October 9th 2026
“The pain you go through is so, so difficult. It took us completely by surprise. When you are the owner of a small care business, a cyber attack feels personal – it can change your whole life in a moment.”
Grace Stinton, Owner and Registered Manager, Amber Rose Healthcare
As part of Digital Care In Focus: Cyber Month, we met with Grace Stinton to hear what happened when Amber Rose Healthcare was hit by a cyber-attack – and what the experience taught her about protecting a small care organisation.
This was about more than a compromised inbox. It was about keeping a care service running while dealing with uncertainty, pressure and difficult decisions – and discovering just how important it is to be prepared when the unexpected happens.
It started with a phone call
It was a bank holiday Friday and Grace was out on a day trip with a person drawing on care and support when her phone rang. A manager from another care provider had received an unusual email from Amber Rose Healthcare’s main “info” account. It appeared to have been sent by Grace, but Grace knew it hadn’t.
That simple phone call was the first indication that something was seriously wrong.
Grace quickly realised that the email account had been compromised. She immediately arranged for the account password to be changed and contacted her IT supplier and cyber security provider.
What they discovered was much more serious than one suspicious email. The attacker had been inside the account for almost a week before being discovered. During that time, more than 4,000 malicious emails had been sent in batches from the compromised mailbox.
The precise route into the account could not be established, although the investigation identified a weakness associated with the email setup and possible interaction with a link.
When one inbox becomes a whole-business problem
Amber Rose Healthcare is a small provider of supported living and outreach support for people with mental health needs, learning disabilities and autism across Somerset and Devon.
The organisation was established in 2024 and, from the beginning, had taken data protection and cyber security seriously. It had completed the Data Security and Protection Toolkit (DSPT), put data protection processes in place, attended cyber tabletop exercises with the Somerset Registered Care Providers Association, and used separate email accounts for different functions.
But its main “info” mailbox was a critical part of the business. It was used to communicate with commissioners, regulators, the NHS, the Home Office, staff, people drawing on care and support, families and other providers.
Amber Rose had to work out what had happened, understand what information may have been accessed, identify who had received malicious emails and continue running its care service at the same time.
And, initially, Grace didn’t have all the answers.
It was all consuming
The attack consumed the bank holiday weekend and beyond and created enormous anxiety for Grace, and her team.
For a small provider, like Amber Rose, there is often no large IT department or dedicated incident response team to take over when something goes wrong. The people dealing with the crisis are often the same people responsible for continuing to run the service.
That made the human impact of the attack just as significant as the technical one.
“When you are the owner of a small care business, a cyber attack feels personal – it can change your whole life in a moment.”
Grace’s experience is a reminder that cyber resilience is ultimately about people. A cyber incident can affect not only systems and information, but the people drawing on care, families, staff and the leaders responsible for keeping services running.
Responding quickly – and keeping people informed
The immediate priority was containment.
The compromised account was secured and ultimately disabled. The cyber security team revoked access, investigated the attacker’s activity and worked with Amber Rose throughout the weekend.
The organisation also began notifying the relevant organisations, including CQC, commissioners in Devon and Somerset, the ICO and the police (it is easy to forget that this is a crime!). People drawing on care and support, families and other recipients of the fraudulent emails were also contacted where appropriate.
For Grace, communication was an important part of the response.
There can be a temptation during an incident to wait until every detail is known before saying anything. But Amber Rose chose to be open about what had happened, what was still being investigated and what was being done to contain the attack.
For Amber Rose, this wasn’t simply about compliance, it was about trust.
What changed after the attack?
Once the immediate crisis was over, Amber Rose began looking at what it could do differently.
One of the biggest lessons was the need for access to cyber expertise outside normal working hours.
The organisation reviewed how its IT and cyber security support worked together and moved towards a more joined-up approach. Having someone to call at night, at weekends and on bank holidays became a priority.
Amber Rose also took its existing business continuity arrangements and turned them into a more practical incident response plan.
The plan now sets out:
- who to contact;
- what to do first;
- how to escalate an incident;
- what happens if Grace is unavailable; and
- how essential communications can continue if an account is compromised.
The organisation is continuing to use the DSPT as a framework for improvement and cyber culture, rather than treating it as something to complete once and file away.
Four things Amber Rose wants other providers to know
1. Cyber Support
Don’t wait until something goes wrong to find out who provides your cyber support.
Check your IT contract. Ensure it covers cyber support and know what happens outside office hours. Make sure you have a number you can call at 2am – and keep it somewhere that isn’t dependent on your main email account.
“They want to take you when you are off guard – Christmas, Easter, bank holidays, weekends. Any time when they may go undiscovered for longer.”
2. Complete your DSPT
Complete your DSPT, but don’t then forget about it – embed it in your culture and practices. Share the concepts, policies and ways of working with your staff. And embed a robust cyber culture amongst your teams.
You don’t need everyone in your organisation to be a cyber security expert. But everyone should know the basics, such as how to spot something suspicious and feel confident about reporting it.
3. Business Continuity Plan
Have a robust business continuity plan that covers cyber-attacks. But remember that a business continuity plan is only useful if people know what to do.
Make it practical. Make sure it is accessible. Include the contacts, actions and escalation routes people will need. And test it – like you would a fire drill.
Your Local Support Organisation can also help with DSPT completion, embedding good practice and relevant cyber security training.
4. Share your learning
It can be hard to admit when things have gone wrong, but be open about what happened and what you would do differently. Sharing your experience helps other providers learn from it, strengthening their own cyber resilience, helping them to be better prepared, and ultimately, keeping people safe.
The bigger lesson
Amber Rose’s experience shows that cyber-attacks are not just a problem for large organisations. Even small providers with the DSPT completed, data protection policies in place and IT support can still be caught out.
What matters is what happens next. For Amber Rose, the attack reinforced the importance of acting quickly, communicating openly and having practical support and clear plans in place before they are needed.
Most importantly, it showed that cyber resilience isn’t simply about technology. It’s about people, preparation and being ready to respond when things go wrong.
See the links below to useful Digital Care Hub cyber resilience resources, to help keep you organisation cyber secure:
- Cyber incident communications checklist
- Business continuity plan resources
- Free data protection and cyber e-learning for staff, and digital/data leads
- The Cyber Game – a fun and interactive game to play with staff to help keep cyber on their agenda
- For free, tailored support with your data protection and cyber security arrangements, please contact your Local Support Organisation