NHS cyber security: Ex security chief warns of future attacks (2024)

NHS cyber security: Ex security chief warns of future attacks (1)Image source, Blavatnik School of Government

Guy Lynn and Stephen Menon

BBC Investigations, London

  • Published

A leading cybersecurity expert has warned that the NHS remains vulnerable to further cyber-attacks unless it updates its computer systems.

This stark assessment comes in the wake of a major ransomware attack that has severely disrupted healthcare services across London.

Prof Ciaran Martin, the founding CEO of the UK's National Cyber Security Centre (NCSC), told the BBC: "I was horrified, but not completely surprised. Ransomware attacks on healthcare are a major global problem."

NHS England said it was increasing its cybersecurity resilience and had invested £338m in the past seven years addressing this issue.

But Prof Martin's warnings suggest more urgent action may be needed.

A recent British Medical Association report, external highlighted the NHS's ageing IT infrastructure, revealing that doctors waste 13.5 million hours annually due to outdated systems - equivalent to 8,000 full-time medics' time.

The 3 June cyber-attack, which Prof Martin described as one of the most serious in British history, targeted Synnovis, a pathology testing organisation, severely affecting services including at Guy's, St Thomas', King's College and Evelina London Children's Hospitals.

NHS England declared it a regional incident, resulting in 4,913 acute outpatient appointments and 1,391 operations postponed and major data security concerns.

The Russian-based hacking group Qilin, believed to be part of a Kremlin-protected cyber army, demanded a £40m ransom. When the NHS refused to pay, the group published stolen data on the dark web.

This incident reflects a growing trend of Russian cyber criminals targeting global healthcare systems.

Now a professor at the University of Oxford, Prof Martin highlighted three critical issues facing NHS cybersecurity: outdated IT systems, the need to identify vulnerable points, and the importance of basic security practices.

He warned: "In parts of the NHS estate, it's quite clear that some of the IT is out of date."

He stressed the importance of identifying "single points of failure" in the system and implementing better backups.

Prof Martin also emphasised that improving basic security measures could significantly hinder attackers, stating: "Those little things make the point of entry quite a lot harder for the thugs to get in."

Emphasising the severity of the recent attack, he concluded: "It was obvious that this was going to be one of the most serious cyber incidents in British history because of the disruption to healthcare."

'Cybersecurity is costly'

Some front-line staff who spoke anonymously are very worried following the recent cyber attacks, with reference being made to outdated equipment they are using.

A senior intensive care doctor in London warned: "The NHS is vulnerable.

"It's a patient safety issue, but there's no interest in addressing it. People either don't know or don't want to hear about it."

An A&E consultant in north London told us they were working with "decade-old computers and Windows 7" and that their systems crashed "every few months" while a junior doctor highlighted the risks of outdated equipment and privatization.

"Old computers pose a security risk for patient data. The Synnovis incident shows how vulnerable we are," the doctor said.

A senior orthopaedic surgeon described the fragmented nature of NHS IT: "There's no unified system. A patient's X-ray in one hospital can't be accessed in another.

"It's shocking and worrying for cybersecurity."

Another junior doctor added: "The NHS isn't doing enough.

"Cybersecurity is costly, and our funding has been cut for over a decade.

"It's incredibly frustrating."

Dr Daniel Gardham from the University of Surrey's Centre for Cyber Security echoed Prof Martin's concerns about outdated systems and their potential link to cyber-attacks.

"If you have old computers, then simply put, there's going to be unpatched vulnerabilities," he said.

"This means that there are ways in for attackers."

Dr Gardham stressed that while sophisticated attacks did occur, many breaches result from basic security oversights.

"It could be something really, really, simple and actually most likely it is something very, very, simple.

"It would be one person, perhaps, that had a weak password or left their computer unattended in a cafe.

"A lot of cyber security attacks are not sophisticated."

An NHS England spokesperson told the BBC: "We are increasing cyber resilience across the NHS and over £338 million has been invested over the past seven years to help keep health and care organisations as safe as possible.

"Our ambitious Cyber Improvement Programme will support the NHS to respond to the changing cyber threats, expand protection and reduce the risk of a successful attack."

Contact us:

If you have something you'd like BBC London's investigations team to look into, get in touch, in confidence on: londoninvestigationsteam@bbc.co.uk, external

Related Topics

  • Cyber-crime
  • London
  • Cyber-security
NHS cyber security: Ex security chief warns of future attacks (2024)

References

Top Articles
Fact-checking Biden and Trump's claims at the first debate
Cheap Boats For Sale Craigslist
What Did Bimbo Airhead Reply When Asked
Joliet Patch Arrests Today
Wmu Course Offerings
Ashlyn Peaks Bio
Publix 147 Coral Way
Autozone Locations Near Me
[2024] How to watch Sound of Freedom on Hulu
Mawal Gameroom Download
MindWare : Customer Reviews : Hocus Pocus Magic Show Kit
Industry Talk: Im Gespräch mit den Machern von Magicseaweed
Flower Mound Clavicle Trauma
Local Collector Buying Old Motorcycles Z1 KZ900 KZ 900 KZ1000 Kawasaki - wanted - by dealer - sale - craigslist
Becu Turbotax Discount Code
5 high school volleyball stars of the week: Sept. 17 edition
Procore Championship 2024 - PGA TOUR Golf Leaderboard | ESPN
Grandview Outlet Westwood Ky
Free Online Games on CrazyGames | Play Now!
Vintage Stock Edmond Ok
Missed Connections Inland Empire
Laveen Modern Dentistry And Orthodontics Laveen Village Az
Best Nail Salons Open Near Me
Ice Dodo Unblocked 76
yuba-sutter apartments / housing for rent - craigslist
A Person That Creates Movie Basis Figgerits
27 Paul Rudd Memes to Get You Through the Week
Jobs Hiring Near Me Part Time For 15 Year Olds
Dark Entreaty Ffxiv
Greensboro sit-in (1960) | History, Summary, Impact, & Facts
Table To Formula Calculator
Federal Express Drop Off Center Near Me
Elanco Rebates.com 2022
Ofw Pinoy Channel Su
24 slang words teens and Gen Zers are using in 2020, and what they really mean
Build-A-Team: Putting together the best Cathedral basketball team
AI-Powered Free Online Flashcards for Studying | Kahoot!
Why Gas Prices Are So High (Published 2022)
Page 5662 – Christianity Today
Geology - Grand Canyon National Park (U.S. National Park Service)
Chatropolis Call Me
Final Fantasy 7 Remake Nexus
Dwc Qme Database
Pekin Soccer Tournament
FedEx Authorized ShipCenter - Edouard Pack And Ship at Cape Coral, FL - 2301 Del Prado Blvd Ste 690 33990
Online-Reservierungen - Booqable Vermietungssoftware
Benjamin Franklin - Printer, Junto, Experiments on Electricity
Star Sessions Snapcamz
ESPN's New Standalone Streaming Service Will Be Available Through Disney+ In 2025
Billings City Landfill Hours
Ubg98.Github.io Unblocked
683 Job Calls
Latest Posts
Article information

Author: Dan Stracke

Last Updated:

Views: 5896

Rating: 4.2 / 5 (63 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Dan Stracke

Birthday: 1992-08-25

Address: 2253 Brown Springs, East Alla, OH 38634-0309

Phone: +398735162064

Job: Investor Government Associate

Hobby: Shopping, LARPing, Scrapbooking, Surfing, Slacklining, Dance, Glassblowing

Introduction: My name is Dan Stracke, I am a homely, gleaming, glamorous, inquisitive, homely, gorgeous, light person who loves writing and wants to share my knowledge and understanding with you.