE incident – they infiltrate the system, hijack it and then hold the victim to ransom.
“There are certainly victims who would be the private networks as opposed to State infrastructure but I’m sure State infrastructure is always under attack via our networks that are connected to the wider internet.
“So [the hackers] are all the time looking for loopholes and weaknesses – they’ll be going after all sorts of networks, including space infrastructure,” he added.
Ireland has been directly involved in international efforts and liaising with other countries taking part in large-scale exercises with other countries such as the Locked Shield event, said Hickey.
This event is organised by NATO’s Cooperative Cyber Defence Centre of Excellence (CCDCE) in Estonia and sees the world’s cyber response teams, including Ireland, come together to practice and develop ways to fight a live hacker attack.
The CIS also has an officer seconded and working at the CCDCE based in the Estonian capital of Tallinn.
Participants work during the Locked Shields exercise organized by NATO Cooperative Cyber Defence Centre of Excellence in Tallinn, Estonia. Alamy Stock Photo
Alamy Stock Photo
Looking ahead
For Hickey the next most important issue to solve is the retention crisis, and also the implementation of the recommendations by the Commission on the Defence Forces to grow CIS.
The Defence Forces has been suffering a major difficulty in retaining talented and highly skilled staff, with bodies such as the Representative Association of Commissioned Officers stating that better pay in the private sector was a major draw for members.
“To be able to retain people that we have, those that are coming through, that’s the number one thing I think, because our numbers are reducing all the time. People are leaving all of the time,” he explained.
“Recruitment is a big challenge, we’re never increasing our numbers, we’re not getting back to where we should be in terms of our current establishments.
“If we could retain our staff, it would make things an awful lot easier, it would take the pressure off people, those who are left behind are doing more and more of the work on their own, as opposed to spreading the load evenly among a number of people,” he said.
Hickey believes that the recommendations contained in the Commission on the Defence Forces would see the CIS Corps increased in strength by 100 specialists.
There are also calls to bring a direct entry capability for civilian experts to help to protect the State.
But Hickey ends on a positive note about the cyber threat: “I don’t think people should be overly concerned.
“However, it always remains a significant threat to Ireland. We saw how quickly it happened with the HSE and if that was to happen again, and to replicate across other services, it could be quite significant.
“However, I think there’s a lot of improvements in different areas. There’s the Commission on the Defence Forces report, a number of key positions being filled in the NCSC, and as long as momentum is retained I think that Ireland will be in a much stronger position into the future,” he said.
Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article.
Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.
To embed this post, copy the code below on your site
Close
7 Comments
This is YOUR comments community. Stay civil, stay constructive, stay on topic.
Please familiarise yourself with our comments policy
here
before taking part.
Give over stop worrying about cyber attacks and threats on the national security and all that hse crap. Now we have more cycle lanes. What’s not to love!! Eamonn Ryan ye legend.
The defence forces could have retained the personnel that they lost through stupidity on their own behalf in not granting these personnel with an extra €20 in tech pay which they were value for money so the same were head hunted by private companies.
@Noel O’Neill: €20 a week. You think people are leaving over €20 a week?
A CIS technician can be on as low as 40k in the DF, while their counterparts in private sector are getting 80k plus.
€20 a week…. That gave me a giggle….
It only takes one rogue machine to bring a whole network down. As long as the antvirus software is kept continuously up to date, systems shouldn’t be compromised.
@Mike Dunne: Seriously you think anti virus works like that. It is a game of cat and mouse.
You cant have an antivirus program that stops a virus it does not know. Hence the updates.
High pressure 'omega block' means warm and sunny spells are here to stay until next week
14 mins ago
388
1
trade war
Mary Lou McDonald tells Dáil that counter EU tariffs on the US are not in Ireland's interest
21 mins ago
1.2k
3
RIP
'An uber-creative firecracker': Tributes as film star Val Kilmer dies aged 65
7 hrs ago
40.1k
28
Your Cookies. Your Choice.
Cookies help provide our news service while also enabling the advertising needed to fund this work.
We categorise cookies as Necessary, Performance (used to analyse the site performance) and Targeting (used to target advertising which helps us keep this service free).
We and our 161 partners store and access personal data, like browsing data or unique identifiers, on your device. Selecting Accept All enables tracking technologies to support the purposes shown under we and our partners process data to provide. If trackers are disabled, some content and ads you see may not be as relevant to you. You can resurface this menu to change your choices or withdraw consent at any time by clicking the Cookie Preferences link on the bottom of the webpage .Your choices will have effect within our Website. For more details, refer to our Privacy Policy.
We and our vendors process data for the following purposes:
Use precise geolocation data. Actively scan device characteristics for identification. Store and/or access information on a device. Personalised advertising and content, advertising and content measurement, audience research and services development.
Cookies Preference Centre
We process your data to deliver content or advertisements and measure the delivery of such content or advertisements to extract insights about our website. We share this information with our partners on the basis of consent. You may exercise your right to consent, based on a specific purpose below or at a partner level in the link under each purpose. Some vendors may process your data based on their legitimate interests, which does not require your consent. You cannot object to tracking technologies placed to ensure security, prevent fraud, fix errors, or deliver and present advertising and content, and precise geolocation data and active scanning of device characteristics for identification may be used to support this purpose. This exception does not apply to targeted advertising. These choices will be signaled to our vendors participating in the Transparency and Consent Framework.
Manage Consent Preferences
Necessary Cookies
Always Active
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work.
Targeting Cookies
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
Functional Cookies
These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then these services may not function properly.
Performance Cookies
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not be able to monitor our performance.
Store and/or access information on a device 110 partners can use this purpose
Cookies, device or similar online identifiers (e.g. login-based identifiers, randomly assigned identifiers, network based identifiers) together with other information (e.g. browser type and information, language, screen size, supported technologies etc.) can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here.
Personalised advertising and content, advertising and content measurement, audience research and services development 143 partners can use this purpose
Use limited data to select advertising 113 partners can use this purpose
Advertising presented to you on this service can be based on limited data, such as the website or app you are using, your non-precise location, your device type or which content you are (or have been) interacting with (for example, to limit the number of times an ad is presented to you).
Create profiles for personalised advertising 83 partners can use this purpose
Information about your activity on this service (such as forms you submit, content you look at) can be stored and combined with other information about you (for example, information from your previous activity on this service and other websites or apps) or similar users. This is then used to build or improve a profile about you (that might include possible interests and personal aspects). Your profile can be used (also later) to present advertising that appears more relevant based on your possible interests by this and other entities.
Use profiles to select personalised advertising 83 partners can use this purpose
Advertising presented to you on this service can be based on your advertising profiles, which can reflect your activity on this service or other websites or apps (like the forms you submit, content you look at), possible interests and personal aspects.
Create profiles to personalise content 39 partners can use this purpose
Information about your activity on this service (for instance, forms you submit, non-advertising content you look at) can be stored and combined with other information about you (such as your previous activity on this service or other websites or apps) or similar users. This is then used to build or improve a profile about you (which might for example include possible interests and personal aspects). Your profile can be used (also later) to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests.
Use profiles to select personalised content 35 partners can use this purpose
Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services (for instance, the forms you submit, content you look at), possible interests and personal aspects. This can for example be used to adapt the order in which content is shown to you, so that it is even easier for you to find (non-advertising) content that matches your interests.
Measure advertising performance 134 partners can use this purpose
Information regarding which advertising is presented to you and how you interact with it can be used to determine how well an advert has worked for you or other users and whether the goals of the advertising were reached. For instance, whether you saw an ad, whether you clicked on it, whether it led you to buy a product or visit a website, etc. This is very helpful to understand the relevance of advertising campaigns.
Measure content performance 61 partners can use this purpose
Information regarding which content is presented to you and how you interact with it can be used to determine whether the (non-advertising) content e.g. reached its intended audience and matched your interests. For instance, whether you read an article, watch a video, listen to a podcast or look at a product description, how long you spent on this service and the web pages you visit etc. This is very helpful to understand the relevance of (non-advertising) content that is shown to you.
Understand audiences through statistics or combinations of data from different sources 74 partners can use this purpose
Reports can be generated based on the combination of data sets (like user profiles, statistics, market research, analytics data) regarding your interactions and those of other users with advertising or (non-advertising) content to identify common characteristics (for instance, to determine which target audiences are more receptive to an ad campaign or to certain contents).
Develop and improve services 83 partners can use this purpose
Information about your activity on this service, such as your interaction with ads or content, can be very helpful to improve products and services and to build new products and services based on user interactions, the type of audience, etc. This specific purpose does not include the development or improvement of user profiles and identifiers.
Use limited data to select content 37 partners can use this purpose
Content presented to you on this service can be based on limited data, such as the website or app you are using, your non-precise location, your device type, or which content you are (or have been) interacting with (for example, to limit the number of times a video or an article is presented to you).
Use precise geolocation data 46 partners can use this special feature
With your acceptance, your precise location (within a radius of less than 500 metres) may be used in support of the purposes explained in this notice.
Actively scan device characteristics for identification 27 partners can use this special feature
With your acceptance, certain characteristics specific to your device might be requested and used to distinguish it from other devices (such as the installed fonts or plugins, the resolution of your screen) in support of the purposes explained in this notice.
Ensure security, prevent and detect fraud, and fix errors 92 partners can use this special purpose
Always Active
Your data can be used to monitor for and prevent unusual and possibly fraudulent activity (for example, regarding advertising, ad clicks by bots), and ensure systems and processes work properly and securely. It can also be used to correct any problems you, the publisher or the advertiser may encounter in the delivery of content and ads and in your interaction with them.
Deliver and present advertising and content 99 partners can use this special purpose
Always Active
Certain information (like an IP address or device capabilities) is used to ensure the technical compatibility of the content or advertising, and to facilitate the transmission of the content or ad to your device.
Match and combine data from other data sources 72 partners can use this feature
Always Active
Information about your activity on this service may be matched and combined with other information relating to you and originating from various sources (for instance your activity on a separate online service, your use of a loyalty card in-store, or your answers to a survey), in support of the purposes explained in this notice.
Link different devices 53 partners can use this feature
Always Active
In support of the purposes explained in this notice, your device might be considered as likely linked to other devices that belong to you or your household (for instance because you are logged in to the same service on both your phone and your computer, or because you may use the same Internet connection on both devices).
Identify devices based on information transmitted automatically 88 partners can use this feature
Always Active
Your device might be distinguished from other devices based on information it automatically sends when accessing the Internet (for instance, the IP address of your Internet connection or the type of browser you are using) in support of the purposes exposed in this notice.
Save and communicate privacy choices 69 partners can use this special purpose
Always Active
The choices you make regarding the purposes and entities listed in this notice are saved and made available to those entities in the form of digital signals (such as a string of characters). This is necessary in order to enable both this service and those entities to respect such choices.
have your say