Site navigation

PwC: Reduced Cyber Budgets Putting Healthcare Sector at Risk

Rachel Sim

,

healthcare cyber budgets
Organisations in the healthcare sector are accepting risks to cybersecurity to avoid the significant upfront costs.

A PwC survey of 381 global healthcare executives has highlighted the critical risks the sector faces amid pressure to cut cybersecurity budgets. 

Whilst organisations are aware of the potential vulnerabilities, many feel pressured to compromise on cybersecurity to reduce financial strain and prioritise other operations. 

Below, we’ll take a look at some of the key data and insights derived from PwC’s survey.

What are the top threats?

Last year saw a significant increase in high profile cyber-attacks, which are becoming more sophisticated and increasingly damaging to organisations. 

Despite the sensitive and critical nature of their work, only 35% of healthcare organisations have implemented data controls across the entire data lifecycle. This is a 9% deficit when compared to averages across other sectors.

Globally, healthcare organisations are becoming increasingly invested in technology and digital platforms, whether that be the use of digital records or managing online financial transactions, making them a high value target for cyber criminals. 

With limited budgets and increasing demands, IT leaders within the healthcare sector are having to cut their cloth accordingly, weighing up investing in data protection, cybersecurity, AI, or digital systems. Cybersecurity often only becomes a priority when a reactive response is required to a threat. 

However, there are many reasons investment in cybersecurity should remain top of the priority list – attacks are at an all time high, patient information is at significant risk and reputational damage can be catastrophic for an organisation.

Cloud-related threats, quantum computing risks and attacks on connected products are thought to pose the highest risks to the sector. 

Regulators are increasingly introducing tighter regulations about how personal (patient) information is stored and managed, so whilst budgets have been cut, there are parameters organisations will have to adhere to in order to meet regulatory requirements. 

As such, PwC suggests that data protection and security awareness should be top priorities for training in 2026.

Ensuring Organisations are Protected

According to the report, some organisations in the healthcare sector are accepting risks to cybersecurity to avoid the significant upfront costs. 

However, the importance of maintaining trust in healthcare providers can not be understated and is one of the key drivers for increasing investment in cybersecurity.

This is the case more than ever as the UK health sector undergoes rapid transformation in the advent of AI, with the Medicines and Healthcare products Regulatory Agency (MHRA) reporting 17% more clinical investigations approved in 2025 as cutting-edge medtechs race to market.

With the substantial risks and opportunities posed, IT leaders are looking to prioritise spend in cybersecurity and AI in 2026, according to PwC. Balancing innovation and seizing opportunities will have to be carefully balanced with risk to avoid organisational and customer damage. 


Recommended reading


Organisations must build security measures into their systems and processes from the ground up. 

The implementation of a new system is the ideal time to consider security as it avoids organisations having to take back steps and fix problems further down the line. 

Beyond this, outsourcing creates opportunities for organisations, particularly smaller ones with less in-house expertise, to reduce resource requirements and leave security to experts.

Couple this with strong data governance and future proofing for regulatory changes, as well as conducting ongoing risk assessments, vulnerability testing, disaster recovery planning and broader organisational training, will allow organisations to foster a more robust cybersecurity environment. 

Essentially, PwC posits that the healthcare sector must make substantial and informed decisions about their cybersecurity spending to ensure long-term protection for organisations and to uphold customer trust. 

Rachel Sim

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data