NHS: Cybersecurity

(asked on 9th July 2026) - View Source

Question to the Department of Health and Social Care:

To ask His Majesty's Government how many cyber incidents the NHS Cyber Security Operations Centre (1) detected and prevented, (2) detected but failed to prevent, and (3) initially detected but subsequently found to be a false alarm, in (a) the first half of 2025, (b) the second half of 2025, and (c) the first half of 2026.


Answered by
Baroness Merron Portrait
Baroness Merron
Parliamentary Under-Secretary (Department of Health and Social Care)
This question was answered on 20th July 2026

The following figures are from the NHS England Cyber Security Operations Centre (CSOC) incident ticketing systems, namely aggregating data from security tooling that monitors cyber security incidents detected by, or reported to, the CSOC. The following table shows the number of security incidents detected by the CSOC where the impact to National Health Services has been prevented:

Period

Incident count

2025H1

1,443

2025H2

1,364

2026H1

1,740

There are no recorded cyber security incidents that were initially detected by the CSOC which were subsequently not prevented.

The following table shows the number of security incidents initially detected by CSOC security tooling, but which were subsequently found to be a false alarm via either automated mechanisms or manual activity:

Period

Incident Count

2025H1

Unavailable

2025H2

85,819

2026H1

73,628


As these are false positives, the data surrounding them is only retained for 12 months, making a response to 2025H1 not possible.

Reticulating Splines