The Top 3 Cyber Risks Facing the UK Healthcare Sector

The NHS is a national institution that enjoys a profound level of public support, even in spite of its current state as a weakened and oversubscribed arm of the UK’s public infrastructure. In recent years, many issues have dogged the NHS – but none have posed such a unilateral risk as that of its cyber infrastructure.

Cyber risks and cyber-crime have become definitive aspects of our new tech-advanced normal, from phishing scams to ransomware – but what exactly are these risks? And how do they relate to the health of our health service? What follow are some explorations of the key risks facing the NHS, and their specific form in today’s tech landscape.

Data Breaches

It is the personal and sensitive data that NHS facilities hold on patients which makes the NHS such a cause for concern. One of the bigger cyber risks posed to the NHS is not even necessarily a malicious one, being simply the unintentional release – or breaching – of said data.

Data breaches can occur via a number of ways, and are often the purpose for cyber attacks as examined below. However, they can also occur passively, through the mistaken accessing or release of patient information by a poorly trained member of administrative staff.

Ransomware Attacks

Ransomware attacks are not only some of the more significant threats posed to the UK’s healthcare infrastructure, but also some of the most well-publicised. In 2017, a ransomware attack using a ‘cryptoworm’ virus called WannCry took place – affecting NHS systems across the country. Various screens were disabled and processes disrupted, from blood transfers to patient handovers and beyond, and important patient information was put at risk in the process.

Ransomware holds systems and information hostage in service of gaining ransom funds, and as such is something of a blunt instrument. The WannaCry worm was deemed an unsophisticated virus in its own right, and one that human error had let run rampant on aging NHS systems.

Phishing Scams

Phishing scams are easily the most common form of cybercrime today, and can range from inelegant grabs at personal information to highly sophisticated systems of capture. Ultimately, a phishing scam involves tricking an individual into giving up sensitive assets or access to them, by posing as a legitimate contact or service.

There’s no ‘hacking’ in phishing scams, nor indeed in most cyber risks. The path of least resistance is through the most suggestible employee, and so the broad net of a phishing email can be an effective way for cybercriminals to catch the data they need.

It is for this reason – along with the dogged persistence of phishing attacks against local NHS facilities – that cybersecurity awareness should be given especial attention. Staff members in the NHS at all levels of administration and governance should be given comprehensive training, in order to recognise the signs of a phishing scam and act accordingly.

In this way, training and knowledge are the most powerful ways to reduce the risk that cybercrime poses to the NHS. But with resources already stretched thin, things are likely to get worse before they get better.

Share This: