Info Gov

NHS England has published a toolkit of campaign assets and template copy for health and care organisations ahead of Cyber Security Awareness Month in October, telling staff that keeping the NHS safe is everyone's responsibility and not only a matter for IT and security teams.

James Hutton, Head of Protective Monitoring at NHS England, said in a blog published on 2 September and linked from the campaign page that "You don't need to be a cyber security expert to make a big difference." Hutton said clinical staff are not expected to configure firewalls or deploy antivirus software, but that the most effective defence comes when IT teams and frontline staff work together.

The campaign asks staff to take four steps:

- use strong passwords
- turn on multi-factor authentication
- recognise and report phishing
- keep up to date with learning

NHS England said cyber criminals target healthcare because of the sensitive data it holds and the critical services it provides. It pointed to the 2024 ransomware attack on pathology provider Synnovis, which affected multiple NHS organisations and disrupted patient services across London, and to incidents involving suppliers including Ortivus as evidence of how interconnected healthcare has become.

It also cited attacks on M&S, Co-op and Harrods, and said criminals are increasingly using artificial intelligence to create convincing scams and impersonate trusted people.

Controllers and processors in health and care are required by Article 5(1)(f) and Article 32 of the UK GDPR to apply appropriate technical and organisational measures to secure personal data, and organisations with access to NHS patient data must complete the Data Security and Protection Toolkit each year.

NHS bodies designated as operators of essential services are also subject to the Network and Information Systems Regulations 2018, which the Cyber Security and Resilience (Network and Information Systems) Bill would amend. The Bill completed its Commons stages on 16 June 2026 and began committee stage in the House of Lords on 1 September. The minister told peers at second reading that the Synnovis attack delayed 11,000 appointments, and the Bill would allow suppliers of critical goods or services to be designated as critical suppliers.

During the month NHS England is inviting staff to learn new cyber security skills, run a local campaign, become a security champion and take a password pledge. Resources include centrally funded immersive cyber security learning for the NHS workforce, free NCSC-assured training for NHS boards delivered by Templar International Group, and cyber incident response exercises built on the NCSC's exercise-in-a-box service.

The Keep I.T. Confidential toolkit, which includes screensavers, animations, digital banners and social media content, is available in separate versions for health and for adult social care and can be used by any organisation at any time.

Hutton said the Cyber Security Operations Centre protects more than 37 million NHS App users and around 60,000 NHS 111 calls every day. He described two NHS organisations targeted by malicious files delivered through email links, one of which had national security tools in place and removed the threat quickly, while the other had not deployed them and required NCSC-accredited forensic teams for a more complex recovery.

Cyber Security Awareness Month 2026 resources can be found at: https://digital.nhs.uk/cyber-and-data-security/guidance-and-resources/cyber-security-awareness-month

Also in this section

Sep 23, 2026

Prime Minister announces new National Centre for Information Defence

Prime Minister Andy Burnham has tasked the UK's security chiefs with establishing a National Centre for Information Defence to detect, attribute and disrupt hostile state information attacks, telling the UN General Assembly in New York on 22 September that AI would "multiply the threat" from disinformation and deepfakes.
Sep 11, 2026

Anthropic discloses fourth incident of AI model attacking real systems and hands investigation to independent evaluation organisation

Anthropic has published details of four incidents in which its Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations, downloading and modifying user records at a real company, reading the personal information of an individual, harvesting credentials and accessing a security vendor's live database, after the test environments were mistakenly…
Sep 10, 2026

Welsh environmental watchdog hit by data breach

Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public.
Aug 24, 2026

Ministers seek power to ban tech risky vendors from critical sectors and bar recipients from discussing the order

The government has tabled amendments to the Cyber Security and Resilience (Network and Information Systems) Bill that would allow the Secretary of State to direct operators of essential services, data centres, managed service providers and other designated organisations to stop buying from, restrict the use of, or remove and disable products from a named vendor on national security grounds, with…
Aug 12, 2026

ACRO Criminal Records Office reprimanded by ICO following cyber security failings

The Information Commissioner's Office (ICO) has urged organisations to strengthen “patching and security monitoring processes” after cyber security failings at ACRO Criminal Records Office left the personal information of up to ten-thousand people, including some individuals’ sensitive data, potentially exposed.
Aug 06, 2026

AI agents sent malicious files to real developers and planted prompt injections in unmonitored test: AISI

The AI Security Institute (AISI) has published an incident report disclosing that AI agents under evaluation in its research environment took sustained, unsanctioned action against real people and organisations on the live internet, including researching the human maintainers of an open-source project, creating fake online identities to pressure one of them into approving malicious code, and…

InfoGov Masthead Newsletter 800