MTU outlines measures which have 'strengthened' cybersecurity

MTU was hit by a significant ransomware attack in February 2023, paralysing much of its IT systems
In its latest annual report, MTU details the steps it has taken, and is continuing to take, to protect itself and its staff and students from cyber attacks. Picture: Denis Minihane

In its latest annual report, MTU details the steps it has taken, and is continuing to take, to protect itself and its staff and students from cyber attacks. Picture: Denis Minihane

Munster Technological University (MTU) has introduced a range of measures that “significantly strengthens” its cybersecurity systems to future attacks.

In its latest annual report, MTU details the steps it has taken, and is continuing to take, to protect itself and its staff and students from cyber attacks.

Home to around 18,000 students and 2,000 staff, MTU is spread across six campuses in Cork and Kerry, and boasts a large number of high-tech research centres, including in computing and engineering.

MTU was hit by a significant ransomware attack in February 2023, paralysing much of its IT systems. A Russian-based cyber-crime group, BlackCat, was cited by the MTU in the courts as being the suspected perpetrators.

BlackCat had encrypted systems and demanded ransom be paid by the college, otherwise it would publish confidential information of staff and students.

The college said no ransom was paid and had secure backups which facilitated full system recovery.

But the costs of the IT response, recovery and resilience projects were significant, estimated by the Government at around €3.5m.

The response project involved a significant data analysis and notification process, in accordance with the University’s data protection obligations.

MTU was hit again last February but this was the indirect result of a cyber attack on a US-based education software company, that provided learning tools to colleges around the world, including MTU and UCC.

It affected the Irish colleges on a Thursday night, so it was described as having limited impact.

In its annual report, covering September 2024 to August 2025, MTU details cyber-related legal and professional costs:

  • €498,000 was paid out in cyber consultancy fees in the year ending August 2023 and a further €79,000 in the year ending August 2024;
  • €199,000 was paid out in cyber-related fees in relation to legal costs and settlements in the year ending August 2024 and a further €43,000 in the year ending August 2025. 

The report said: “Following a cyber ransomware attack in February 2023 a large body of work is underway across the MTU IT environment to best align IT systems with leading practices in relation to both IT security, risk, data compliance, hybrid environment recovery, and monitoring.” 

It said it commissioned consultancy firm KPMG to review and implement many measures, either now concluded or ongoing, including:

Managed service vendor has been appointed to “actively monitoring logs from network devices and systems across the MTU campus and hybrid cloud environment”;

  • SAOR software platform is being used, which helps cybersecurity teams “collect threat data, connect different security tools, and run automated workflows to fix security incidents”;
  • Deployment of 4,800 “endpoints”, which are described as any physical or virtual device that connects to a corporate or private network and can send, receive, or process data;
  • Network segmentation has been implemented across both the Cork and Kerry Campus, which separates various critical systems and restricts access across the systems, making them more secure.

  • Cormac O’Keeffe is Security Correspondent.

More in this section

Lunchtime News

Newsletter

Get a lunch briefing straight to your inbox at noon daily. Also be the first to know with our occasional Breaking News emails.

Cookie Policy Privacy Policy Brand Safety FAQ Help Contact Us Terms and Conditions

© Examiner Echo Group Limited