NHS at risk of major cyber attack while it deals with coronavirus, experts warn

Health service already stretched to 'breaking point' and could be forced to deal with more, Chatham House warns

Andrew Griffin
Friday 03 April 2020 07:13 EDT
Comments
Nurses clean their hands before taking swabs at a Covid-19 Drive-Through testing station for NHS staff on March 30, 2020 in Chessington, United Kingdom
Nurses clean their hands before taking swabs at a Covid-19 Drive-Through testing station for NHS staff on March 30, 2020 in Chessington, United Kingdom (Getty)

Your support helps us to tell the story

From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.

At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.

The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.

Your support makes all the difference.

The NHS is at risk of a major cyber attack as it fights against the outbreak of coronavirus, according to experts.

The health service is already stretched to “breaking point” and needs greater support to ensure that it can stay protected from any potentially devastating hack, according to think tank Chatham House.

Lessons have been learned since the WannaCry ransomware attack which caused widespread disruption to the NHS in 2017 but today’s situation is “far more fragile”.

“Evidently, the NHS is stretched to breaking point – expecting it to be on top of its cybersecurity during these exceptionally challenging times is unrealistic,” Joyce Hakmeh, senior research fellow at Chatham House’s International Security Programme, said.

She argues that supporting the NHS should go beyond increasing human resources and equipment capacity, as cyber security is critical in ensuring health professionals can carry on saving lives, safely and securely.

At such a critical time for the health service, they want the government to call upon the private cybersecurity sector for assistance.

The think tank is also concerned about usual security processes being side-stepped, such as a national audit of the NHS’s security and cyber-resilience which was put on hold until September due to Covid-19.

It comes as Europol recently warned about pandemic profiteering, particularly online where criminals are attempting to exploit the crisis.

“Now is the time where innovative public-private partnerships on cybersecurity should be formed – similar to the economic package that the UK chancellor has put in place to shore up the economy against the Covid-19 impact and the innovative thinking on ventilator production,” Ms Hakmeh continued.

“The ways in which this support can be delivered can take different forms, the important thing is that it is mobilised swiftly.”

Neil Bennett, acting chief information security officer at NHS Digital, said: “This is a time of unprecedented stress on the NHS, not least for the cyber security and IT teams who are continuing to work hard in all NHS organisations to keep patient data and systems secure, to continue to deliver safe patient care.”

He continued: “Working closely with partner organisations such as the National Cyber Security Centre and NHSX, we have created a new programme of work to help tackle the challenges that Covid-19 has presented the health and care sector.

“This will support local organisations even further to identify and fix technical issues, provide resource where needed, enhance our threat intelligence and threat-hunting capabilities, and support the new field hospitals to set up their operations securely.

“In addition, we are doing further work to protect Critical National Infrastructure assets, aligned to CPNI standards, and we are continuing to issue guidance to the sector on secure remote working, which we will continue to update as the threat landscape develops.”

Additional reporting by Press Association

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in