Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Critical Infrastructure Security - Cybersecurity Concerns Arise After Announcement to Scrap NHS England
Critical Infrastructure Security News & Analysis Security

Cybersecurity Concerns Arise After Announcement to Scrap NHS England

Adam ParlettBy Adam ParlettMarch 17, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
NHS
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In the wake of Sir Keir Starmer’s announcement that NHS England, the body with many responsibilities relating to cybersecurity, will be scrapped to cut costs and improve efficiency, questions around cybersecurity have been raised relating to the NHS’s ability to prevent cyberattacks. 

NHS England is an administrative body established in 2013 that operates separately from the UK government but is guided by it. The service manages how health services in England (other UK countries have separate organizations) operate in relation to things away from the frontline, such as training and data collection. 

Relating to cybersecurity, its current responsibilities include ensuring that the outcome of cyber security assessments is acted upon and that organizations register to the Respond to an NHS Cyber Alert service, act on advisories when they are issued, and submit remediation plans. 

Good News? 

Any move designed to save taxpayers money, cut bureaucracy, and restore democratic control must be good news, right? The government insists it is, but the level of disruption this will bring presents opportunities for cybercriminals. 

We recently reported on an NHS investigation into an alleged API flaw emanating from an online healthcare provider working with the NHS that may have exposed confidential patient information. 

Owing to the continued outsourcing of NHS services and the critical need for APIs that facilitate real-time medical data sharing, our featured expert in the article questioned whether it was best for organizations to be ‘marking their own homework’. Currently, outsourced providers are not contractually obliged to have a third party test their systems before using live public sector data. Will gaps like these be more likely to be resolved or exasperated by the removal of NHS England? 

Oversight and Implementation 

Although not perfect by any means, there are frameworks in place that are experiencing ongoing development. Back in September 2024, the NHS Data Security and Protection Toolkit for 2024-25 adopted the National Cyber Security Centre’s Cyber Assessment Framework (CAF) as its foundation for cyber security and information governance assurance. As a result, NHS Trusts, integrated care boards (ICBs), commissioning support units (CSUs), and arm’s-length bodies (ALBs) experienced a revised interface that outlines requirements aligned with the CAF in terms of objectives, principles, and outcomes. 

Organizations are required to assess themselves against the updated requirements by June 30, 2025. If they cannot meet the required achievement levels, they must submit an improvement plan by June 30, 2026. Failure to agree on a plan will result in receiving a 2024-2025 DSPT status of “Standard Not Met,” indicating a lack of an approved plan for achieving necessary cybersecurity and information governance levels. 

Analysis 

Cybersecurity expert Graeme Stewart, head of public sector at Check Point Software, believes that the move to disband NHS England could potentially leave the NHS vulnerable.  

He likened the removal of the centralized cybersecurity infrastructure to “a hospital suddenly removing its emergency department and expecting patients to fend for themselves.” Adding that “At present, NHS England provides the backbone for our cyber defenses, from a unified email service to specialized threat protection. Removing these central functions risks leaving individual NHS Trusts to fend off cyberattacks with a patchwork of under-resourced teams.” 

He also echoed our sentiments about raising security concerns over the regulation of third-party suppliers offering outsourced NHS services. Speaking on how the removal of a centralized service presents an opportunity for an influx of third parties, he posited that “While more suppliers might seem like a win for competition, it also fragments our defense and leaves us vulnerable; each new supplier is a potential weak link in our security armor.” 

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The evolution of cyber risk: Addressing geopolitical threats

May 13, 20265 Mins Read

“Recovery Is the New Prevention”: a Q&A with CSO of Health-ISAC, Errol Weiss

May 7, 20266 Mins Read

Pro-Russian threat actors target Swedish heat and power plant in failed cyberattack

April 20, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}