While nearly all (94%) of NHS staff understand their role in protecting the organisation from cyber-attacks, only 36% believe current measures are sufficient, new online research from BT has found.
Meanwhile, most UK citizens (60%) are concerned that cyber-attacks could disrupt or disable critical NHS systems.
BIT surveyed both staff and the public from around 200 NHS trusts the company works with, exploring sentiment around digital healthcare in the UK, underscoring the pivotal role cybersecurity plays in safeguarding patients and helping protect service delivery.
The research revealed a stark reality around anxiety over NHS cybersecurity, as well as the need for updated equipment and training to keep pace with emerging and advancing attacks.
Over half (57%) of UK citizens BT polled say they worry about cyber-attacks on the NHS, and 56% are concerned about patient data exposure.
The high figure shows that cybersecurity has entered the public consciousness, with people now seeing a direct link between secure systems and healthcare delivery.
NHS staff are also taking notice, and are calling for action, as just 42% trust that existing systems are robust enough to safeguard sensitive patient data, revealing the importance of connecting staff with the tools and infrastructure needed to work effectively.
Currently, the NHS faces a critical challenge with legacy technology systems, which lack the level of inbuilt cybersecurity found in more modern systems, hindering care delivery and collaboration.
Nearly two-thirds (64%) of NHS staff report that patient data is isolated and inoperable due to outdated systems. These technological constraints threaten the ability of staff to deliver care safely and efficiently.
Investing in future-proofed networks and prioritising smart communications solutions will help reduce wait times and improve healthcare outcomes.
While awareness of cyber security is growing, gaps in training remain a significant barrier to preparedness.
Despite a modest rise in training on new technologies (from 5% in BT’s 2022 survey to 15% in 2024), training on both new and existing systems has fallen from 47% to 39%.
Frontline staff report a lack of regular training, with 60% calling for more. This data suggests that training is mostly a one-off initiative, rather than an ongoing effort, which exacerbates risks and vulnerabilities.
Encouragingly, 55% of the UK public rank training NHS staff in new technologies as a priority – showing that people recognise there are ways to strengthen the NHS beyond cutting-edge medical equipment.
Recommended reading
- NHS Dumfries and Galloway Hit by Cyber-attack
- NHS IT Firm May Get £6M Fine Following Ransomware Attack
- NHS London Data Breach: 400GB Leaked
There’s a growing public understanding that equipping staff with the right cyber knowledge is fundamental to improving healthcare delivery.
Commenting on this research, Professor Sultan Mahmud, director of healthcare, BT, said: “The NHS is rightly focused on saving lives, so it can be hard to stay ahead of cybersecurity threats with the landscape shifting so quickly.
“Threats targeting healthcare have grown in frequency and sophistication, endangering patient care and compromising vital services. BT logs 2,000 signals of potential cyber-attacks every second, totalling 200 million per day across sectors. With over 1.7 million employees, the NHS is the UK’s biggest employer, so empowering this workforce is vital.”
“Across the NHS, high awareness of cyber risk is overshadowed by a lack of preparedness. Moreover, significant frustrations with legacy systems are affecting care, exacerbating training gaps.
“Having worked in the NHS before joining BT, I understand many of these challenges and the importance of bringing together leading minds. Through initiatives like our Clinical Advisory Board and Vanguard Programme, BT Health is enabling collaboration between healthcare, policy, and business to drive meaningful change. A cyber-resilient NHS will be a better NHS for everyone.”





