Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - The Real Diagnosis For The Health Of NHS Cybersecurity
News & Analysis

The Real Diagnosis For The Health Of NHS Cybersecurity

ISBuzz TeamBy ISBuzz TeamJuly 4, 2019Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
chinese hackers
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The FDA has warned Americans that hackers could compromise insulin pumps by connecting to them via Wi-Fi. A 2017 study from the Technology and Health Care journal found that the US healthcare industry doesn’t keep up with new cybersecurity precautions, this is despite a 2018 study from medical journal Maturitas found that medical devices — including insulin pumps and pacemakers — are highly vulnerable to cybercrime.  

In contrast, a study from Infoblox found that in the UK, the number of security policies in place for new connected devices has increased from 85 to 89 percent, with fewer respondents doubting the effectiveness of these policies (9% in 2019/13% in 2017). This signals a big step forward for the UK, particularly after the disaster that was WannaCry two years ago, and shows that the US could have something to learn from how the UK healthcare system has addressed security vulnerabilities. In saying that, the NHS still has a way to go to modernise its infrastructure, as noted in another recent report raising concerns about the possibility of another WannaCry scale attack.  

Interestingly, despite ongoing concerns, a Veracode study found that globally, the healthcare sector is the fastest industry when it comes to addressing common vulnerabilities found in software. The global report found healthcare organisations took only six days to address a quarter of their vulnerabilities in code and just seven months (216 days) to remediate the majority (75%) of vulnerabilities. That’s almost eight months faster than the average organisation who is taking 15 months (472 days) to fix 75% of its vulnerabilities.   

In light of mounting pressure for the healthcare industry to address security vulnerabilities paired with mixed reports on its success so far, security experts commented below on the importance of cyber security when it comes to health organizations which holds critical information of individuals. 

The National Health Service might be at risk of cyber attacks, a new white paper on NHS cybersecurity has said. https://t.co/efMsWICTlL

— euronews (@euronews) July 3, 2019

Experts Comments:  

Rob Bolton, Director of Western Europe at Infoblox:   

“The widespread disruption caused by the WannaCry attack on the NHS two years ago was a wake-up call to healthcare providers everywhere. We can expect the risk of such attacks to continue to grow as technology is more widely adopted. It’s encouraging, therefore, to see more spending on cyber-security provision, and a more sensible approach to managing the connected devices that have become increasingly crucial to the efficient delivery of care.  

By taking such precautions, healthcare IT providers are right to be more confident about their ability to tackle threats to their network. They mustn’t become complacent, though, and must continue to think strategically about ensuring the security of their networks and – most importantly – the safety of their patients.” 

Paul Farrington, EMEA Chief Technology Officer at Veracode:   

 “Healthcare organisations are remediating at the most rapid rate at every interval compared to their peers. It takes just a little over seven months for healthcare organisations to reach the final quartile of open vulnerabilities, about eight months sooner than it takes the average organisation to reach the same landmark.  

It shows remarkable resilience for an industry which was heavily targeted and badly damaged during the WannaCry ransomware attack two years ago. However, millions of cyber-attacks are aimed at the healthcare sector each day, seeking any weak spot. Using code that is secure from the start can help healthcare reduce security risk further.”   

Barry McMahon, Senior Manager International Marketing at LogMeIn: 

“It is unfortunately not surprising that the NHS Cyber Security White Paper found that the health service remains vulnerable to cyber-attacks. In order to avoid another WannaCry attack, it is true that the Government must take steps to modernise out-dated computer systems and invest further into the digitisation of the NHS.    

“That being said, the risks presented to the NHS are not exclusively the product of antiquated IT systems. Rather, poor password practices among NHS workers can be just as detrimental and risk making patient data vulnerable to cybercriminals. Our 2018 Global Password Security report found that, while 91% of respondents are aware that using the same password for multiple accounts is a security risk, 59% admit to having done so.   

“Additionally our recent research revealed that 92% of organisations surveyed experience challenges when it comes to identity management. Implementing multi-factor authentication and single-sign-on solutions can help companies by adding multiple layers of security to ensure that data remains secure.   

“The reality is that every person with a password is a potential access point, and the only way to change people’s habits and behaviours is to educate and provide easy-to-use tools and apps that they can also use in their everyday personal life. Security is not just for the workplace, it’s just as important in the home environment, given a high percentage of people use the same passwords for personal and workplace logins. Security and positive user-experience should not be traded off against each other, they can co-exist, it’s a matter of finding the right blend of services.   

“Therefore, while digital transformation is indeed vital to protecting data, we must also go back to basics and ensure that NHS employees working with sensitive information are up to scratch with password hygiene and ensure that their workplace credentials remain secure. Only then can NHS databases remain secure, keeping patient data safe and making another WannaCry far less likely in the process.” 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}