September 29th 2026
A White Paper shaped by a parliamentary roundtable attended by Digital Care Hub is calling for practical action to strengthen cyber resilience across the NHS and the organisations, partners and suppliers it works with.
Published by Fortinet, Keeping the NHS Online: Cyber Resilience in a New Regulatory Era brings together insights from parliamentarians, NHS IT leaders, academics and cybersecurity specialists. Claire Howarth, Project and Strategic Delivery Manager at Digital Care Hub, was among those who took part.
The report looks at the growing cyber threat to health services, the shortage of cyber skills and the need for clearer governance and accountability. It warns that ageing and fragmented technology can allow a single incident to cause widespread disruption. The roundtable also explored the challenge of securing a health and care system that relies on many organisations and a wide supply chain. Participants highlighted risks linked to third-party providers, personal devices and inconsistent cyber training, which can leave organisations more exposed to phishing and scam emails.
The report is firmly focused on the NHS, rather than adult social care. However, it does reference the Government’s 2023 policy paper, A cyber resilient health and adult social care system in England. It also includes Digital Care Hub’s call for role-based, sector-specific training, with clear pathways for care providers, primary care teams, commissioners and system leaders.
These themes will feel familiar across adult social care. Providers operate in complex digital environments, rely on external technology and service partners, and share sensitive information across organisational boundaries. Resilience therefore depends on everyone understanding their responsibilities and having support they can use in practice.
What does the report recommend?
- Develop a dedicated NHS cyber workforce and training plan, covering both specialist recruitment and relevant training for the wider workforce.
- Make “secure by design” part of procurement, service redesign and the supply chains of external providers and partners.
- Improve cybersecurity oversight, assessment and accountability, with stronger benchmarking and less reliance on self-assessment alone.
Turning complex requirements into practical action
For Claire Howarth and Digital Care Hub, the priority is to give people clear, practical support rather than expecting each organisation to work through complex cyber frameworks on its own. In the report, she says:
“Government and the NHS should invest in common language, practical tools and repeatable support rather than expecting every provider to interpret complex cyber frameworks alone. Training should be role-based and sector-specific, with clear pathways for care providers, primary care teams, commissioners and system leaders.”
The report makes a clear case for action: regulation alone will not build resilience. Organisations also need investment, relevant training, secure-by-design approaches and clearer accountability. Collaboration across government, health and care, industry and cybersecurity experts will be essential to reduce risks across connected services and supply chains.
Read Keeping the NHS Online: Cyber Resilience in a New Regulatory Era.
#CyberSecurity #Fortinet #CyberResilience