20 Accepted

In our 2018 report on the WannaCry Cyber-attack on the NHS, we found that the...

Conclusion
In our 2018 report on the WannaCry Cyber-attack on the NHS, we found that the Department and its arm’s-length bodies were unprepared for the relatively unsophisticated WannaCry attack and had a lot of work to do to improve cyber-security for when, and not if, there was another attack.39 We asked how the NHS was ensuring that it had the skills it needed to manage the risks of future cyberattacks, NHS Digital acknowledged that there remained a “significant cyber risk” associated with legacy IT systems, which were especially vulnerable to cyber-attack.40 It admitted that the NHS “desperately need skills” in cyber security. It told us that it was using questionnaires to assess trusts’ exposure to cyber-security risks and was focusing its efforts on trusts at the bottom end of the 32 C&AG’s Report, para 1.4, Figure 2 33 Q37 34 C&AG’s Report, para 17 35 C&AG’s Report, para 8, Figure 4. 36 Q41 37 C&AG’s Report, para 7 38 Qq 73, 81–82 39 House of Commons Committee of Public Accounts, Cyber-attack on the NHS, HC 787, Session 2005–06, 18 April
Government Response Summary
The government agrees with the conclusion, detailing NHS Digital's ongoing commitment and existing efforts to improve cyber security across the health and care system, including the Data Security Centre and various national services. They acknowledge the enduring risk and state NHS Digital will continue to strengthen defences, with a full update promised in Spring 2021.
Government Response
Accepted
HM Government Accepted
2.1 The government agrees with the Committee’s recommendation. Target implementation date: April 2021 2.2 NHS Digital’s commitment to improving cyber security across the health and care system is unwavering. They are addressing the inherent cyber risks that legacy systems create across the estate, continuing to drive the national cyber security programme. This includes ensuring all organisations are reporting their cyber security position through the Data Security and Protection Toolkit and through direct engagement with Trusts to address the most significant cyber risks within the estate. 2.3 Since WannaCry, NHS Digital has created the Data Security Centre, the dedicated cyber security operations unit for health and social care. The Data Security Centre has introduced a range of centrally provided capabilities and services that have significantly improved resilience across the health and care system. 2.4 These include: a national cyber security operating centre, threat intelligence, vulnerability scanning and proactive cyber security assessments for trusts to help them understand and address their cyber risks. These services are supporting NHS organisations to protect their data, identify and respond to cyber threats and meet the standards set out in the Data Security and Protection Toolkit. As a result, the ability of NHS organisations to manage cyber risks has greatly improved since WannaCry. 2.5 Whilst significant progress has been made, cyber security will always remain a significant and enduring risk for the NHS given its size and complexity, the evolving threat landscape and the increasing sophistication of cyber-attacks. Therefore, NHS Digital will continue to work to strengthen the health and care system’s cyber defences in order to protect patient data and reduce the risk and impact of future attacks. 2.6 NHS Digital will provide a full update to the Committee in Spring 2021.
Addressee Bodies
HM Treasury
Timeline
Recommendation age 5.7 yrs
Report published 06 Nov 2020