NHS IT, Records and Data

23.01.17

Exclusive: Rate of NHS cyber-attacks quadruples in just four years

While provider spending on cyber security measures has remained broadly stable since 2013-14, the rate of cyber-attacks suffered by trusts – even excluding unsuccessful attempts – has more than quadrupled in the past four years, an NHE investigation has found.

The Freedom of Information (FoI) investigation identified that spending across the 75 trusts and FTs that were able to provide this data showed investment in cyber security has, amongst them, broadly remained around the £18m mark since 2013.

However, cyber-attacks, including growing rates of ransomware threats, grew from 1,565 reported cases in 2013-14 to 7,178 so far this financial year. This data excludes recorded unsuccessful attempts, such as the hundreds of thousands of phishing emails trusts receive regularly.

The FoI request was sent to England’s 253 trusts and FTs. Of the 158 who responded (62.5%), a total of 125 providers agreed to supply their data on cyber-attacks, while 33 either withheld information or didn’t collect it altogether. Those that supplied their data revealed a worrying trend of rising attacks in the NHS, with figures more than quadrupling since 2013-14.

This is, however, also partly influenced by changing methods of data collection and a greater awareness amongst staff. For example, Staffordshire and Stoke-on-Trent NHS Trust said the 40 phishing emails detected so far in 2016-17 were mostly reported by staff due to an “increased effort to raise awareness of email security”.  

Other trusts also revealed that staff have to take part in monthly or yearly cyber security training, and trust communications are often sent out to advise employees on the dangers of attacks and growing rates of ransomware threats.

Nevertheless, the findings closely follow major incidents of cyber-attacks on the NHS which have recently made it to national news, most notably the ransomware attack on Barts Health this month – which forced the trust to take systems offline – and the attack on North Lincolnshire and Goole NHS FT in October.

The latter had to cancel around 2,800 patient appointments after being hit with what it later confirmed to NHE was a variant of ransomware called Globe2. Although the issue was eradicated and systems were up and running within 48 hours, police were called to investigate the issue.

“As the police regional cybercrime unit’s investigation is still in progress, it could be prejudicial to publish any further detail about the case, including the exact details of how the perpetrator gained access,” a North Lincolnshire spokesperson told NHE.

“However, we can confirm that recent publicly reported information alleging that access was gained through a USB stick or due to remote working have no grounding in fact. We can assure our patients and other stakeholders that we acted swiftly to enhance our existing cyber security but in order to maintain security and support the police investigation, we are unable to share specific information on the exact steps we have taken.”

But writing for the latest edition of NHE (January/February), NHS Digital’s head of security, Dan Taylor – who argues cyber-attacks “have and will affect patient care” – said that it’s more important to focus on how we can shut the “digital doors” of the NHS than focus on what specific variant the attack belonged to.

“I know, it’s stretching an analogy to breaking point, but if this was a burglary we’d want to know if the door was locked, whether the door had a known vulnerability or whether we’d closed the windows,” wrote Taylor. “Yes, ransomware is on the increase, but it’s just another threat, another piece of malware. Being cyber prepared means being secure against a variety of attack types.”

In Sheffield Teaching Hospital’s major ‘Information and Technology Strategy 2020’, published in December, the foundation trust made clear that the “significance of cyber security in the modern world cannot be overestimated” – especially in the NHS, a bigger target due to its wealth of valuable data.

“The benefits of moving towards an electronic NHS are significant, however doing this safely in a way that patient data is secure and the provision of care is not interrupted is becoming increasingly complicated,” the strategy said.

“The threats posed by cybercriminals means that we must address any vulnerabilities we may have. In a healthcare setting, the effects resulting from a cyber-attack can be devastating.”

Find Taylor’s top tips for preventing cyber-attacks and developing digital maturity in the Jan/Feb edition of NHE, alongside in-depth coverage of our FoI investigation.

To view the complete results of the FoI investigation, please get in touch with [email protected].

Comments

There are no comments. Why not be the first?

Add your comment

national health executive tv

more videos >

latest healthcare news

NHS England commits £30m to join up HR and staff rostering systems

09/09/2020NHS England commits £30m to join up HR and staff rostering systems

As NHS England looks to support new ways of working, it has launched a £30m contract tender for HR and staff rostering systems, seeking sup... more >
Gender equality in NHS leadership requires further progress

09/09/2020Gender equality in NHS leadership requires further progress

New research carried out by the University of Exeter, on behalf of NHS Confederation, has shown that more progress is still needed to achieve gen... more >
NHS Trust set for big savings in shift to digital patient letters

09/09/2020NHS Trust set for big savings in shift to digital patient letters

Up and down the country, NHS trusts are finding new and innovative ways to leverage the power of digital technologies. In Bradford, paper appoint... more >

editor's comment

26/06/2020Adapting and Innovating

Matt Roberts, National Health Executive Editorial Lead. NHE May/June 2020 Edition We’ve been through so much as a health sector and a society in recent months with coronavirus and nothing can take away from the loss and difficulties that we’ve faced but it vital we also don’t disregard the amazing efforts we’ve witnessed. Staff have gone above and beyond, whole hospitals and trusts have flexed virtually at w... read more >

last word

Haseeb Ahmad: ‘We all have a role to play in getting innovations quicker’

Haseeb Ahmad: ‘We all have a role to play in getting innovations quicker’

Haseeb Ahmad, president of the Association of the British Pharmaceutical Industry (ABPI), sits down with National Health Executive as part of our Last Word Q&A series. Would you talk us th... more > more last word articles >

the scalpel's daily blog

Covid-19 can signal a new deal with the public on health

28/08/2020Covid-19 can signal a new deal with the public on health

Danny Mortimer, Chief Executive, NHS Employers & Deputy Chief Executive, NHS Confederation The common enemy of coronavirus united the public side by side with the NHS in a way that many had not seen in their lifetimes and for others evoked war-time memories. It was an image of defiance personified by the unforgettable N... more >
read more blog posts from 'the scalpel' >

comment

NHS England dementia director prescribes rugby for mental health and dementia patients

23/09/2019NHS England dementia director prescribes rugby for mental health and dementia patients

Reason to celebrate as NHS says watching rugby can be good for your mental health and wellbeing. As the best rugby players in the world repr... more >
Peter Kyle MP: It’s time to say thank you this Public Service Day

21/06/2019Peter Kyle MP: It’s time to say thank you this Public Service Day

Taking time to say thank you is one of the hidden pillars of a society. Being on the receiving end of some “thanks” can make communit... more >
Nurses named as least-appreciated public sector workers

13/06/2019Nurses named as least-appreciated public sector workers

Nurses have been named as the most under-appreciated public sector professionals as new research reveals how shockingly under-vauled our NHS, edu... more >
Creating the Cardigan integrated care centre

10/06/2019Creating the Cardigan integrated care centre

Peter Skitt, county director and commissioner for Ceredigion Hywel Dda University Health Board, looks ahead to the new integrated care centre bei... more >

interviews

Matt Hancock says GP recruitment is on the rise to support ‘bedrock of the NHS’

24/10/2019Matt Hancock says GP recruitment is on the rise to support ‘bedrock of the NHS’

Today, speaking at the Royal College of General Practitioners (RCGP) annual conference, Matt Hancock highlighted what he believes to be the three... more >
NHS dreams come true for Teesside domestic

17/09/2019NHS dreams come true for Teesside domestic

Over 20 years ago, a Teesside hospital cleaner put down her mop and took steps towards her midwifery dreams. Lisa Payne has been delivering ... more >
How can winter pressures be dealt with? Introduce a National Social Care Service, RCP president suggests

24/10/2018How can winter pressures be dealt with? Introduce a National Social Care Service, RCP president suggests

A dedicated national social care service could be a potential solution to surging demand burdening acute health providers over the winter months,... more >
RCP president on new Liverpool college building: ‘This will be a hub for clinicians in the north’

24/10/2018RCP president on new Liverpool college building: ‘This will be a hub for clinicians in the north’

The president of the Royal College of Physicians (RCP) has told NHE that the college’s new headquarters based in Liverpool will become a hu... more >

health service focus

View all News