Question to the Department of Health and Social Care:
To ask His Majesty's Government how many cyber incidents the NHS Cyber Security Operations Centre (1) detected and prevented, (2) detected but failed to prevent, and (3) initially detected but subsequently found to be a false alarm, in (a) the first half of 2025, (b) the second half of 2025, and (c) the first half of 2026.
The following figures are from the NHS England Cyber Security Operations Centre (CSOC) incident ticketing systems, namely aggregating data from security tooling that monitors cyber security incidents detected by, or reported to, the CSOC. The following table shows the number of security incidents detected by the CSOC where the impact to National Health Services has been prevented:
Period | Incident count |
2025H1 | 1,443 |
2025H2 | 1,364 |
2026H1 | 1,740 |
There are no recorded cyber security incidents that were initially detected by the CSOC which were subsequently not prevented.
The following table shows the number of security incidents initially detected by CSOC security tooling, but which were subsequently found to be a false alarm via either automated mechanisms or manual activity:
Period | Incident Count |
2025H1 | Unavailable |
2025H2 | 85,819 |
2026H1 | 73,628 |
As these are false positives, the data surrounding them is only retained for 12 months, making a response to 2025H1 not possible.