Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

Alamy Stock Photo

A year on: Inside the Defence Forces response against the HSE ransomware hack

We speak to an officer in the Irish Defence Forces’ Communications Information Services Corps about the HSE attack and future threats.

AN OFFICER IN the Irish military’s response to cyber threats said the State must maintain momentum to prevent future online attacks.

Commandant Frank Hickey is a senior officer in the Irish Defence Forces’ Communications Information Services Corps (CIS).  

Hickey said that attacks such as the HSE ransomware incident shows the importance of continuous growth in Ireland’s cyber defences. 

The CIS and the wider Defence Forces are not the primary agency – the responsibility for running the response to threats is owned by the National Cyber Security Centre (NCSC).

The Defence Forces, and their expertise in the area, was called upon during the health service crisis.

Hickey spoke to The Journal this week to reveal how the State’s response to cyber threats has changed since the HSE hack, the threats currently faced and how the Commission on the Defence Forces could see his team grow to better confront future attacks.

The military’s cyber defence capability is contained within the CIS Corps, and Hickey also spoke about the behind the scenes efforts of dozens of CIS teams. 

CIS are tasked with many jobs in the Defence Forces, including the operation of radio systems and IT networks, and have a number of cyber defence specialists. The soldiers and technicians in the unit were key to getting HSE systems back online after the hack.

HSESupp4 CIS personnel working to restore HSE computer systems. Irish Defence Forces Irish Defence Forces

Primary role

Hickey was eager to stress that the primary agency is the National Cyber Security Centre, and that CIS only becomes involved when called upon to assist in the response.   

In any incident, Hickey said, his unit’s primary role is to ensure that the Defence Force’s systems are secure. The Commandant explained that the role for the Defence Forces during the HSE hack was to participate in the “recovery process” of HSE data and to get computers back working.    

He said one key to the response was that there already was a very good link between the HSE and the Defence Forces as both responded to Covid-19. He said this helped to make the response a much more rapid deployment.  

The task force dealing with the pandemic was not the correct command and control structure to deal with the cyber attack, so that was changed and CIS specialists developed a strategy to deal with the problem. 

Some in CIS were advising while other members were dispatched to begin the process of getting the HSE computer systems back online. Hickey said that there were an estimated 12,000 HSE centres affected across the State, with a list of 49 critical locations that needed an immediate response. 

To achieve that, Hickey and his team devised a strategy which saw their core response team within the CIS augmented by other teams from the various Defence Forces elements across the country. 

The specialists pivoted from managing the internal communications of the Defence Forces to the frontline of a fight to save the HSE in a very short period of time – travelling across the State to find the locations to help. 

“I think it was a great source of pride to be honest. A number of people would have commented it was probably one of the highlights of their career,” he said of that urgent time.

It had real world consequences beyond just an IT system, it meant that people’s health care was delayed, maybe didn’t go ahead, maybe they got sicker because of this. 
You could see when the teams went down to the various hospitals, the relief on people’s faces when they have somebody coming in to support them.

“Then from our own perspective people were jumping into vehicles to go down to support these locations. It was a great sense of pride, because everybody just wanted to help.” He said they even had people coming from Galway to Dublin “because their family members were treated in a particular location that we were supporting. And they felt obliged, it was a sense of duty”. 

Hickey said that the CIS Corps’ experience in the HSE cyber attack was a major learning opportunity for the unit. It was a huge opportunity to test their skills in a real world major incident.

 Recent attacks

Away from the HSE, Hickey said that recent cyber attacks on Okta and Microsoft show the level of activity of criminals and bad State actors across the internet. 

Okta is a US based company specialising in managing secure access – it was hit in March. The same South American group of hackers thought to have targeted Okta were also suspected of being behind a cyber infiltration of Microsoft. 

While Russian hackers were suspected of the HSE ransomware shutdown, Hickey said that the threat is multi-dimensional, with many groups operating in states where they are enabled by rogue Governments.

“It is a mix of state actors and just criminals. But there is a grey area in the middle and there are actors who are operating within nation states, known to the governments of the states and allowed to conduct their business within the state uninterrupted,” he explained.

“(The state-backed actors) are the ones that have the most resources behind them; are the ones most persistent; and most coordinated. So from that perspective they will be one of the biggest worries, but I’d say the most realistic and most common type would be criminals that are just looking to get a payday.

“They are then targeting organisations’ networks and using ransomware and flipping their network, ransoming them looking for payments – they would be the most widespread, but then state actors would be, from a world perspective, the most persistent and most likely to do major damage,” he went on. 

Hickey said that generally the method for cyber criminals is the same as that used in the HSE incident – they infiltrate the system, hijack it and then hold the victim to ransom.

“There are certainly victims who would be the private networks as opposed to State infrastructure but I’m sure State infrastructure is always under attack via our networks that are connected to the wider internet.

“So [the hackers] are all the time looking for loopholes and weaknesses – they’ll be going after all sorts of networks, including space infrastructure,” he added. 

Ireland has been directly involved in international efforts and liaising with other countries taking part in large-scale exercises with other countries such as the Locked Shield event, said Hickey.

This event is organised by NATO’s Cooperative Cyber Defence Centre of Excellence (CCDCE) in Estonia and sees the world’s cyber response teams, including Ireland, come together to practice and develop ways to fight a live hacker attack.

The CIS also has an officer seconded and working at the CCDCE based in the Estonian capital of Tallinn.  

participants-work-during-the-locked-shields-2017-exercise-organized-by-nato-cooperative-cyber-defence-centre-of-excellence-in-tallinn-estonia-april-26-2017-reutersints-kalnins Participants work during the Locked Shields exercise organized by NATO Cooperative Cyber Defence Centre of Excellence in Tallinn, Estonia. Alamy Stock Photo Alamy Stock Photo

Looking ahead

For Hickey the next most important issue to solve is the retention crisis, and also the implementation of the recommendations by the Commission on the Defence Forces to grow CIS.

The Defence Forces has been suffering a major difficulty in retaining talented and highly skilled staff, with bodies such as the Representative Association of Commissioned Officers stating that better pay in the private sector was a major draw for members. 

“To be able to retain people that we have, those that are coming through, that’s the number one thing I think, because our numbers are reducing all the time. People are leaving all of the time,” he explained.

“Recruitment is a big challenge, we’re never increasing our numbers, we’re not getting back to where we should be in terms of our current establishments.

“If we could retain our staff, it would make things an awful lot easier, it would take the pressure off people, those who are left behind are doing more and more of the work on their own, as opposed to spreading the load evenly among a number of people,” he said. 

Hickey believes that the recommendations contained in the Commission on the Defence Forces would see the CIS Corps increased in strength by 100 specialists. 

There are also calls to bring a direct entry capability for civilian experts to help to protect the State. 

But Hickey ends on a positive note about the cyber threat: “I don’t think people should be overly concerned.

“However, it always remains a significant threat to Ireland. We saw how quickly it happened with the HSE and if that was to happen again, and to replicate across other services, it could be quite significant.

“However, I think there’s a lot of improvements in different areas. There’s the Commission on the Defence Forces report, a number of key positions being filled in the NCSC, and as long as momentum is retained I think that Ireland will be in a much stronger position into the future,” he said. 

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
7 Comments
This is YOUR comments community. Stay civil, stay constructive, stay on topic. Please familiarise yourself with our comments policy here before taking part.
Leave a Comment
    Install the app to use these features.
    Mute Rebecca Zada
    Favourite Rebecca Zada
    Report
    Jun 29th 2012, 10:20 PM

    nice one

    140
    Install the app to use these features.
    Mute Tim Jackson
    Favourite Tim Jackson
    Report
    Jun 29th 2012, 11:22 PM

    Vincent Browne is a ledgend and is the only real journalist out there that reports the issues that the public want to hear and not a load of bs that the government and the papers feed to its people every day.

    38
    Install the app to use these features.
    Mute Brenda Lawrence
    Favourite Brenda Lawrence
    Report
    Jun 29th 2012, 10:53 PM

    I’m sick to death of hearing more of the same regurgitated about the bank debt…repeating it won’t change anything. Energies are better focused on what we can do to turn things around

    97
    Install the app to use these features.
    Mute Tim Jackson
    Favourite Tim Jackson
    Report
    Jun 29th 2012, 11:00 PM

    Becaue the bank debt matters. You are paying for it with YOUR money. I’m not sure if your post is meant to be sarcastic but on the current trajectory, we are heading for a second bailout with savage austerity. If you’re ok with that, good luck!

    13
    Install the app to use these features.
    Mute Darragh Flynn
    Favourite Darragh Flynn
    Report
    Jun 29th 2012, 11:09 PM

    I hear ya Brenda. (Most) Irish peoples attitudes are a big reason I want to do a few years abroad working, not the economic crisis!

    40
    Install the app to use these features.
    Mute Aidan Kearney
    Favourite Aidan Kearney
    Report
    Jun 29th 2012, 11:04 PM

    A good news story, a murder suspect tracked down. Good work by Gardai & Interpol. a long wait for family of victim. Plenty of coverage of our banks etc … A dangerous man behind bars has to be a good result.

    89
    Install the app to use these features.
    Mute Tim Jackson
    Favourite Tim Jackson
    Report
    Jun 29th 2012, 11:13 PM

    The Police have done their job but my original point is that people on here are starting the vigilante thing. Brave computer warriors. Aren’t people more concerned about issues close to home like our banking debts that we are saddled with?

    9
    Install the app to use these features.
    Mute Darragh Flynn
    Favourite Darragh Flynn
    Report
    Jun 29th 2012, 11:19 PM

    Tim – your Facebook details alone scream anti anything other than Sinn Fein. Please reserve these ludicrous comments for relevant articles regarding government, economy, Europe (not the football) etc. otherwise stop peddling this anarchism on completely unrelated articles.nnThanks,nEvery other reader

    113
    See 1 more reply ▾
    Install the app to use these features.
    Mute Sluazcanal
    Favourite Sluazcanal
    Report
    Jun 29th 2012, 11:21 PM

    Not every story is going to be about bank debt.

    60
    Install the app to use these features.
    Mute Tim Jackson
    Favourite Tim Jackson
    Report
    Jun 29th 2012, 10:38 PM

    Can we move onto more relevant stories closer to home please. Namely, the Bank debt.

    18
    Install the app to use these features.
    Mute mart_n
    Favourite mart_n
    Report
    Jun 29th 2012, 10:50 PM

    lol.. did you just get the internet yesterday? Bank debt.. shur that’s hardly relevant these days.

    Anyways.. fair play to Interpol and our Gardai. At least something positive still exists in this debt ridden hole of ours!

    196
    Install the app to use these features.
    Mute Tim Jackson
    Favourite Tim Jackson
    Report
    Jun 29th 2012, 10:56 PM

    mart,

    You’re not as clever as you want others to believe. Few vigilantes go on a witchhunt except those with little or no news to report as a journalist. At least Vincent Browne is one respected journalist to admire – he covers issues of interest to the Irish people.

    14
    See 6 more replies ▾
    Install the app to use these features.
    Mute mart_n
    Favourite mart_n
    Report
    Jun 29th 2012, 11:01 PM

    You need to lighten up, Tim. Not everything revolves around our national debt… good things can still happen when you fell like you’re in the doldrums.

    170
    Install the app to use these features.
    Mute Sinéad O'Carroll
    Favourite Sinéad O'Carroll
    Report
    Jun 29th 2012, 11:03 PM

    Hi Tim,

    Plenty of economic stories on the site today. Here’s just one:

    http://www.thejournal.ie/explainer-eu-bank-debt-deal-anglo-irish-bank-promissory-notes-503962-Jun2012/

    Thanks,
    Sinead

    87
    Install the app to use these features.
    Mute Darragh Flynn
    Favourite Darragh Flynn
    Report
    Jun 29th 2012, 11:07 PM

    Jesus Tim, if you want to read about debt and economic woe by all means look at the titles before you click in. This is a good news story – yes, they still happen – don’t dampen it with your negativity. Good news TheJournal et al. I remember seeing the story a few weeks ago. nnNext theyve got to find DJ MorgIOS…couldn’t resist….

    106
    Install the app to use these features.
    Mute Kevin O' Brien
    Favourite Kevin O' Brien
    Report
    Jun 30th 2012, 7:26 AM

    In the end there shall be only 1

    3
    Install the app to use these features.
    Mute Gerard
    Favourite Gerard
    Report
    Jun 30th 2012, 8:09 AM

    My god Tim I’m losing the will to live reading your comments. How negative, boring and repetitive can one person be? Maybe you’re just trolling like lots of other people on this site?

    27
    Install the app to use these features.
    Mute John Mooney
    Favourite John Mooney
    Report
    Jun 30th 2012, 10:54 PM

    What Bank debt, it’s now the Irish Taxpayers’ debt. The un-named bondholders are laughing all the way to their Euro banks with our money given to them by that idiot Cowen in late night deals and now supported by this spineless government.

    1
    Install the app to use these features.
    Mute seamus mcdermott
    Favourite seamus mcdermott
    Report
    Jun 30th 2012, 1:20 AM

    If they put him in a cell with Sean Quinn, who would walk out alive?

    13
    Install the app to use these features.
    Mute Brían Corish
    Favourite Brían Corish
    Report
    Jun 30th 2012, 4:38 AM

    If they put me in a cell with him instead of Sean Quinn, he’d probably walk out alive because I would probably have died from boredom.

    21
    Install the app to use these features.
    Mute Tim Jackson
    Favourite Tim Jackson
    Report
    Jun 29th 2012, 11:19 PM

    Hyperbole media is replacing tabloid media. Personally, I no longer read newspapers that report on court cases because it’s merely an attempt to cover-up for their lack of journalism. Negative news reporting with titles like “man arrested for xyz” or “man jailed for xyz” is boorish.

    “Journalism is printing what someone else does not want printed: everything else is public relations.”

    ― George Orwell

    9
    Install the app to use these features.
    Mute Gerry McGuinness
    Favourite Gerry McGuinness
    Report
    Jun 29th 2012, 11:47 PM

    Yeah yeah yeah, whine, whine, whine, what a ball of fun your friends must find you. Life goes on with or without bank debt. I am not here forever and intend enjoying the time I am here so not planning on spending it whining.

    81
    Install the app to use these features.
    Mute jason bourne
    Favourite jason bourne
    Report
    Jun 30th 2012, 12:30 AM

    Because the bank debt matters everything else doesn’t…. Yeah, sure, nice one… Go away, your boorish

    41
    Install the app to use these features.
    Mute Chuck Eastwood
    Favourite Chuck Eastwood
    Report
    Jun 30th 2012, 11:51 AM

    Tim ( bank debt ) Jackson. Has a nice ring to it. As many here have pointed out there are a couple of stories here day to day on the dealings of the banks and they like of scoundrels like Quinn. This is the journal.ie not bankdebt.ie. it was interesting to see some post about your Facebook saying your were pro SF. Is it any wonder you are not find of Interpol. Half the shiners are on the run with a boot full of stolen ink

    4
    Install the app to use these features.
    Mute Chuck Eastwood
    Favourite Chuck Eastwood
    Report
    Jun 30th 2012, 4:27 PM

    Edit .Fond of interpol. Thanks you and goodnight.

    1
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.

Leave a commentcancel

 
JournalTv
News in 60 seconds