Site navigation

NHS Calls On Suppliers to Improve Their Cybersecurity

Elizabeth Greenberg

,

nhs supplier cybersecurity
The NHS is urging their suppliers to improve their cybersecurity posture to protect patient data and critical infrastructure. 

Digital and cyber leaders at the NHS are calling on its suppliers to sign up to a voluntary cybersecurity charter as it aims to build its resilience against cyber threats along its supply chain.

In the wake of several retail cyber-attacks and with a long history of breaches across different health boards and various vendors, the NHS is urging its suppliers to take cybersecurity more seriously by signing the voluntary charter.

In an open letter to vendors stated: “As valued partners to the NHS, it is important to us that we work together and defend as one.”

As the Cyber Security and Resilience Bill aims to reform the cyber regulation in the UK, the NHS is calling on suppliers to ensure that their systems are secure to protect patient data and operations.

The open letter has a list of requirements for vendors, such as supporting systems with the latest patches to address vulnerabilities, achieving at minimum a ‘Standards Met’ as part of the Data Security and Protection Toolkit (DSPT), and applying multi-factor authentication to networks and systems.

The NHS is also asking suppliers to deploy effective 24/7 cyber monitoring and logging of critical IT structures, as well as ensuring they have immutable backups of critical data and products.

It also requires suppliers to have undertaken board level exercising to ensure confidence in incident response, and that any incidents are reported according to all regulatory requirements promptly.

Further, it states that vendors suppling software to the NHS must ensure that this has been produced in adherence to the National Cyber Security Centre’s software code of practice.


Recommended reading


Suppliers must commit to being a partner to the NHS by signing the charter for cybersecurity good practice, join the NHS in future supplier summits and engagement opportunities to continually keep the NHS resilient to attack, and work with local NHS customer to provide mutual understanding of incident preparation.

The charter also includes a series of legal obligations to maintain cybersecurity in agreements with NHS organisations.

The NHS also says that it has acknowledged the tumultuous cyber landscape, and is working to develop tools to ensure suppliers can carry out appropriate assurance.

The NHS is also working to define requirements for a national supplier management platform, as well as reviewing the contractual frameworks that NHS organisations use to enter contracts.

Cyber leaders at the NHS will be launched a series of webinars over the next coming months as well as building a supplier forum for cybersecurity in the autumn to help vendors close the cybersecurity gap.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data