Skip to content
NHS to investigate suppliers' security posture

NHS to investigate suppliers' security posture

Computing January 26, 2026

The NHS will begin probing suppliers’ cybersecurity risk management stance following a series of cyber incidents.

There has been a steady uptick in the number of high-profile attacks targeting NHS suppliers in recent years. These include one in 2022 against Advanced Computer Software Group, which disrupted services across the country for weeks; a 2024 attack on private blood testing company Synnovis, which saw patients diverted from London hospitals; and a massive data breach at HCRG last year.

In an open letter to suppliers, Phil Huggins - CISO for Health and Care at the Department of Health and Social Care - and Mike Fell - Executive Director of National Cyber Operations at NHS England – note that “the health and care sector is not exempt” from cyber attacks, and “the scale and endurance of the threat” necessitates a “more direct, proportionate engagement with suppliers to safeguard essential services.”

This direct engagement will aim to strengthen cyber resilience across the sector. From this month, NHS England “or the relevant contracting authority” will begin reaching out to suppliers to key cyber controls, with the ability to request supporting information “where relevant.”

The letter stresses that from NHS England is “not an audit,” or a “pass or fail exercise.” However, it contains several recommendations for suppliers in how to prepare now – much of which, we would hope, is already common best practice:

Questions can be sent to [email protected] .

Designed exclusively for senior security professionals, Computing’s Security Leaders Summit returns to London on 26 th March. Register now to insights, explore new technologies and uncover real-world solutions for protecting your organisation’s data, infrastructure and reputation.

Extracted Entities

Attack Types (1)

Ransomware Groups (1)