NHS England has published a toolkit of campaign assets and template copy for health and care organisations ahead of Cyber Security Awareness Month in October, telling staff that keeping the NHS safe is everyone's responsibility and not only a matter for IT and security teams.
James Hutton, Head of Protective Monitoring at NHS England, said in a blog published on 2 September and linked from the campaign page that "You don't need to be a cyber security expert to make a big difference." Hutton said clinical staff are not expected to configure firewalls or deploy antivirus software, but that the most effective defence comes when IT teams and frontline staff work together.
The campaign asks staff to take four steps:
- use strong passwords
- turn on multi-factor authentication
- recognise and report phishing
- keep up to date with learning
NHS England said cyber criminals target healthcare because of the sensitive data it holds and the critical services it provides. It pointed to the 2024 ransomware attack on pathology provider Synnovis, which affected multiple NHS organisations and disrupted patient services across London, and to incidents involving suppliers including Ortivus as evidence of how interconnected healthcare has become.
It also cited attacks on M&S, Co-op and Harrods, and said criminals are increasingly using artificial intelligence to create convincing scams and impersonate trusted people.
Controllers and processors in health and care are required by Article 5(1)(f) and Article 32 of the UK GDPR to apply appropriate technical and organisational measures to secure personal data, and organisations with access to NHS patient data must complete the Data Security and Protection Toolkit each year.
NHS bodies designated as operators of essential services are also subject to the Network and Information Systems Regulations 2018, which the Cyber Security and Resilience (Network and Information Systems) Bill would amend. The Bill completed its Commons stages on 16 June 2026 and began committee stage in the House of Lords on 1 September. The minister told peers at second reading that the Synnovis attack delayed 11,000 appointments, and the Bill would allow suppliers of critical goods or services to be designated as critical suppliers.
During the month NHS England is inviting staff to learn new cyber security skills, run a local campaign, become a security champion and take a password pledge. Resources include centrally funded immersive cyber security learning for the NHS workforce, free NCSC-assured training for NHS boards delivered by Templar International Group, and cyber incident response exercises built on the NCSC's exercise-in-a-box service.
The Keep I.T. Confidential toolkit, which includes screensavers, animations, digital banners and social media content, is available in separate versions for health and for adult social care and can be used by any organisation at any time.
Hutton said the Cyber Security Operations Centre protects more than 37 million NHS App users and around 60,000 NHS 111 calls every day. He described two NHS organisations targeted by malicious files delivered through email links, one of which had national security tools in place and removed the threat quickly, while the other had not deployed them and required NCSC-accredited forensic teams for a more complex recovery.
Cyber Security Awareness Month 2026 resources can be found at: https://digital.nhs.uk/cyber-and-data-security/guidance-and-resources/cyber-security-awareness-month

