60% of NHS staff want more cyber security training, finds study

  • 4 March 2025
60% of NHS staff want more cyber security training, finds study
Shutterstock.com
  • Research from BT found that 94% of NHS staff understand their role in protecting the organisation from cyber attacks, yet only 36% believe current measures are sufficient
  • It also found that 60% of frontline staff report a lack of regular cyber security training
  • 64% of NHS staff report that outdated systems make data hard to access and use

Research from BT found that 94% of NHS staff understand their role in protecting the organisation from cyber attacks, yet only 36% believe current measures are sufficient.

The independent online survey of 76 NHS staff at 59 NHS organisations and integrated care systems, carried out between 8 September 2024 and 16 September 2024, explored sentiment around digital healthcare in the UK.

It found that only 42% of NHS staff surveyed trust that existing systems are robust enough to safeguard sensitive patient data and 64% report that patient data is isolated and inoperable due to outdated systems.

Despite a rise in training on new technologies from 5% in BTā€™s 2022 survey to 15% in the 2024 survey, training on both new and existing systems has fallen from 47% to 39%, with 60% of frontline staff surveyed calling for more cyber security training.

Commenting on the research, Professor Natasha Phillips, former chief digital nurse to NHS England, founder of Future Nurse and BT clinical advisory board (CAB) member, said: ā€œIn healthcare, cyber security isnā€™t just about protecting data; itā€™s about protecting lives.

ā€œNurses are often the first point of care. To deliver life-saving and compassionate treatment, they depend on easy access to secure systems.

ā€œAs we embrace digital innovation, we must ensure that all clinicians have the confidence, training, and tools to work safely and free from disruption.

ā€œUltimately, building a resilient NHS requires a united effort, where technology, training, and trust come together.ā€

A YouGov survey of 2,159 adults in the UK, carried out online between 5 July 2024 and 8 July 2024, found that 60% of UK citizens are concerned that critical NHS systems could be disrupted or disabled by cyber attacks and 56% are concerned about patient data exposure.

Professor Sultan Mahmud, director of healthcare at BT, said: ā€œThe NHS is rightly focused on saving lives, so it can be hard to stay ahead of cyber security threats with the landscape shifting so quickly.

ā€œThreats targeting healthcare have grown in frequency and sophistication, endangering patient care and compromising vital services.

ā€œBT logsĀ 2,000 signals of potential cyber attacks every second, totalling 200 million per day across sectors.

ā€œWithĀ over 1.7 million employees, the NHS is the UK’s biggest employer, so empowering this workforce is vital.

ā€œAcross the NHS, high awareness of cyber risk is overshadowed by a lack of preparedness.

ā€œMoreover, significant frustrations with legacy systems are affecting care, exacerbating training gaps.ā€

NHS private service provider, the HCRG Care Group, confirmed in February 2025 that it is investigating a suspected ransomware attack, after a cyber crime group claimed that it has breached sensitive information.

Figures revealed in January 2025, found that at least two patients suffered long-term or permanent damage to their health as a result of the cyber attack on NHS pathology provider Synnovis in June 2024.

Meanwhile, waiting times for cancer pathways at Wirral University Teaching Hospital NHS Foundation Trust were ā€œsignificantly impactedā€ by a cyber incident in November 2024, according to trust board papers.

Subscribe to our newsletter

Subscribe To Our Newsletter

Subscribe To Our Newsletter

Sign up

Related News

Data chief raises concern about future of NHSE cyber security team

Data chief raises concern about future of NHSE cyber security team

Guysā€™ and St Thomasā€™ NHS Foundation Trustā€™s digital chief has called on the government not to scrap the NHS England cyber security team.
Medefer refutes claim that security flaw left patient data vulnerable

Medefer refutes claim that security flaw left patient data vulnerable

Online healthcare provider Medefer has denied claims that its application programming interface (API) left NHS patient data vulnerable.
Digital Health Coffee Time Briefing ā˜•

Digital Health Coffee Time Briefing ā˜•

This Coffee Time Briefing includes a pledge to boost digital inclusion and AI-powered cardiovascular screening using retinal imaging.

Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.