Ireland, like the rest of Europe, is “absolutely involved in a hybrid war”

By Ben Davern

Former Defence Forces Chief Mark Mellett and cybersecurity leader Jacky Fox warn that national security, economic security and technology are becoming increasingly interconnected, requiring a broader approach to resilience and leadership

Ireland, like the rest of Europe, is already involved in a form of hybrid warfare and faces growing exposure to cyberattacks, threats to critical infrastructure, disinformation and geopolitical disruption, former Chief of Staff of the Defence Forces Mark Mellett has warned.

Speaking at an Irish Management Institute (IMI) Senior Leaders Breakfast Briefing for corporate members, Leadership in an Age of New Threat, Mellett said the nature of security has changed significantly, with threats increasingly extending beyond conventional military action.

“We need to recognise that we live in a period of profound vulnerability. Ireland, like the rest of Europe, is absolutely involved in a hybrid war at present,” he said.

Drawing on arguments developed in his forthcoming book, Blue Heart: War, Climate and the Battle for the Ocean That Keeps Us Alive, Mellett said the boundaries between national security, economic security, energy security, climate security and the protection of critical infrastructure are rapidly disappearing.

He was joined at the briefing by Jacky Fox, Global Digital Core Secure Lead at Accenture and Vice-Chair of Cyber Ireland, who said the same changing geopolitical environment is forcing organisations to reconsider assumptions around technology, global integration and cybersecurity.

Together, their warnings point to a security environment that is no longer the preserve of governments, defence forces or technical specialists and has potentially massive ramifications for business leaders.

A different kind of threat

Mellett cited the 2021 cyberattack on the HSE and Russia’s plans to conduct naval exercises within Ireland’s exclusive economic zone in early 2022 as examples of threats to the State that extend beyond conventional warfare.

For Mellett, the HSE attack demonstrated how an incident that begins in the digital environment can quickly affect essential services, economic activity and wider public confidence.

“Cyber and cyberattacks are really a means to an end,” he said during the briefing.

The HSE attack also provided Fox with a direct example of the challenges involved in responding to a major cyber incident.

Fox said she was called in to help assemble a task force following the attack. The incident took place during the Covid-19 pandemic, limiting the ability to bring specialists physically into Ireland.

“I had to go to all of my competitors and say, come on, we need to live here together and go against this,” she said.

Fox contrasted cyber incidents with other forms of infrastructure disruption.

When a major storm threatens electricity infrastructure, there may be time to identify its path and bring in engineers from elsewhere in Europe. Countries regularly support one another in restoring physical infrastructure. Cyberattacks operate differently.

The impact can be immediate and, when one country or organisation is being attacked, others may simultaneously be preparing for the possibility that they will be next. Fox noted the HSE response demonstrated the importance of having trusted networks already in place.

Sovereignty and interdependence

Mellett said Ireland’s exposure also requires a more precise understanding of sovereignty.

“In a globalised world, nobody is neutral. You’re completely dependent on lines of communication through fibre-optic cables, international monetary systems, trade and more,” he said.

He described this as a “sovereignty paradox”, arguing that the discussion cannot focus solely on national autonomy when modern states are dependent on international systems and one another.

“If we get obsessed in terms of talking about sovereignty, we should be talking about interdependence and collaboration,” he said.

That distinction also informed his comments on Irish neutrality, and Mellett drew a clear distinction between neutrality and military non-alignment.

“Ireland is militarily non-aligned. That is different from suggesting that we are somehow neutral in relation to the values we uphold, the international rules-based order on which we depend or the threats that affect our security and prosperity.”

Responding to a question about Ireland’s triple lock, he said the debate should not obscure the principle that decisions regarding the deployment and use of the Defence Forces remain the responsibility of the democratically elected Government.

“The triple lock debate or discussion—it’s a non-story,” he said.

“We’re not a neutral state. We can’t be a neutral state in a globalised economy where we depend on others for trade and for so much more. We’re militarily non-aligned.

“Ultimately, decisions about the use of our Defence Forces must remain with the sovereign Government, accountable to the Irish people and acting in accordance with our Constitution and laws.”

Mellett said no individual country can now provide entirely for its own security. This makes domestic capability important, on hand, but also increases the importance of cooperation between countries and institutions.

Europe’s technology dependence

Fox identified a similar challenge in technology.

Much of the technology on which European organisations increasingly depend is not developed in Europe. This creates potential vulnerabilities if international relationships change or export restrictions are introduced or access to strategically important technologies becomes more tightly controlled.

Fox pointed to emerging cryptographic technologies as one example, arguing that Europe is heavily dependent on capability developed elsewhere. She also raised concerns about Europe’s relative position in artificial intelligence.

“In order to have some kind of European sovereignty, I believe that as Europe, we should be investing in both AI and cryptographic controls to make sure that our future as Europe is safe independently from having to rely on other people outside,” she said.

Her argument wasn’t pushing for technological isolation, rather that organisations and governments need to understand where reliance on technologies developed elsewhere could become a strategic vulnerability.

“If we all end up kind of holding hands and getting on forever, great,” Fox said. “But if we don’t, and the world is unpredictable, we’ve seen that in the last couple of years, then we really probably need to be thinking a little bit more seriously about this in Europe.”

Fox said Europe is stronger in some areas, including regulation and identity, but should consider whether it has sufficient indigenous capability in technologies that will become increasingly important to economic and national security.

“We have been living in a bubble”

Mellett argued that greater international cooperation also needs to be matched by stronger capability within Ireland.

“We have been living in a bubble since the foundation of the State. We haven’t been paying our way in terms of the defence architecture required,” he said.

“If we claim jurisdiction over almost one million square kilometres and we don’t know what’s happening out there, we don’t have sovereignty—or we don’t have meaningful sovereign rights.

“Ireland needs to get its act together and start building its own infrastructure here.”

However, Mellett said increased investment in defence and security should not simply be viewed as a cost.

Developments in Ukraine have demonstrated the growing importance of robotics, automation, artificial intelligence and integrated networks to modern defence.

He argued that Ireland could build on its existing technology ecosystem to develop capability that has both defence and civilian applications.

“It doesn’t need to be a cost centre. It could actually be an investment and, ultimately, a profit centre if we developed our technological capabilities,” he said.

“We should nurture a defence and dual-use technology sector in Ireland, which would also strengthen our broader security capabilities. There is a massive opportunity for us here.”

Mellett also argued that Ireland should be discerning about where future investment goes, pointing to the rapid technological change in military capability seen during the war in Ukraine.

From integration to the ability to separate

For global businesses, Fox said geopolitical uncertainty is beginning to change another long-standing assumption.

For decades, organisations have worked to integrate operations internationally. Finance systems, technology platforms, data and specialist expertise have increasingly been connected across jurisdictions.

But companies are now asking whether that integration can be reversed quickly if circumstances require it.

Fox said organisations increasingly want to know whether they could ring-fence operations in one country from operations elsewhere while retaining the benefits of global integration during normal conditions.

“I want to keep that going for now. But if a day happens that I want to press a big red button, can I?” she said of the questions organisations are now asking.

Fox said she has already seen organisations facing criminal or politically motivated attacks having to separate operations across different countries rapidly, something which is not straightforward.

Companies operating in sectors such as food, financial services or critical infrastructure cannot necessarily withdraw from a jurisdiction overnight without creating wider consequences.

The result is a new operational question for global businesses: how do organisations maintain the advantages of international cooperation while retaining the ability to limit that cooperation quickly when necessary?

“There’s still trust, but it’s not quite as global as it used to be,” Fox said.

From prevention to resilience

Mellett said the same uncertainty requires a different approach to organisational preparedness, as governments and organisations cannot expect to prevent every cyberattack or infrastructure failure.

“Rather than trying to prevent every attack, you need to war-game the consequences: how can I build the resilience to absorb a hit and recover?”

He identified situational awareness, resilience and collaboration as critical capabilities in responding to hybrid threats.

Situational awareness means understanding what is happening and where vulnerabilities exist, while resilience means having the capacity to absorb disruption and recover. Collaboration is essential because increasingly complex threats cross organisational, sectoral and national boundaries.

“There isn’t a counter-hybrid army” that can simply be deployed against these threats, Mellett said. The response instead depends on building capability across different parts of society.

Fox’s experience during the HSE attack provided a real-life example of that approach. As the expertise needed to respond did not sit inside a single organisation, competitors that would normally operate independently needed to work together because the scale of the incident required collective action.

AI and a new category of cyber risk

Fox also identified artificial intelligence as an emerging challenge for cybersecurity.

She stressed that she is a strong supporter and user of AI and works with organisations deploying the technology, but the pace of development means there is limited historical experience on which organisations can draw when deciding how increasingly capable AI systems should be controlled.

“Nobody in the world has years of experience of putting guardrails around AI,” she said.

Cybersecurity creates a particular difficulty because AI capabilities can have legitimate defensive uses while the same capabilities can also be used maliciously.

Fox described cybersecurity as a “dual use” environment in which distinguishing between offensive and defensive activity is not always straightforward.

The challenge isn’t necessarily an argument against AI, she said, but another example of organisations moving into areas where established assumptions around risk and control may no longer be sufficient.

That makes leadership judgement important alongside technical expertise.

The growing problem of “cyber inequity”

The security challenge is also distributed unevenly.

Fox highlighted what the World Economic Forum has described as “cyber inequity”: the gap between organisations that have the resources to invest heavily in cybersecurity and those that do not.

Smaller and mid-sized businesses increasingly face sophisticated threats while operating with fewer financial and technical resources. At the same time, those organisations frequently form part of the supply chains of much larger companies.

Fox said regulation is increasing the cybersecurity standards expected of suppliers but warned that there can be unintended consequences if the cost of meeting those standards becomes too high.

“What you might do is put a lot of organisations out of business because they can no longer comply with the rules that they have to,” she said.

“But you also end up with a concentration risk if you do that, because then you only have a finite number of suppliers that you can pick from. So you’re going to stifle innovation.”

The result is a difficult balance. Stronger standards can increase security at the level of an individual company while simultaneously reducing the number of viable suppliers and concentrating dependency among fewer providers.

Fox said larger organisations therefore have a role in helping smaller businesses in their supply chains to improve cybersecurity capability. She also pointed to initiatives involving Ireland’s National Cyber Security Centre and indigenous cybersecurity providers aimed at supporting smaller organisations.

Energy security and national resilience

Mellett noted the same questions around dependence and resilience apply to Ireland’s energy security, arguing that Ireland needs to accelerate the development of indigenous renewable energy to reduce its vulnerability and strengthen its energy sovereignty.

The issue reflects one of the central arguments in Blue Heart: that the ocean, climate, energy, economic prosperity and security are increasingly interconnected.

Ireland’s maritime area creates significant potential for offshore renewable energy, and Mellett argued that developing that capacity could strengthen domestic resilience while positioning Ireland to contribute more to Europe’s future energy requirements.

He also linked the issue to Ireland’s wider technology economy, arguing that the country should not approach the energy demands of data centres solely as a constraint.

“If we lose that lead we have, we will not regain it,” he said of Ireland’s position in the wider technology ecosystem.

According to Mellett, the wider opportunity is to address vulnerability while also building new economic capability.

Trust, institutions and leadership

Not every element of the new security environment involves physical or digital infrastructure. Mellett also identified disinformation and declining trust in institutions as significant vulnerabilities.

“It is a leadership issue, and institutions cannot defend themselves,” he said.

“The integrity and calibre of the leader become the face of the institution. Institutions fall away if their leadership does not take on the battle.”

He argued that leadership includes actively defending the institutions and values on which democratic societies depend.

Asked during the briefing whether institutions such as the United Nations had become ineffective, Mellett rejected the idea that responsibility could simply be transferred to the institution itself.

“We are the UN. We are the UN,” he repeated, arguing that international institutions ultimately depend on countries continuing to participate in and strengthen them.

The same principle applies within organisations, and Mellett argued that trust cannot be created for the first time during a crisis.

“We use the word ‘trust’ like confetti at a wedding,” he said.

Trust, he argued, is better understood as trustworthiness developed through relationships over time.

Similarly, in complex organisations, leaders will rarely possess every piece of expertise required to deal with a major disruption, but they must have access to people and networks that do.

Those relationships need to be developed before they are required, and the experiences described by both Mellett and Fox point to a similar conclusion.

Security is increasingly shaped by connections: between countries and between organisations, between technology providers and their users, between large companies and their suppliers, and between leaders and the networks they rely upon.

That creates vulnerabilities, but neither Mellett nor Fox argued that the answer is simply to retreat from interdependence. Instead, the challenge is to understand those dependencies and strengthen capability where vulnerabilities are greatest and ensure that organisations and institutions can continue to operate when disruption occurs.

For leaders, that means security can no longer be treated as a specialist issue sitting elsewhere in the organisation. It’s increasingly part of the broader responsibility of leading through a more contested, interconnected and uncertain environment.

#Critical Infrastructure #Cyber Resilience #Cybersecurity #Geopolitical Risk #Hybrid Threats #National Security #Organisational Resilience