Written evidence submitted by Suresh Renukappa1, Chandrashekar Subbarao1, Subashini Suresh1, Prashant Pillai1, Panagiotis Georgakis1, Kieran Fernando2 and Chandrashekar Rangaswamy3, 1Faculty of Science and Engineering, University of Wolverhampton, U.K., 2Consultant Physician and Associate Medical Director, Midlands Partnership NHS Foundation Trust, St. George’s Hospital, U.K, and 3Consultant Anaesthesia, The Royal Wolverhampton NHS Trust, Wolverhampton, U.K

Executive Summary

 

Written evidence

  1. Evidence is provided by conducting a survey of available material in public domain on cyber security attacks on healthcare systems. The WannaCry ransomware attack that affected many NHS service providers in 2017 was perhaps the most significant attack in the UK. There have been many more reported like the NHS 111 Service outage (2022), Bart ransomware attack, and GPSoC breach (2019) to name a few. Increasingly, the healthcare sector has shown susceptibility to cyber-attacks. These are recognised as one of the most significant societal and organisational threats, based on likelihood and impact (WEF, 2019).

 

  1. Cybercrime very quickly adapts to changing external conditions. The world pandemic condition due to COVID-19 was used as an opportunity by cyber criminals and challenged the security of the healthcare system. The threats get pronounced because during times of such stress, the focus is more on actual delivery of healthcare to save lives than worry about security of the healthcare systems. The NHS ecosystem is extremely complex, and the healthcare supply chain is also very heterogenous and loosely connected. This increases the threat vectors. Digital maturity is critical to reduce risks, especially when the ecosystem complexity is a big challenge.

 

  1. As the landscape is huge and the data is residing in multiple places, it increases the attack vectors. It is important to limit the number of attack vectors, i.e., there should be as few places as possible where malicious code can be introduced into the system. According to Ghafur, et al., (2019), there exists no catalogue to systematically list all software and hardware deployed within the large digital landscape of NHS. This can lead to a severe lack of awareness of vulnerabilities.

 

  1. Multidisciplinary team working within healthcare is expanding, now with different electronic e-messaging systems to collaborate/seek expert and wider opinion for clinical management of complex cases – this may be linking in with other hospitals in the UK and/or abroad. With changes in UK commissioning arrangements for healthcare services and the implementation if ICBs (integrated care boards), there will be increased drive for collaborative work with other NHS organisations; and also public sector and sometimes private sector organisations, which will require secure communication channels to ensure safe transfer of and access to patient records. For cyber criminals, this cross-collaboration will be seen as an area of vulnerability that can potentially be exploited.

 

  1. Ghafur, et al., (2019) also point out lack of clearly defined responsibilities and security preparedness in the face of a cyberattack. This is because of the NHS’s complex structure. This also makes it very difficult to assess the NHS’s resilience and the potential effect an event would have on the health and social care system.

 

  1. Some of the most common cyber security threats come through phishing attacks, ransomware attacks, denial of service attacks, and data breaches. Of these, Ransomware is the most common and has ‘matured’ to such an extent that there are RaaS – Ransomware-as-a-service, which will allow even novice cyber criminals to get into the cyber-crime fray easily.

 

  1. According to Renukappa, et al., (2022), most of existing healthcare systems are centralised that are vulnerable to single point of failures and information leakage due to the rise of cybersecurity attacks. The leakage of patients’ personal and critical information can lead to serious consequences.

 

  1. The healthcare industry has generally been slow to catch up with the industry with regard to cyber security. This lag has caused the healthcare industry to be a prime target for cyberattacks leading to data thefts and disruption of services. The healthcare sector  therefore, also has to follow other industries in clearly defining cyber security policies and duties. Only 4–7% of a healthcare systems’ budget is invested in their cyber security, compared to about 15% for other sectors such as the financial industry (Morgan, 2020).

 

  1. Post WannaCry attack in 2017, the UK government had published a very detailed ‘Lessons learned’ along with a number of recommendations. These recommendations span across the organisational structure, processes to manage incidents, people, and technology. Many things must be done in synergy for effective protection against cyber-attacks. This cyber security imperative is addressed through both cybersecurity regulation and policy, and voluntary practices implemented across the healthcare ecosystem as per the Health Industry Cybersecurity  Recommendations for Government Policy and Programs (2023). The starting point is the defining of the national policy. This has gained speed and traction now with the publishing of the general Government Cyber Security Strategy: 2022 to 2030 followed by the Cyber Security Strategy for Health and Adult Social Care in March 2023.

 

  1. According to Giansanti (2021), cyber security in the healthcare is applied to application security, information security, operational security, network security, disaster recovery, resilience and end-user training which are tuned and specialised for the health-care sector. The healthcare specific policy of UK closely follows this and is very comprehensive and rightly identifies ‘five complementary pillars for a joint approach to building cyber resilience, uniting health and adult social care.

 

  1. The National Cyber Security Centre (NCSC) has published the Cyber Essentials Plus standard which should be adopted by all the healthcare organisations. NCSC also has a Cyber Assessment Framework (CAF) which is the standard for organisations in the NHS ecosystem. The CAF will help in tracking progress in working towards sector-wide cyber resilience. Also, such a common framework will enable organisations understand what is expected of them and will also provide a standardised and consistent reporting on risk levels. Also, specifically for data security, there are data security standards recommended by the National Data Guardian (NDG). This should become the basis for all healthcare organisations to reduce the vulnerability to attacks.

 

  1. Governance is at the centre of IT solutions within the NHS.  In this respect, NHS organisations have appointed Chief Information Officers (CIOs) who are responsible for driving digital strategies for the NHS Trust, enhancing efficiency, quality and safety of digital communication and solutions.

 

  1. Enumerating the different challenges in adopting digital healthcare strategies, Subbarao, et al., (2022), emphasise that ensuring cyber security is a big challenge. All eco-system players have to be sensitised to this with clear policy guidelines. The readiness to adopt digital health strategies have to necessarily take into consideration cyber-security too.

 

  1. Constant technology upgradations, not using very old software, following basic cyber hygiene like using good passwords, multi-factor authentication, not sharing passwords and a general organisational and systems-usage culture that is tuned to data security are key to reducing vulnerabilities to cyber-attacks. According to Cyber Security Breaches Survey (2023), the most common cyber threats are relatively unsophisticated. Therefore, government guidance advises businesses and organisations to protect themselves by adopting a set of “cyber hygiene” measures.

 

  1. As people are central to any security, all users working with the healthcare provider systems must be fully trained from a security perspective. This training will need to be constantly upgraded and delivered at frequent intervals. There must be a strong people centric approach to cyber defence as most malware makes its way through injudicious use of the systems by individuals.

 

  1. With the advent of AI and its application in almost every sphere, AI-based cyberattacks and deepfakes poses a new level of risk that healthcare organisations have to deal with- Giannopoulos (2023). Organisations and their technology partners must be prepared to confront this threat. This threat from AI is not yet fully understood as AI is itself nascent. Even the Policy paper on cyber security has very little reference to AI powered threats or how AI could be used both to mitigate the threat and also to engineer a threat.

7 November 2023