Info Gov

Digital Care Hub has endorsed a new white paper written by cybersecurity firm Fortinet calling for a dedicated NHS cyber workforce plan, secure-by-design requirements in procurement and supply chains, and stronger cyber security oversight.

The white paper, Keeping the NHS Online: Cyber Resilience in a New Regulatory Era, brings together contributions from parliamentarians, NHS IT leaders, academics and cyber security specialists. Its three recommendations are:

1. Develop a dedicated NHS cyber workforce and training plan, covering specialist recruitment and relevant training for the wider workforce.
2. Make secure by design part of procurement, service redesign and the supply chains of external providers and partners.
3. Improve cyber security oversight, assessment and accountability, with stronger benchmarking and less reliance on self-assessment alone.

Drawing on a parliamentary roundtable attended by Claire Howarth, Project and Strategic Delivery Manager at Digital Care Hub, the report examines the rising cyber threat to health services, the shortage of cyber skills and the need for clearer governance and accountability. It warns that ageing and fragmented technology means a single incident can cause widespread disruption.

Roundtable participants identified risks from third-party providers, personal devices and inconsistent cyber training, which they said leave organisations more exposed to phishing and scam emails.

The UK's current cyber security duties for operators of essential services, including in health, are governed by the Network and Information Systems Regulations 2018. The Cyber Security and Resilience (Network and Information Systems) Bill, which would update that regime, bring further sectors into scope, update incident reporting duties and give the government powers to direct organisations on national security grounds, is before the House of Lords, where it completed Grand Committee in September.

Royal Assent is expected between late 2026 and spring 2027. Separately, Article 32 of UK GDPR requires controllers and processors to implement appropriate technical and organisational measures to secure personal data.

Digital Care Hub is an independent consortium, led by care providers, that offers free information, guidance and support to adult social care providers in England on using digital technology safely. Its members are national trade associations representing adult social care providers. It hosts Better Security, Better Care, the national programme funded by NHS England that helps care providers with data and cyber security, including completing the annual Data Security and Protection Toolkit. It is also the subject matter expert to the government's Digitising Social Care programme. The organisation was known as Digital Social Care until September 2023.

Howarth said government and the NHS should invest in "common language, practical tools and repeatable support" instead of leaving each provider to interpret complex cyber frameworks alone. She called for role-based, sector-specific training with clear pathways for care providers, primary care teams, commissioners and system leaders.

Digital Care Hub noted that the report focuses on the NHS, not adult social care, but references the government's 2023 policy paper on a cyber resilient health and adult social care system in England. The organisation said the issues raised are also relevant to social care providers, which rely on external technology and service partners and share sensitive information across organisational boundaries.

The report concludes that regulation alone will not deliver resilience, and that organisations also need investment, relevant training, secure-by-design approaches and clearer accountability, supported by collaboration across government, health and care, industry and cyber security experts.

Also in this section

Sep 25, 2026

NHS England orders immediate suspension for staff suspected of snooping on patient records

NHS England has instructed every trust in England to suspend immediately any member of staff suspected of accessing patient records without a legitimate reason and to remove their access to NHS systems while the facts are established, in a letter from chief executive Sir Jim Mackey announcing a zero-tolerance approach to what he called snooping.
Sep 23, 2026

Prime Minister announces new National Centre for Information Defence

Prime Minister Andy Burnham has tasked the UK's security chiefs with establishing a National Centre for Information Defence to detect, attribute and disrupt hostile state information attacks, telling the UN General Assembly in New York on 22 September that AI would "multiply the threat" from disinformation and deepfakes.
Sep 11, 2026

Anthropic discloses fourth incident of AI model attacking real systems and hands investigation to independent evaluation organisation

Anthropic has published details of four incidents in which its Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations, downloading and modifying user records at a real company, reading the personal information of an individual, harvesting credentials and accessing a security vendor's live database, after the test environments were mistakenly…
Sep 10, 2026

Welsh environmental watchdog hit by data breach

Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public.

InfoGov Masthead Newsletter 800