Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - NHS At 70 And The Role Of Cybersecurity
Articles

NHS At 70 And The Role Of Cybersecurity

ISBuzz TeamBy ISBuzz TeamJuly 17, 20185 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The UK’s National Health Service is celebrating its 70th anniversary this year. To coincide with this, the UK government has made a big financial commitment to the service’s future. The NHS annual budget of £114 billion will rise by 3.4 percent a year.

Technology is one of the four main pillars to be covered in a new 10-year plan that’s supported by this new funding. But, as the service was seriously disrupted by cyber-attacks only a year ago, there is clearly a need to consider cybersecurity as part of any future investment in new technology.

The challenge of protecting NHS from cyber-attacks is complicated by its vast size and complexity. In England alone, the NHS is the largest public-sector employer with over 1.4 million staff. Medical services are accessed and delivered through a network of close to 500 hospitals and over 3,500 GP surgeries dotted across the UK. Despite the ‘national’ in its name, NHS reforms have meant the service is run on a very regionalised basis with local budgets and budget decision-makers, making it difficult for the NHS to coordinate a response to prevent or recover from a cyber-attack.

At the same time, the service has a chequered history of digitisation. For many years, there have been plans and targets to modernise how the NHS collects and shares patient information digitally. While progress has been difficult, the NHS is committed to digitisation where it can deliver better medical outcomes and patient experience.

Cybersecurity has a positive role in how it can facilitate the use of digital technologies across the NHS. It also can improve trust in how the NHS uses and shares data, especially critical when many patients and patient groups have expressed serious opposition to projects in this field in the past. However, cybersecurity for cybersecurity’s sake isn’t appropriate when what’s of prime importance to the NHS is that patient services are never interrupted by another cyber-attack.

The great lesson of the WannaCry incident wasn’t how the ransomware caused problems but because NHS IT teams didn’t know the extent of the threat and had to turn off IT systems. There was no operational crisis management in place in the event of an attack, with the outcome being that no individual, region or even central government body knew the extent or level of attack impact. It was this lack of clarity and certainty that meant a shutdown was the only option, which was what then directly disrupted medical services on an alarmingly wide scale.

A clear goal of the 10-year plan will be how technology helps deliver excellent medical services and outcomes for patients. Cybersecurity must serve this end but must not get in the way. 

As WannaCry demonstrated, greater visibility of threats and vulnerabilities is key but not if it simply hands a small and overstretched team of NHS IT specialists an even longer to do list. There is great expertise and skill within the NHS, but the reality is the service cannot retain enough staff with top cybersecurity skills when it has rigid pay structures and competes with the private sector which can pay much more.

So, NHS IT teams are desperate for practical support that will help direct priorities, as well as technology that can automate much of the workload of mitigating vulnerabilities effectively. The answer is threat and vulnerability management solutions that use current threat intelligence to cut through the noise of vulnerabilities – which in large, complex networks can range in the millions – and more accurately prioritise remediation.

A threat-centric vulnerability management approach focuses action on the small subset of vulnerabilities most likely to be used in an attack – and often, those vulnerabilities are not the most obvious ones.

The solution must also have at its core the ability to consider network context, which comes from being able to model the entire hybrid network, including the security controls in place. This is key in situations where patching may not be an option, or when the team needs to consider more expedient, cost-effective or lower risk options, depending on the environment. This may include relying on existing security controls such as IPS signatures, changing firewall or security tags and adjusting configurations. The threat-centric approach not only has the greatest impact on risk reduction, it increases the efficiency and effectiveness of vulnerability management teams.

How this might be applied in NHS as digitisation is rolled out more widely? Empower NHS IT teams with technology that breaks down data silos by merging together all the information about the network into a single repository of truth, including assets, network topology, existing security controls, vulnerabilities and threats. This provides the foundation of network visibility and context that’s needed to identify and assess risks and security priorities clearly and – more importantly – efficiently address them without interrupting medical care or placing additional burden on the limited NHS IT resources.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}