Research and Technology

18.04.18

Cyber security plans impossible as NHS still in dark about WannaCry

The WannaCry cyber-attack on 12 May 2017 was a wake-up call for the NHS and the Department of Health and Social Care (DHSC) must now act on priorities by June this year, the Public Accounts Committee (PAC) has argued.

The attack caused widespread disruption to health services, with more than a third of trusts affected by the ransomware. The NHS had to cancel almost 20,000 hospital appointments and operations as patients were diverted from the five A&E departments that were unable to treat them.

If the attack had not happened on a Friday afternoon in the summer and the kill switch to stop the virus spreading had not been found relatively quickly, then the disruption could have been much worse, MPs claimed.

PAC said the DHSC and its arm’s-length bodies were unprepared for the relatively unsophisticated WannaCry threat and that they had not shared and tested plans for responding to a cyber-attack, nor had any trust passed a cyber security inspection.

To make matters worse, the department still does not know what financial impact the WannaCry cyber-attack had on the NHS, which is hindering its ability to target its investment in cyber security.

The committee said that, even though lessons have been learnt from the attack, the department and NHS bodies have a lot of work to do to improve cyber-security for when, and not if, there is another attack.

MPs urged the DHSC to provide the committee with an update by the end of June at the latest.

PAC chair Meg Hillier said: “The extensive disruption caused by WannaCry laid bare serious vulnerabilities in the cyber security and response plans of the NHS.

“Government must get a grip on the vulnerabilities of and challenges facing local organisations, as well as the financial implications of WannaCry and future attacks across the NHS. Cyber security investment cannot be properly targeted unless this information is collected and understood.”

Meanwhile, Hillier added, this case should serve as a warning to the whole of government: a “foretaste of the devastation that could be wrought by a more malicious and sophisticated attack.”  When this comes, the UK must be ready, she argued.

Responding to the report, the director of development and operations at NHS Providers, Ben Clacy, said: “The PAC rightly acknowledges that lessons have been learned by the NHS bodies and the DHSC, including how they communicate with trusts and the public. Trusts have also taken further steps to ensure they are applying software patches and keeping anti-virus software up to date.

“However, with no indication that there will be the capital available to carry out the required upgrades and changes, progress is being hampered. Cyber security must be a priority so it is vital that the capital investment needed is protected from plugging gaps in day to day spending.” 

Clacy concluded: “It is also worth remembering that this attack was not specific to the NHS. It affected thousands of computers in hundreds of countries.”

Comments

There are no comments. Why not be the first?

Add your comment

 

national health executive tv

more videos >

latest healthcare news

Lancashire County Council to pay £200k in legal costs after Virgin Care legal battle

17/08/2018Lancashire County Council to pay £200k in legal costs after Virgin Care legal battle

Lancashire County Council has agreed to pay £200,000 in legal costs to two NHS Trusts after their decision to hand a £104million cont... more >
Former inadequate West Midlands maternity unit upgraded by CQC

17/08/2018Former inadequate West Midlands maternity unit upgraded by CQC

Walsall Manor Hospital’s maternity services have been given an improved rating from the health inspectorate following assessments made in J... more >
Major hospital stalled by Carillion collapse will go ahead under government funding deal

16/08/2018Major hospital stalled by Carillion collapse will go ahead under government funding deal

The construction of a major Midlands hospital that had its future cast into doubt following the collapse of infrastructure giant Carillion has be... more >

editor's comment

25/09/2017A hotbed of innovation

This edition of NHE comes hot on the heels of this year’s NHS Expo which, once again, proved to be a huge success at Manchester Central. A number of announcements were made during the event, with the health secretary naming the second wave of NHS digital pioneers, or ‘fast followers’, which follow the initial global digital exemplars who were revealed at the same show 12 months earlier.  Jeremy Hunt also stated th... read more >

last word

Hard to be optimistic

Hard to be optimistic

Rachel Power, chief executive of the Patients Association, warns that we must be realistic about the very real effects of continued underfunding across the health service. It’s now bey... more > more last word articles >

the scalpel's daily blog

The NICE impact on falls and fragility fractures

10/08/2018The NICE impact on falls and fragility fractures

Falls should not be an inevitable part of ageing – and their snowball effect means the consequence of falls are far from limited to just hospital admissions, says Professor Gillian Leng, deputy chief executive and director of health and social care at NICE Almost a third of over-65s in the UK have a fall at least once a year, with a... more >
read more blog posts from 'the scalpel' >

comment

Listening to the frontline

15/08/2018Listening to the frontline

Professor Wendy Reid, executive director of education & quality and national medical director at Health Education England (HEE), shares insig... more >
Medication without harm

15/08/2018Medication without harm

The World Health Organization’s (WHO’s) Third Global Patient Safety Challenge, ‘Medication without harm,’ is ambitious, b... more >
Stepping up the fight against AMR

15/08/2018Stepping up the fight against AMR

Professor Mark Baker, director of the Centre for Guidelines at NICE, explains what the organisation is doing to support the fight against antimic... more >
Population health for the 21st century

15/08/2018Population health for the 21st century

NHS Partners Network (NHSPN) chief executive David Hare discusses the themes covered at his organisation’s Confed18 panel debate on populat... more >

interviews

Duncan Selbie: A step on the journey to population health

24/01/2018Duncan Selbie: A step on the journey to population health

The NHS plays a part in the country’s wellness – but it’s far from being all that matters. Duncan Selbie, chief executive of Pu... more >
Cutting through the fake news

22/11/2017Cutting through the fake news

In an era of so-called ‘fake news’ growing alongside a renewed focus on reducing stigma around mental health, Paul Farmer, chief exec... more >
Tackling infection prevention locally

04/10/2017Tackling infection prevention locally

Dr Emma Burnett, a lecturer and researcher in infection prevention at the University of Dundee’s School of Nursing and Midwifery and a boar... more >
Scan4Safety: benefits across the whole supply chain

02/10/2017Scan4Safety: benefits across the whole supply chain

NHE interviews Gillian Fox, head of eProcurement (Scan4Safety) programme at NHS Supply Chain. How has the Scan4Safety initiative evolved sin... more >

health service focus

View all News