Skip to main content

Strengthening cyber resilience across the NHS with collaboration and innovation

How the NCSC is reducing risk, improving detection, and helping to keep vital services running.

Healthcare in Great Britain concept: A stethoscope on a 3d map of Great Britain overlayed by the British flag

aprott via Getty Images

We all rely on the UK’s health services, from booking a GP appointment and collecting prescriptions, to receiving life‑saving treatment in hospitals.

These services increasingly depend on digital systems to operate safely and effectively. When it works well, patients rarely notice it. Behind the scenes, healthcare depends on interconnected IT systems and supply chains. Securing the NHS is particularly challenging because it spans a vast collection of legacy and modern technologies, numerous suppliers and critical services, where even small vulnerabilities can have system‑wide consequences for patient care. Issues in one area can have wide-reaching consequences across many other organisations, disrupting services far beyond a single provider.

Recent cyber incidents have shown that attacks on healthcare do not just affect systems or data. They can delay tests, disrupt care, and put pressure on frontline staff. For example, in June 2024, a ransomware attack on Synnovis, a key NHS pathology provider, led to postponed tests and procedures across multiple hospitals and GP practices.

Incidents like this show that cyber resilience is linked to patient safety and why the health sector is a priority for the NCSC. But cyber resilience in healthcare cannot be achieved by individual organisations working alone. It depends on shared responsibility, strong partnerships and practical collaboration across the NHS, government, and industry.

Building on the national and local preparedness and resilience work undertaken by the NHS over the last decade, collaboration between organisations working across the health sector has deepened over the past 18 months. By working together, we are reducing cyber risk, improving detection, and helping to keep vital services running. This has included:

Collaboration has also driven improvements in how software is built and bought. The Software Security Code of Practice, developed jointly with DSIT and co‑endorsed by the Canadian Centre for Cyber Security, ensures providers are complying with the Code to deliver software that is secure and resilient. NHS organisations have been early adopters, using the Code during procurement to better understand the cyber maturity of their suppliers.


Turning partnership into practical protection

Healthcare bodies in England, Northern Ireland, Scotland and Wales are home to some of the UK’s most skilled cyber analysts, and their expertise has been central to the development of the NCSC’s Threat Hunting Workshops. These workshops bring together expert practitioners to tackle real‑world threats, develop defensive tradecraft, and strengthen relationships across the UK’s defender communities.

This work has strengthened cyber resilience in health and generated benefits for other critical sectors. Our most recent workshop brought together 170 expert practitioners from across government and private‑sector critical national infrastructure. It produced around 63 crowdsourced threat hypotheses, which informed community‑led discussions and hands‑on threat hunts.

Effective defence also depends on visibility. Working closely with health organisations, we have improved technical capabilities to better understand the threat surface and to deploy defensive tradecraft at scale. These partnerships have provided valuable insight into the systemic challenges facing defender communities, helping to address national barriers to effective intrusion detection and vulnerability management.


Improving vulnerability management across the sector

For many years, the NCSC has operated the Vulnerability Reporting Service (VRS) as a central coordination point for UK government online service vulnerability reports, including the health sector. Since 2019, this service has supported GP surgeries, NHS trusts, ambulance services, acute hospital trusts and health boards.

While the VRS remains a core service for UK government, the NCSC’s focus has increasingly shifted towards building sustainable capability within the sector itself. Working closely with partners, we have helped NHS England, the NHS Business Services Authority and NHS Scotland establish their own vulnerability disclosure processes. These routes provide clear reporting pathways for the public and security researchers, improving response times and supporting the continued delivery of safe, secure services.


Building confidence for the future

Building on this momentum, we partnered with a UK health organisation to explore how supplier cyber risk could be understood and prioritised more effectively using data‑science‑driven tools. The final output has now been delivered and this work lays the groundwork for future enhancements, including network‑level analytics and trend analysis.

We are now extending this approach through further analysis of health sector datasets. This ongoing work is exploring correlations between baseline data and incident history, alert and vulnerability activity from the NCSC Early Warning service, and technical indicators such as remediation patterns and exposed attack surfaces. These insights will support more targeted, proactive and data‑informed interventions across the sector.


Leading the way on modern security

Collaboration has also enabled leadership in modern authentication. The NHS App was the first government-sponsored app to offer passkeys as a login option for its services. Close partnership between the NHS and the NCSC has been central to accelerating wider UK adoption of passkeys, combining NHS England deployment experience with the NCSC’s technical expertise. Together, we are encouraging other organisations to follow suit, improving security for users nationwide.

Alongside this visible progress, quieter but equally important work continued through External Attack Surface Management (EASM) and deception technology experiments. Partnerships between health, industry, and the NCSC informed the NCSC’s EASM guidance and contributed to a growing, nation‑scale evidence base for cyber deception.

Finally, in collaboration with DSIT and an industry partner, the NCSC surged analytical effort to improve namespace security within the NHS, helping to identify and resolve DNS‑related risks.


A model for critical sectors

Taken together, this work shows what is possible when organisations align around a shared goal. Effort is coordinated rather than duplicated, lessons are reused, and risk is reduced across the system, not just within individual organisations.

Most importantly, this approach offers a model for other critical sectors. Cyber security challenges are too complex for any one organisation to tackle alone. While there is more to do, the progress we’ve made together demonstrates what can be achieved when we align priorities and focus collaboration on protecting a sector that matters to us all. By continuing to work together, sharing insights and learning from experience, we can build even stronger resilience where it matters most.

Nicholas W
National Resilience Directorate

Written by

Nicholas W

National Resilience Directorate, NCSC

Published