WannaCry was arguably the most high-profile cyber attack of 2017. For the National Health Service, this ransomware proved to be devastating, knocking out computer systems across the UK and resulting in a costly recovery process.
More than one year on, the health service in England is still struggling and the financial losses incurred due to this attack are staggering. According to a report published by the Department of Health and Social Care, efforts to bolster the NHS’ IT resilience are underway, but there are significant challenges and costs involved.
Costly Consequences
The 2017 WannaCry attack, according to the Department, cost the NHS approximately £92 million. These figures include around £19 million of lost output, as well as £73 million in IT costs during the aftermath. These numbers highlight both the devastation of the attack, but the increased need for greater IT resilience across the NHS and other public services.
While the attack itself wreaked havoc, this event did play a significant role in prompting the NHS to adopt more stringent IT security methods. Having signed a three-year deal with Microsoft – worth roughly £150 million – to update its Windows 10 systems, more than 130 organisations have deployed Advanced Threat Protection, according to the Department of Health and Social Care.
“This national agreement allows local NHS organisations to save money, reduce potential vulnerabilities and increase cyber resilience,” the NHS claimed.
Case studies were carried out at an NHS mental health trust, which the report said was “very impressed” with Advanced Threat Protection and is “already experiencing the benefits this provides.”
The benefits that the report mentions were highlighted due to rather concerning practices by staff, it must be noted. During testing a member of staff is alleged to have opened a phishing email containing a “malicious excel spreadsheet attachment”. ATP notified IT security teams of this and the issue was resolved.
Additionally, staff are alleged to have downloaded malware from a website which, given the widespread issues caused by malware some 12-months before, is concerning.
The report also highlighted the procurement of a new Cyber Security Operations Centre (CSOC), which it said is helping to boost the “national capacity to prevent, detect and respond to cyber attacks.”
IBM will collaborate with NHS Digital as part of this initiative in a three-year strategic partnership worth £30 million.
In total, more than £250 million will be invested nationally to improve the cybersecurity effectiveness of the healthcare system. This does, however, exclude investment by local organisations, as well as wider national IT investment which supports better security; such as the Microsoft licensing agreement.
Failing to Commit
While the report underlines the fact that proactive steps are being taken, it also suggests that the NHS will fail to reach deadlines on cybersecurity standards. In an update report published in February, NHS England said it aimed to reach the Cyber Essentials Plus standards in June 2021. In this recent publication, it appears to have distanced itself from this claim.
Meeting these standards could pose a significant challenge for the NHS. The Health Service Journal (HSJ) recently reported that achieving the Cyber Essentials Plus certification could cost anywhere between £800 million and £1 billion.
Documents released under Freedom of Information also revealed the NHS Digital is of the opinion that this would not be “value for money” and casts doubt on the health service’s ability – and resolve – to maintain standards in this regard.






