NHS: Cybersecurity
The question
To ask the Secretary of State for Health and Social Care, what assessment he has made of the cyber security risks associated with the expansion of NHS digital infrastructure.
Answered by Preet Kaur Gill
Cyber security is a key enabler for the shift from analogue to digital envisaged in the 10-Year Health Plan for England.
Our cyber security strategy, Cyber resilient health and adult social care system in England, sets out the importance of cyber security in ensuring patient and service user safety and details our vision for a cyber resilient health and social care system by 2030. Pillar one of the strategy is to focus on the greatest risks and harms. As part of this approach, the Department and NHS England monitor cyber risk across the sector, and assist organisations with the management of their own cyber risks.
The Data Security and Protection Toolkit (DSPT) is the main tool we use to manage cyber risk. It provides the minimum level of cyber security and information governance that health and care organisations must meet. It is revised annually to increase the standard in line with the changing cyber threat. Through the DSPT, organisations provide assurance on an annual basis that they are practising good data security and that personal information is handled correctly.
We are supporting organisations to manage cyber risk through an ambitious Cyber Improvement Programme. Since 2025/26, we have invested £75 million in the cyber security of health and social care, building on the £375 million invested since 2017.
This programme includes initiatives such as the Cyber Data Platform to better understand risk posture across the system, which in turn will allow for refinement of risk reducing interventions. Our understanding of the risk and our response to it is constantly evolving in line with the cyber threat and the expanding digital footprint of the National Health Service.
In addition, NHS England runs a Cyber Security Operations Centre that is able to monitor over 1.8 million devices across the NHS, identifying and responding to threats as they arise. When critical cyber vulnerabilities are identified, NHS England issues a High Severity Alert to warn NHS organisations.
Nevertheless, cyber incidents, including WannaCry in 2017, Advanced in 2022, and Synnovis in 2024, show that it is a matter of when, not if, the next cyber-attack impacting the NHS will take place. The impact of cyber incidents can be severe, including cancelled appointments, delays, or data breaches. Therefore, preparing for and responding to incidents is also an important part of our programme.
Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →