British Healthcare System Spends £150m Extra On Cybersecurity

The NHS is to spend £150m to bolster its defences against the “growing threat” of cyber-attacks following the chaos caused by the WannaCry virus.

Amid warnings that hackers linked to Russia and other countries have been targeting Britain’s critical national infrastructure, including power networks, a new security contract has been drawn up with Microsoft.

The Department of Health and Social Care said the package would enhance security intelligence and give individual trusts the ability to detect threats, isolate infected machines and kill malicious processes before they are able to spread.
Jeremy Hunt, the health secretary, said: “We know cyber-attacks are a growing threat, so it is vital our health and care organisations have secure systems which patients trust.

“We have been building the capability of NHS systems over a number of years, but there is always more to do to future-proof our NHS against this threat.

“This new technology will ensure the NHS can use the latest and most resilient software available, something the public rightly expect.”

It comes almost a year after the global WannaCry cyber-attack crippled parts of the NHS in May 2017, locking data on computers with demands for money.

At least 80 health trusts and 603 NHS organisations and GP practices were disrupted by the global ransomware attack, which caused 20,000 hospital appointments and operations to be cancelled as ambulances were diverted from some A&Es.
A scathing report by the National Audit Office said the “unsophisticated” attack could have been prevented if the NHS had followed basic IT security best practice.

“There are more sophisticated cyber threats out there than WannaCry so the Department and the NHS need to get their act together to ensure the NHS is better protected against future attacks,” said head Amyas Morse at the time.
The government was warned of the risk of cyber-attacks a year before the incident and trusts were instructed to move away from outdated software like Windows XP as early as 2014.

The new measures will ensure all health and care organisations can use the most up-to-date Windows 10 software with its latest security settings, giving the Care Quality Commission (CQC) regulator will new powers to inspect cyber and data security capabilities. The government has separately invested £60m to address key cyber security weaknesses and the new £150m will be spread across three years.

A new digital security operations centre is being set up to prevent, detect and respond to incidents, allow NHS Digital to respond to cyber-attacks more quickly and increase the abilities of local trusts.

There will be £21m to upgrade protective firewalls and network infrastructure at major trauma centre hospitals and ambulance trusts, £39m spent by NHS trusts on infrastructure weaknesses and a new a text messaging alert system able transmit information even if internet and email services are down.

All health and care organisations will be required to meet 10 standards set for data security and protection toolkit.
Lord O’Shaughnessy, a health minister, said: “Patient data must be properly protected and this significant investment will help to keep our systems resilient and up to date. “This will give patients greater confidence in how their information is managed by the NHS.”

Sarah Wilkinson, chief executive of NHS Digital, welcomed the announcement, adding: “The new Windows Operating System has a range of advanced security and identity protection features that will help us to keep NHS systems and data safe from attack.”

Independent

You Might Also Read:

NHS Trusts Failed Cyber Security Assessment:

Healthcare Suffers Most Cyber Security Incidents:
 

« TSB's IT Meltdown Was Evident A Year Before
Australia's Largest Bank Lost The Personal Financial Histories Of 12m Customers »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

FIDO Alliance

FIDO Alliance

FIDO Alliance is a non-profit organization formed to address the lack of interoperability among strong authentication devices.

Advantech

Advantech

Advantech is a leader in providing trusted innovative embedded and automation products and solutions. Activities include IoT security.

OSIRIS Lab - NYU Tandon

OSIRIS Lab - NYU Tandon

The Offensive Security, Incident Response & Internet Security Lab (OSIRIS) is a security research environment where students analyze and understand how attackers take advantage of real systems.

Seric Systems

Seric Systems

Seric is a technology business specialising in security, infrastructure and data management.

Circadence

Circadence

Circadence offer the only fully immersive, AI-powered, patent-pending, proprietary cybersecurity training platform in the market today.

Ignyte Assurance Platform

Ignyte Assurance Platform

Ignyte Assurance Platform™ is a leader in collaborative security and integrated GRC solutions for global corporations in Healthcare, Defense, and Technology.

Guardian Data Destruction

Guardian Data Destruction

Guardian Data Destruction provides a comprehensive suite of onsite e-data destruction services.

Phoenix Cybersecurity

Phoenix Cybersecurity

Phoenix Cybersecurity Services and Managed Security Services help clients just like you take full advantage of leading cybersecurity technologies and industry best practices.

Hassans International Law Firm

Hassans International Law Firm

Hassans is the largest law firm in Gibraltar, providing a full range of legal services across corporate and commercial law including Data Protection and GDPR compliance.

BlackDice Cyber

BlackDice Cyber

Threat Intelligence is only part of the solution. Our solution matches threats to vulnerabilities and automatically takes remedial action against compromised apps, devices and websites.

Managed IT Services

Managed IT Services

Managed IT Services is a managed IT Services Company offering a diverse range of Cyber Security services and IT solutions.

Strata Identity

Strata Identity

Strata is pioneering identity orchestration to unify on-premises and cloud-based authentication and access systems for consistent identity management in multi-cloud environments.

Exacom

Exacom

Exacom is a leading provider of multimedia logging/recording solutions across public safety, government, DoD, energy, utilities, transportation, and security applications.

Huntr

Huntr

Huntr provides a single place for security researchers to submit vulnerabilities, to ensure the security and stability of AI/ML applications.

Two99

Two99

Two99 provide tailored excellence in the areas of E-Commerce, Marketing, Consulting, and Cyber Security.

PDI Technologies

PDI Technologies

PDI Technologies helps convenience retail and petroleum wholesale businesses around the globe increase efficiency and profitability by securely connecting their data and operations.