British Healthcare System Spends £150m Extra On Cybersecurity

The NHS is to spend £150m to bolster its defences against the “growing threat” of cyber-attacks following the chaos caused by the WannaCry virus.

Amid warnings that hackers linked to Russia and other countries have been targeting Britain’s critical national infrastructure, including power networks, a new security contract has been drawn up with Microsoft.

The Department of Health and Social Care said the package would enhance security intelligence and give individual trusts the ability to detect threats, isolate infected machines and kill malicious processes before they are able to spread.
Jeremy Hunt, the health secretary, said: “We know cyber-attacks are a growing threat, so it is vital our health and care organisations have secure systems which patients trust.

“We have been building the capability of NHS systems over a number of years, but there is always more to do to future-proof our NHS against this threat.

“This new technology will ensure the NHS can use the latest and most resilient software available, something the public rightly expect.”

It comes almost a year after the global WannaCry cyber-attack crippled parts of the NHS in May 2017, locking data on computers with demands for money.

At least 80 health trusts and 603 NHS organisations and GP practices were disrupted by the global ransomware attack, which caused 20,000 hospital appointments and operations to be cancelled as ambulances were diverted from some A&Es.
A scathing report by the National Audit Office said the “unsophisticated” attack could have been prevented if the NHS had followed basic IT security best practice.

“There are more sophisticated cyber threats out there than WannaCry so the Department and the NHS need to get their act together to ensure the NHS is better protected against future attacks,” said head Amyas Morse at the time.
The government was warned of the risk of cyber-attacks a year before the incident and trusts were instructed to move away from outdated software like Windows XP as early as 2014.

The new measures will ensure all health and care organisations can use the most up-to-date Windows 10 software with its latest security settings, giving the Care Quality Commission (CQC) regulator will new powers to inspect cyber and data security capabilities. The government has separately invested £60m to address key cyber security weaknesses and the new £150m will be spread across three years.

A new digital security operations centre is being set up to prevent, detect and respond to incidents, allow NHS Digital to respond to cyber-attacks more quickly and increase the abilities of local trusts.

There will be £21m to upgrade protective firewalls and network infrastructure at major trauma centre hospitals and ambulance trusts, £39m spent by NHS trusts on infrastructure weaknesses and a new a text messaging alert system able transmit information even if internet and email services are down.

All health and care organisations will be required to meet 10 standards set for data security and protection toolkit.
Lord O’Shaughnessy, a health minister, said: “Patient data must be properly protected and this significant investment will help to keep our systems resilient and up to date. “This will give patients greater confidence in how their information is managed by the NHS.”

Sarah Wilkinson, chief executive of NHS Digital, welcomed the announcement, adding: “The new Windows Operating System has a range of advanced security and identity protection features that will help us to keep NHS systems and data safe from attack.”

Independent

You Might Also Read:

NHS Trusts Failed Cyber Security Assessment:

Healthcare Suffers Most Cyber Security Incidents:
 

« TSB's IT Meltdown Was Evident A Year Before
Australia's Largest Bank Lost The Personal Financial Histories Of 12m Customers »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Vertical Structure

Vertical Structure

Vertical Structure services include Security & Penetration Testing, Information Assurance, Bespoke Training Programs and Secure Hosting.

RSA Conference

RSA Conference

RSA Conference conducts information security events around the globe that connect you to industry leaders and highly relevant information.

Hotlava Systems

Hotlava Systems

HotLava network adapters enable today's powerful servers and workstations to deliver more productivity by reducing congestion at the network interface.

Marsh

Marsh

Marsh is a global leader in insurance broking and risk management and has been a leader in combatting cyber threats since their emergence.

CTR Secure Services

CTR Secure Services

CTR Secure Services provides a broad range of security consulting services from asset protection to cyber security.

Preempt Security

Preempt Security

The Preempt Platform delivers adaptive threat prevention that continuously preempts threats based on identity, behavior and risk.

Riskified

Riskified

Riskified is a leading eCommerce fraud-prevention company, trusted by hundreds of global brands – from luxury fashion houses and retail chains, to gift card and ticket marketplaces.

infySEC

infySEC

InfySEC is an information security services organization offering Security Technology services, Security Consulting, Security Training, Research & Development.

IoT Defense

IoT Defense

IoT Defense (IOTD) is a cybersecurity and networking company building solutions that enable the protection of networks and the ever-increasing prevalence of IoT devices.

Cytenna

Cytenna

Cytenna Signal is a suite of SaaS (Software-as-a-Service) products that use AI and machine learning to automatically aggregate the latest information about software vulnerabilities.

cleverDome

cleverDome

cleverDome has created the first community built and proven model that redefines the standards for protecting the most confidential data and information of consumers in the cloud.

Fibernet

Fibernet

Fibernet's innovative solutions in the fields of cybersecurity and fiber optics range from telecommunications infrastructure to small business cybersecurity.

Cyber-Security Council Germany

Cyber-Security Council Germany

The German Cyber Security Council's objective is to consult businesses, government agencies and political decision-makers and to support them against cybercrime.

Queen Consulting & Technologies

Queen Consulting & Technologies

Queen Consulting & Technologies specialize in providing IT support, management, and Security to Gov’t Contractors, CPAs, and Nonprofits.

LevelBlue

LevelBlue

LevelBlue simplify cybersecurity through award-winning managed security services, experienced strategic consulting, threat intelligence and renowned research.

Bridgenet Solutions

Bridgenet Solutions

Bridgenet specialises as a top-notch Information and Technology Solutions Provider for businesses.