
What happened
On 14 May 2021, Ireland's Health Service Executive was hit by a human-operated Conti ransomware attack that, as the country's National Cyber Security Centre recorded at the time, severely disabled a number of systems and led the HSE to shut down the rest of its network as a precaution. A related, separate intrusion attempt against the Department of Health's network around the same time was detected and stopped before ransomware could execute. According to Ireland's national audit office, which reviewed the incident and the independent post-incident review the HSE commissioned from PricewaterhouseCoopers, full access to HSE systems was not restored until late September 2021, more than four months after the attack began.
Confidence and limits
The national cyber centre's contemporaneous alert and the audit office's later report, which quotes the independent review at length, agree on the attack date, the ransomware involved, and the shutdown decision. This article draws the specific findings of PwC's independent review, such as its description of a frail, legacy-dependent IT estate and its 83 key recommendations, from the audit office's account of that review rather than from the review document itself, which could not be retrieved directly; readers who need the review's exact wording should consult it directly rather than rely on this summary alone.
Why it mattered
The audit office's account describes an IT estate that had evolved rather than being designed for resilience, with a flat network structure that meant a trust relationship between the HSE and connected hospitals could carry an attacker from one organisation's network into another's. That same flatness worked in the defenders' favour once monitoring caught the intrusion early: the Department of Health and Beaumont Hospital both detected suspicious activity on their own systems in time to block the ransomware before it executed, while the HSE itself did not. The difference between those outcomes came down to which organisation's monitoring caught the activity first, not to any difference in the underlying network architecture.
Defensive takeaway
If your organisation shares a trust relationship with other networks, such as an active domain trust with a partner organisation, review whether that relationship could carry an intrusion in either direction, and invest in continuous, not business-hours-only, network monitoring.
- Would your monitoring detect suspicious activity outside normal business hours, before an attacker executes a ransomware payload?
- Do you know every external organisation whose network has a trust relationship with yours, and what that relationship could carry?
- How long would full recovery take if your primary systems were encrypted today, and have you tested that estimate?
Two organisations connected to the same attacker, on the same day, had very different outcomes because one caught the activity before execution and one did not, which is a narrower and more actionable lesson than the scale of the disruption alone suggests.
Review whether any trust relationship with a partner network could carry an intrusion in either direction, and invest in continuous, not business-hours-only, monitoring.
Ireland's National Cyber Security Centre and national audit office agree on the attack date, the ransomware and the shutdown. Specific findings of PwC's independent review are drawn from the audit office's account of it rather than from the review document itself, which could not be retrieved directly.
Sources & reading trail
Ireland's national CSIRT records the 14 May attack date, the Conti ransomware, the precautionary shutdown, and the related near-miss at the Department of Health.
government-primary · Source published: 16 May 2021 · Retrieved: 16 September 2026
Ireland's national audit office, drawing on PwC's independent post-incident review, records the review's findings, its 83 key recommendations accepted by the HSE Board in November 2021, and the restoration timeline.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.