What recent assessment he has made of the resilience of NHS data systems to unauthorised access and attempted data breaches.
All organisations with access to National Health Service patient data and systems must use the Data Security and Protection Toolkit (DSPT) to provide annual assurance that they are practising good data security and that personal information is handled correctly. In September 2024, the National Cyber Security Centre’s Cyber Assessment Framework was implemented into the DSPT for large NHS organisations. This enables them to understand and manage their own cyber, and information governance, risks, while maintaining the high standards necessary to protect patients.National cyber teams are tackling the changing cyber risk head-on through their ambitious Cyber Improvement Programme, expanding protection and services to better protect the health and care system. In 2025/26, the Government invested £75 million across health and social care, building on the £375 million invested since 2017.NHS England runs a Cyber Security Operations Centre that can monitor over 1.8 million devices across the NHS, through Microsoft Defender for Endpoint, identifying and responding to threats, including unauthorised access, as they arise. When critical cyber vulnerabilities are identified, NHS England issues a High Severity Alert to warn NHS organisations.NHS England routinely conducts highly specialised ‘Red Teaming’ and Penetration Testing of their data systems to assess their cyber security and resilience. NHS England and the Department have developed a strategy and programme of cyber exercising to test and improve resilience and capacity across the system and regularly exercise our cyber incident response/business continuity capabilities at a local and national level. We are using lessons learned from both recent incidents and exercises to improve processes and policy around our response to cyber incidents. When incidents do occur, NHS England provides a suite of support to help organisations recover quickly, but safely. This includes specialist, on the ground, certified incident response services free of charge to NHS organisations who have been severely impacted by Cyber Incidents as well as technical and operational support to contain, investigate, and remediate incidents. The National Cyber Security Centre has published guidance for individuals to help them protect against the impact of data breaches.