Cyber Security in Adult Social Care: Governance, Risk and Commissioner Assurance

Cyber security is no longer a technical back-office issue in adult social care. Digital systems now support care planning, medication administration, rostering, safeguarding, incident reporting, workforce management and communication with commissioners. A cyber incident can therefore disrupt frontline care, expose sensitive information and weaken organisational accountability within a very short period.

Providers developing digital transformation, cyber security and resilient care systems in adult social care must treat digital risk as a core governance responsibility. External IT suppliers may operate systems and technical controls, but provider boards and senior leaders remain accountable for understanding how technology affects safety, continuity, confidentiality and quality.

Cyber security increasingly connects with reliable digital records and data and robust business continuity planning. Commissioners and regulators now look beyond whether technology is available and examine whether cyber risks are identified, controlled, tested and reviewed in everyday operations.

Why cyber security is a care-governance issue

Cyber security is sometimes discussed through technical language concerning networks, malware, encryption and system access. These controls matter, but the consequences of failure are operational and personal.

A cyber incident may result in:

  • staff losing access to current care plans;
  • medication records becoming unavailable or unreliable;
  • missed or delayed homecare visits;
  • safeguarding information being inaccessible;
  • personal data being exposed or altered;
  • staff accounts being misused;
  • communication with health partners being disrupted;
  • commissioner reporting being delayed;
  • payroll and workforce systems becoming unavailable; and
  • significant loss of confidence among people and families.

Cyber security becomes a care-quality issue whenever digital failure can prevent staff from delivering safe, informed and timely support.

Cyber security as a formal governance responsibility

Providers should include cyber security within mainstream organisational governance rather than maintaining it as a separate technical workstream. Cyber risks should be considered alongside safeguarding, workforce, financial, quality and business-continuity risks.

A strong governance framework should establish:

  • named executive accountability;
  • clear operational responsibilities;
  • defined reporting and escalation routes;
  • specific organisational risk-register entries;
  • board and committee oversight;
  • supplier assurance arrangements;
  • staff training and competency requirements;
  • incident-response responsibilities;
  • business-continuity integration; and
  • continuous improvement following incidents and audits.

Responsibility should remain clear even where technology management is outsourced. Providers cannot outsource accountability for care continuity, safeguarding or lawful data use.

Named leadership and accountability

Commissioners increasingly expect providers to identify a senior leader responsible for cyber risk, information security and digital resilience. The precise title may vary, but the role should carry sufficient authority to challenge weaknesses and secure organisational action.

Senior accountability may include:

  • approving the cyber-security framework;
  • ensuring material risks reach the board;
  • overseeing improvement priorities;
  • reviewing significant incidents;
  • challenging supplier performance;
  • ensuring continuity plans are tested;
  • confirming commissioner notifications;
  • authorising material risk acceptance; and
  • monitoring whether controls remain effective.

Operational responsibility should also be distributed clearly across IT, information governance, safeguarding, quality, workforce, procurement and registered management roles.

Operational example 1: removing former staff access

Context: An internal audit identifies several former employees whose accounts remain active across care-planning and workforce systems.

Step 1: The accounts are disabled immediately and access logs are reviewed for inappropriate activity.

Step 2: The risk is escalated to senior cyber and information-governance leads because active leaver accounts create confidentiality and safeguarding exposure.

Step 3: Workforce, payroll and IT processes are mapped to identify where notifications and account closure failed.

Step 4: A revised leaver workflow is introduced with named responsibility, automatic alerts and completion deadlines.

Step 5: Monthly governance reports track unresolved accounts, average removal times and repeat exceptions.

This turns an isolated access failure into a governed organisational improvement process with clear accountability and measurable assurance.

Operational cyber risks in everyday care

Cyber risks frequently arise from ordinary operational activity rather than sophisticated external attack. Staff may develop unsafe workarounds because systems are slow, access is delayed or approved communication routes are impractical.

Common risks include:

  • shared or reused passwords;
  • care records accessed through personal devices;
  • unlocked screens in shared environments;
  • lost or stolen mobile phones;
  • personal email or messaging used for work information;
  • misdirected emails and attachments;
  • unapproved software downloads;
  • former staff retaining access;
  • excessive user permissions;
  • weak supplier controls;
  • unsupported software; and
  • poorly protected backups.

Providers should identify the operational reasons behind unsafe behaviour. Repeating policy expectations may have limited impact where staff lack suitable devices, timely access or practical alternatives.

Mapping critical digital dependencies

Effective governance begins with understanding which systems support which care functions. Providers should map digital dependencies so that risk assessments and continuity arrangements reflect real service delivery.

The map may include:

  • electronic care planning;
  • digital medication systems;
  • rostering and call monitoring;
  • incident and safeguarding platforms;
  • mobile devices and applications;
  • secure email and messaging;
  • workforce and training systems;
  • commissioner portals;
  • internet and telephone connectivity;
  • cloud hosting;
  • assistive technology; and
  • external technology suppliers.

For each dependency, leaders should understand what information is held, who relies on it, how long disruption can be tolerated and what safe alternatives exist.

Operational example 2: insecure discharge information sharing

Context: A homecare service routinely receives hospital discharge documents through unsecured email chains because the approved portal is difficult to access.

Step 1: A quality review identifies the confidentiality, version-control and recipient risks created by the informal process.

Step 2: Operational and information-governance leads assess how frequently the workaround is used and what information is being shared.

Step 3: The provider agrees a secure alternative pathway with hospital and commissioning partners.

Step 4: Staff receive practical guidance on approved transfer routes and checking recipient details.

Step 5: Subsequent audits test whether insecure email use has reduced and whether discharge information is arriving reliably.

This addresses both the security weakness and the system-access problem that caused staff to adopt the workaround.

Assessing likelihood and care impact

Cyber-risk assessment should consider the likelihood of an event and the potential consequences for people and services. Technical severity alone does not provide a complete picture.

Impact assessment should consider:

  • the number of people and services affected;
  • the sensitivity of information involved;
  • whether medication could be disrupted;
  • whether safeguarding arrangements could fail;
  • the likely duration of interruption;
  • whether manual alternatives are available;
  • the impact on staff deployment;
  • contractual or regulatory consequences;
  • financial and recovery costs;
  • supplier dependency; and
  • the potential loss of trust.

A brief outage may have limited impact in one administrative system but create immediate risk where care workers lose access to visit schedules, medication information or current support guidance.

Cyber risks within organisational risk registers

Material cyber risks should be recorded specifically within organisational and service-level risk registers. Generic wording such as “risk of cyber attack” provides limited assurance.

More useful entries may address:

  • loss of electronic care-record access;
  • compromise of privileged accounts;
  • failure of a critical cloud supplier;
  • ransomware affecting several services;
  • unsupported legacy software;
  • weak removal of leaver access;
  • inadequate backup restoration;
  • mobile-device loss;
  • phishing exposure; and
  • loss of digital medication records.

Each entry should identify the potential care impact, accountable owner, current controls, remaining exposure, required action and review date.

Implementing proportionate controls

Commissioners do not expect every provider to operate the same technology or controls. They do expect safeguards to be proportionate to organisational size, service complexity and the sensitivity of the information involved.

Common preventive controls include:

  • individual user accounts;
  • multi-factor authentication;
  • role-based permissions;
  • prompt removal of leaver access;
  • regular updates and security patches;
  • device encryption;
  • automatic screen locking;
  • email filtering;
  • malware protection;
  • approved applications and communication routes;
  • staff cyber-awareness training;
  • supplier assurance; and
  • secure backups.

Controls should be tested in practical working conditions. Security that staff cannot use reliably may encourage unsafe workarounds and increase risk.

Workforce competence and safe digital behaviour

Staff behaviour is a significant part of cyber assurance. Providers should integrate safe digital practice into induction, supervision, competency assessment and ongoing learning.

Training should cover:

  • recognising phishing and suspicious activity;
  • password and authentication safety;
  • secure mobile-device use;
  • approved information-sharing routes;
  • checking email recipients and attachments;
  • reporting mistakes promptly;
  • responding to lost devices;
  • system-outage arrangements;
  • protecting temporary records; and
  • the connection between cyber security and safe care.

Completion rates alone are insufficient. Providers should assess practical understanding through scenarios, supervision, spot checks and incident analysis.

Operational example 3: responding to a phishing incident

Context: A registered manager enters login details into a fraudulent website after receiving an email appearing to come from a commissioner.

Step 1: The manager reports the error immediately through the cyber-incident route.

Step 2: The compromised account is disabled, active sessions are terminated and linked systems are reviewed.

Step 3: Information-governance and safeguarding leads assess whether sensitive information was accessed or disclosed.

Step 4: Relevant staff and external recipients are warned about potentially fraudulent messages.

Step 5: The quality committee monitors improvements to email filtering, staff training and authentication controls.

Prompt reporting reduces potential harm. Governance should distinguish honest mistakes from deliberate misconduct and support a culture where staff escalate concerns without delay.

Incident response and escalation

Providers need clear arrangements for recognising, containing and managing cyber incidents. Staff should not be expected to diagnose the technical cause before reporting a concern.

Incident plans should define:

  • what staff must report;
  • how concerns are escalated;
  • who provides out-of-hours leadership;
  • who manages technical containment;
  • who protects care continuity;
  • who assesses safeguarding and data risks;
  • who communicates with commissioners;
  • who authorises system restoration;
  • how decisions are recorded; and
  • how learning is reviewed.

Technical recovery and operational continuity should be coordinated but remain clearly accountable. Restoring systems should not distract leaders from maintaining safe care during disruption.

Business continuity and digital resilience

Cyber-security controls should connect directly with business-continuity arrangements. Providers must be prepared to maintain essential support when digital systems become unavailable.

Continuity planning should preserve access to:

  • current medication and allergy information;
  • critical care plans and risk assessments;
  • safeguarding and protection plans;
  • moving-and-handling guidance;
  • communication needs;
  • visit schedules and staffing priorities;
  • delegated healthcare instructions;
  • emergency contacts; and
  • urgent escalation routes.

Temporary paper or offline records must be current, controlled and securely stored. Outdated contingency information may create greater risk than temporary digital unavailability.

Testing continuity arrangements

A written continuity plan provides limited assurance unless staff have tested it in realistic conditions.

Exercises may include:

  • loss of electronic care records;
  • failure of medication systems;
  • unavailable rostering platforms;
  • ransomware across several services;
  • loss of internet or mobile connectivity;
  • compromise of organisational email;
  • supplier outage; and
  • extended recovery delays.

Exercises should test frontline action, decision-making, access to essential information, safeguarding, communication, restoration and record reconciliation.

Cyber security and safeguarding

Cyber security directly supports safeguarding. Confidential information may be exposed, but loss of access can be equally serious where staff cannot see current protection arrangements.

Providers should consider whether cyber incidents affect:

  • active safeguarding concerns;
  • contact restrictions;
  • known sources of risk;
  • capacity and best-interests information;
  • financial-support records;
  • health and medication information;
  • addresses and personal contact details;
  • communication and advocacy needs; and
  • the ability to implement protection plans.

Safeguarding leads should be involved where compromised or unavailable information could increase a person’s vulnerability.

Cyber incidents within quality systems

Digital and data-related incidents should be recorded within wider quality-assurance arrangements rather than retained solely within technical logs.

Quality systems should capture:

  • the type and severity of the event;
  • services and people affected;
  • care disruption;
  • safeguarding implications;
  • data-protection consequences;
  • technical and operational causes;
  • immediate containment;
  • continuity arrangements;
  • improvement actions; and
  • evidence of sustained change.

This allows providers to identify themes across cyber incidents, service disruptions, staff practice and supplier performance.

Supplier governance and assurance

External suppliers often host or manage care records, medication systems, mobile applications, communications and workforce platforms. Supplier failure can therefore affect care even where internal controls are strong.

Supplier assurance should consider:

  • security standards;
  • data-hosting arrangements;
  • subcontractor dependencies;
  • service availability;
  • incident-notification timescales;
  • backup and restoration capability;
  • out-of-hours support;
  • supplier access permissions;
  • data export and portability;
  • contract termination; and
  • secure deletion.

Critical suppliers should feature within risk registers, continuity exercises and board reporting. Outsourcing technology does not outsource provider accountability.

Commissioner expectations and assurance requirements

Commissioners increasingly assess cyber governance during tender evaluation, mobilisation and contract monitoring. They are generally more interested in practical control and resilience than technical sophistication.

Providers may be expected to demonstrate:

  • named senior accountability;
  • cyber risks within organisational registers;
  • role-based access controls;
  • staff training and competency;
  • supplier assurance;
  • incident-response arrangements;
  • secure backups and tested restoration;
  • service-level downtime procedures;
  • safeguarding integration;
  • commissioner-notification routes;
  • board oversight; and
  • learning from incidents and audits.

Strong tender responses should explain how these arrangements operate in daily practice and what evidence confirms that controls have been tested.

Regulatory and inspection confidence

Inspectors may explore how leaders assure themselves that digital records are secure, accurate and available. They may also ask frontline workers what they would do if systems failed.

Providers should be able to evidence:

  • clear cyber-security leadership;
  • current risk assessments;
  • appropriate user access;
  • safe staff practice;
  • prompt reporting routes;
  • incident learning;
  • service-continuity procedures;
  • supplier oversight;
  • board awareness of material risk; and
  • tested improvement actions.

Policies provide limited assurance where staff cannot explain their responsibilities or leaders cannot demonstrate how risks are monitored.

Board and senior leadership oversight

Boards should receive structured information that explains how cyber risk could affect people, operations and organisational obligations.

Useful assurance may include:

  • significant incidents and near misses;
  • system outages affecting care;
  • current high and emerging risks;
  • phishing and workforce-awareness trends;
  • access-control exceptions;
  • former staff accounts awaiting closure;
  • supplier-performance concerns;
  • backup and restoration results;
  • continuity-exercise findings;
  • overdue improvement actions; and
  • changes in residual risk.

Reports should distinguish between controls that exist, controls that have been tested and actions that remain outstanding.

Board challenge and decision-making

Board members do not need technical expertise, but they should ask informed questions about organisational exposure and preparedness.

Useful questions include:

  • Which systems are essential to safe care?
  • What would happen if they failed today?
  • When were backups last restored successfully?
  • How quickly is former staff access removed?
  • Which supplier creates the greatest dependency?
  • What recent incidents or near misses have occurred?
  • Can frontline staff use downtime arrangements?
  • Are any high-risk actions overdue?
  • What evidence demonstrates improvement?
  • Which risks have been formally accepted?

Board oversight should lead to decisions about investment, priorities, risk acceptance and accountable action.

Audit and independent assurance

Cyber controls should be tested through internal audit, supplier review and independent assessment where proportionate.

Audit activity may include:

  • user-access reviews;
  • leaver-account testing;
  • device inventories;
  • software-update compliance;
  • phishing simulations;
  • penetration testing;
  • supplier assurance;
  • backup restoration;
  • incident-response exercises;
  • service-level continuity plans; and
  • closure testing for previous findings.

Repeated weaknesses should be escalated because they may indicate insufficient resources, leadership attention or ineffective system design.

Measuring cyber-security effectiveness

Providers should use practical measures that show whether controls are reducing risk and protecting care.

Useful indicators may include:

  • number and severity of cyber incidents;
  • time taken to report and contain events;
  • phishing simulation outcomes;
  • lost-device trends;
  • overdue access reviews;
  • time taken to remove leaver accounts;
  • backup and restoration success;
  • supplier outages;
  • service disruption caused by digital failure;
  • repeat audit findings;
  • completion of high-risk actions; and
  • staff confidence in reporting.

An increase in near-miss reporting may initially reflect stronger awareness and a healthier culture rather than deteriorating security.

Reviewing cyber security after change

Cyber risks and controls should be reassessed whenever technology, suppliers or service models change.

Review triggers include:

  • implementation of new software;
  • integration between platforms;
  • opening or acquiring services;
  • changes in hosting or suppliers;
  • increased mobile or remote working;
  • new commissioner reporting;
  • introduction of artificial intelligence tools;
  • significant workforce change;
  • a cyber incident or near miss; and
  • new regulatory or contractual requirements.

Cyber review should form part of change governance before implementation rather than being added after vulnerabilities emerge.

Continuous improvement after incidents and audits

Cyber security is not a one-off compliance exercise. Learning should result in specific improvements to technology, workforce practice, supplier management or continuity arrangements.

Improvement actions should include:

  • a clearly defined weakness;
  • a named accountable owner;
  • a realistic target date;
  • required evidence;
  • risk-based escalation if delayed;
  • testing after implementation; and
  • confirmation that change has been sustained.

Updating a policy or delivering training should not automatically close an action unless the provider can demonstrate improved practice or control effectiveness.

Common pitfalls

A common weakness is treating cyber security as the responsibility of an external IT supplier while senior leaders receive little assurance about care impact and residual risk.

Other pitfalls include:

  • unclear senior accountability;
  • generic risk-register entries;
  • shared or excessive user access;
  • slow removal of former staff accounts;
  • training completion without competency testing;
  • insecure informal communication;
  • supplier contracts without practical resilience assurance;
  • backups that have never been restored;
  • outdated contingency records;
  • weak integration with safeguarding;
  • technical reports that do not explain operational consequences;
  • closing actions without testing effectiveness; and
  • failing to reassess controls after system change.

Providers should also avoid controls that are so complex that staff routinely bypass them. Secure practice must remain compatible with safe, responsive care delivery.

Building mature cyber security in adult social care

Strong providers embed cyber security within mainstream governance, safeguarding, workforce development, quality assurance and business continuity. They understand where technology supports essential care and design proportionate controls around those dependencies.

A mature framework includes:

  • named executive accountability;
  • specific cyber-risk assessments;
  • clear operational ownership;
  • proportionate access and technical controls;
  • staff awareness and competence;
  • supplier assurance;
  • integrated incident response;
  • tested business continuity;
  • board and commissioner oversight;
  • audit and independent challenge;
  • measurable improvement; and
  • continuous review after change.

Cyber security ultimately protects people as well as systems and information. Providers that understand their digital dependencies, maintain clear accountability and test their arrangements are better equipped to prevent disruption and respond safely when incidents occur.

By treating cyber security as a core governance and operational issue, adult social care organisations can strengthen resilience, protect confidentiality and demonstrate to commissioners and regulators that digital care is supported by credible assurance rather than unmanaged risk.