Cyber Resilience in NHS-Commissioned Services: Managing Digital Risk

Cyber incidents disrupt care, not just IT systems. For NHS-commissioned services, cyber resilience is now directly connected to patient safety, business continuity, information governance, commissioner assurance and system trust. When digital systems fail, providers may lose access to care records, rotas, medicines information, referral updates, escalation notes, contact details and performance data. The impact is operational, clinical and reputational.

This article sits within the wider NHS & Integrated Community Services Knowledge Hub, supporting providers working across community care pathways, clinical governance, system partnerships and population health. It also links closely with business continuity, IT and systems resilience, NHS digital, data and interoperability and NHS quality, safety and governance.

Why cyber resilience matters to NHS commissioners

NHS commissioners increasingly expect providers to treat cyber resilience as part of safe service delivery. Digital systems now support referral management, discharge coordination, clinical notes, rotas, medicines administration, incident reporting, safeguarding escalation, performance reporting and communication with system partners. If those systems are unavailable, inaccurate or compromised, the risk moves quickly from IT into care quality.

For NHS-commissioned services, cyber resilience is also a trust issue. Commissioners need confidence that providers can protect sensitive information, maintain continuity during disruption and recover quickly after an incident. A provider that cannot explain how it would continue care during a digital outage may be seen as operationally fragile, even where frontline practice is otherwise strong.

Cyber risk is a care risk

Cyber security is sometimes treated as a technical matter owned by IT suppliers or system administrators. That view is too narrow. In community health and integrated care services, cyber risk can affect:

  • access to care records and risk assessments
  • medicine administration and delegated healthcare tasks
  • referral acceptance and discharge flow
  • rota coverage and lone working oversight
  • safeguarding alerts and incident escalation
  • communication with ICBs, NHS trusts, GPs and local authorities
  • contract reporting and commissioner assurance
  • confidentiality and public trust

Cyber resilience should therefore sit within governance, quality assurance, business continuity and risk management, not only within IT support arrangements.

Common cyber risks in NHS-commissioned services

Commissioners and auditors often identify recurring cyber and digital resilience risks. These include outdated software, unsupported devices, weak password practice, shared logins, poor access controls, limited staff awareness, unclear incident escalation and insufficient testing of downtime procedures.

Other risks are more subtle. A provider may have a secure system but poor user management, meaning former staff retain access longer than they should. A digital care record may be reliable but lack a tested downtime process. A supplier may host critical data but the provider may not fully understand backup, recovery or breach notification arrangements. These gaps can become serious during an incident.

What commissioners expect providers to evidence

Commissioners are unlikely to expect every provider to operate like a large NHS trust. They do, however, expect proportionate and practical cyber resilience controls. Providers should be able to evidence:

  • clear cyber security and information governance policies
  • named leadership accountability for digital and cyber risk
  • access control processes, including starters, leavers and role changes
  • regular software updates, patching and supplier assurance
  • staff awareness training on phishing, scams and data protection
  • incident response and escalation procedures
  • downtime and recovery arrangements
  • business continuity links for critical digital systems
  • post-incident review and learning processes

The strongest providers can show that cyber resilience is not a one-off policy exercise. It is reviewed, tested and improved over time.

Operational example 1: digital outage affecting discharge support

Context: A provider supports people discharged from hospital into short-term reablement. The service relies on digital referrals, electronic care records and rota systems.

Risk: A system outage prevents staff accessing referral updates and care plan changes. Without a backup process, staff may miss medication changes, equipment needs or escalation instructions.

Resilient response: The provider activates its downtime procedure, uses a secure backup list of current high-risk cases, confirms priority information with discharge coordinators and records temporary notes using an agreed contingency template.

Evidence: Governance records show when the outage was identified, who escalated it, what continuity controls were used, how care was prioritised and what learning was applied after recovery.

Staff awareness and day-to-day practice

Human error remains one of the most common cyber risks. Staff may click phishing emails, use weak passwords, share devices, leave records visible, send information to the wrong recipient or delay reporting suspicious activity. Strong cyber resilience therefore depends on simple, repeated and practical staff guidance.

Effective staff awareness should cover:

  • how to identify phishing and suspicious links
  • what to do if a device is lost or stolen
  • rules for passwords and multi-factor authentication
  • safe use of email and messaging
  • information-sharing boundaries
  • how to report concerns quickly
  • what to do during system downtime

Training should be reinforced through supervision, team briefings, induction and incident learning. Cyber awareness is most effective when it is linked to real service scenarios rather than generic IT language.

Access controls and user management

Access control is one of the most important day-to-day cyber resilience controls. Providers should ensure staff only access the information they need for their role and that access is removed promptly when people leave or change duties.

Useful controls include:

  • individual logins rather than shared accounts
  • role-based permissions
  • prompt removal of leaver access
  • regular user access reviews
  • multi-factor authentication where available
  • clear rules for temporary, agency or bank staff access
  • audit trails for sensitive records

Commissioners may not ask about every technical detail, but they will expect providers to protect confidential information and reduce avoidable exposure.

Supplier assurance and third-party risk

Many providers rely on external suppliers for care records, rostering, medicines systems, payroll, HR, incident reporting, learning platforms and secure communication. This creates third-party risk. If a supplier fails, is breached or cannot recover quickly, the provider may still be accountable for service continuity and information governance.

Providers should understand:

  • where data is stored
  • how systems are backed up
  • how quickly services can be restored
  • how incidents are reported by the supplier
  • what support is available during disruption
  • whether the supplier maintains relevant security controls
  • how data can be exported if needed

Supplier assurance does not need to become overly complex for smaller providers, but it should be documented and reviewed. Relying on a system without understanding recovery arrangements creates avoidable risk.

Operational example 2: phishing email and rapid containment

Context: A team member receives an email appearing to come from an NHS partner asking them to open a document and confirm login details.

Risk: If the link is used, credentials could be compromised and sensitive service information exposed.

Resilient response: The staff member reports the email immediately through the provider’s cyber reporting route. The provider alerts the IT support contact, blocks the sender, checks whether anyone clicked the link, changes affected passwords if required and reminds staff of phishing indicators.

Evidence: The provider records the incident, action taken, staff communication, learning shared and whether any further control changes are needed.

Incident response and escalation

Cyber incident response should be clear before an incident occurs. Staff need to know what to report, who to contact, how quickly to escalate and what immediate actions may be required. Managers need to know when to involve IT support, senior leadership, commissioners, suppliers, information governance leads or external reporting routes.

A practical cyber incident response process should cover:

  • initial identification and containment
  • internal escalation
  • supplier or IT support contact
  • assessment of service impact
  • assessment of data protection implications
  • communication with commissioners or partners where required
  • continuity arrangements for affected services
  • recovery steps
  • post-incident learning

The key test is whether the process works under pressure. A policy that staff do not understand will not protect services during a live incident.

Business continuity and maintaining care delivery

Cyber resilience and business continuity should be integrated. Providers should identify which digital systems are critical to safe delivery and what will happen if each system becomes unavailable.

Critical questions include:

  • How will staff access essential care information?
  • How will rotas and visits be managed?
  • How will medicines information be checked?
  • How will incidents or safeguarding concerns be recorded?
  • How will managers contact staff and system partners?
  • How will commissioners be updated if service delivery is affected?
  • How will temporary records be transferred back into digital systems after recovery?

Providers should test these arrangements. Untested downtime plans often fail because contact lists are outdated, staff are unsure where backup information is stored or managers do not know who has decision-making authority.

Operational example 3: cyber incident affecting rota and care records

Context: A commissioned community service loses access to its rota and care record system due to a suspected cyber incident.

Risk: Staff may not know current visit allocations, care plan updates or priority risks. Missed visits, poor handovers and safeguarding delays could follow.

Resilient response: The provider activates its continuity plan, uses secure backup rota information, prioritises high-risk visits, assigns managers to confirm key care information, logs all temporary changes and informs the commissioner where service risk is possible.

Evidence: The incident log captures escalation times, continuity decisions, people affected, service impacts, communications, recovery actions and post-incident improvement.

Governance oversight of cyber resilience

Cyber resilience should be visible within governance. Senior leaders should periodically review cyber risk, supplier assurance, incident themes, staff training, access controls, business continuity testing and improvement actions.

Governance questions may include:

  • What are our most critical digital systems?
  • What would happen if each system failed?
  • When were downtime procedures last tested?
  • Are staff confident in cyber reporting?
  • Are access controls reviewed regularly?
  • Are supplier risks understood?
  • Have incidents or near misses led to learning?

This gives commissioners confidence that cyber resilience is actively managed rather than assumed.

Regulatory and commissioner assurance

Cyber resilience supports wider assurance expectations. Commissioners may ask about digital risk in tenders, contract reviews, mobilisation planning, quality meetings or serious incident follow-up. Providers that can evidence practical controls are better placed to show maturity.

Strong assurance evidence may include:

  • cyber security policy
  • information governance policy
  • business continuity plan
  • system downtime procedure
  • staff training records
  • incident logs and learning records
  • supplier assurance checks
  • access control review records
  • business continuity test outcomes

This evidence should be easy to locate. If evidence cannot be produced during assurance activity, confidence may reduce even where controls exist in practice.

What good looks like in practice

Strong providers can show that cyber resilience is embedded into leadership, operations and improvement. They do not rely solely on policies or suppliers. They understand which systems are critical, how risks are controlled, how staff are trained, how incidents are escalated and how care will continue if systems fail.

Good practice includes:

  • clear leadership accountability
  • practical staff awareness
  • strong access controls
  • tested downtime procedures
  • supplier assurance
  • cyber scenarios in business continuity testing
  • post-incident learning
  • regular governance review

This reassures commissioners that digital dependency is being managed safely.

Conclusion

Cyber resilience in NHS-commissioned services is now a core part of safe, reliable and trusted care delivery. A cyber incident can affect records, rotas, medicines information, referrals, safeguarding, reporting and communication. It is therefore both a digital risk and a service risk.

Providers that manage cyber resilience well can demonstrate practical controls, clear accountability, staff awareness, tested continuity arrangements and learning from incidents. This strengthens commissioner confidence and helps protect people using services when digital disruption occurs.