NHS: Cybersecurity

(asked on 16th June 2026) - View Source

Question to the Department of Health and Social Care:

To ask the Secretary of State for Health and Social Care, what steps his Department has taken to improve the cyber resilience of NHS suppliers following the 2024 ransomware attack on NHS testing provider Synnovis.


Answered by
Preet Kaur Gill Portrait
Preet Kaur Gill
This question was answered on 30th June 2026

Supply chain cyber security is a system-wide operational resilience and patient safety issue, with disruption from a single supplier capable of impacting care delivery at scale.

The health and care system operates within a highly complex and fragmented supply chain, with over 80,000 suppliers and limited central visibility of dependencies, increasing systemic cyber risk.

Cyber threats to the supply chain are increasing in pace, scale, and sophistication, and are now reflected as a top-level strategic risk for NHS England.

The Cyber Improvement Programme (CIP) is delivering a national, coordinated response to reduce supplier cyber risk and strengthen resilience across the health and care ecosystem.

Our immediate priority is to reduce frontline risk quickly, moving from risk identification to active remediation and engagement with critical suppliers.

Core national capabilities are being established to manage supplier risk, including:

  • a governed list of critical suppliers to prioritise action;

  • a national remediation process to identify, assess, and reduce risk;

  • a cyber third-party risk management standard to provide clearer, consistent expectations; and

  • a national platform to improve visibility of systemic risk.

The programme is reinforcing expectations through the Cyber Security Supply Chain Charter and strengthened contract frameworks, signalling clear leadership intent and supporting a transition from voluntary commitments to consistent, enforceable cyber requirements across National Health Service supplier contracts over time.

An iterative, scalable approach is being taken, implementing practical solutions now while building a longer-term operating model for consistent risk management across the system.

Engagement with suppliers and stakeholders is accelerating, with national events and communications reinforcing expectations and supporting adoption.

The direction of travel is clear, that raising cyber standards across the supply chain is non-negotiable to protect patient care, with progression from voluntary commitments to formal standards and legislative underpinning.

This work aligns to the Cyber Security Strategy for Health and Social Care to 2030 and emerging regulation, including the Cyber Security and Resilience Bill, strengthening system-wide accountability and resilience.

Reticulating Splines