Microsoft and NHS Digital sign new agreement for cybersecurity

  • 14 August 2017
Microsoft and NHS Digital sign new agreement for cybersecurity

NHS Digital has signed a new agreement with Microsoft, which includes patches for all its current Windows devices operating XP.

The custom support agreement will cover all NHS organisations in the UK with the contract running until June 2018, as part of NHS Digital’s cybersecurity efforts.

The new agreement will mean that Microsoft will provide NHS Digital with a ā€œcentralised, managed and coordinated framework for the detection of malicious cyber activity through its enterprise threat detection softwareā€, said a NHS Digital spokeswoman.

This software ā€œanalyses intelligence and aims to reduce the likelihood and impact of security breaches or malware infection across the NHSā€.

The agreement will provide patches and updates for all existing Windows devices operating with Windows XP, Windows Server 2003 and SQL 2005.

A new support deal for redundant Microsoft software was referenced in the government’s response, published 12 July, to Dame Fiona Caldicott’s review into data protection from last summer.

The government response referred to ā€œworking in partnership with Microsoft to help mitigate the immediate risks associated with unsupported softwareā€.

The report said Windows XP support will be withdrawn nationally from 2018. According to NHS Digital figuresĀ 4.7% of trusts which use Windows XP, down from 18% in the past 18 months.

It noted, ā€œcentral support for NHS Digital’s national applications operating on outdated platforms will be phased out, with Windows XP support being withdrawn from 2018ā€, the reportĀ states.

ā€œLocal organisations should be aiming to have isolated, moved away from or be actively managing any unsupported systems by April 2018.ā€

The NHS’ vulnerability to cyber-attacks was thrown into sharp relief in May’s WannaCry malware attack, where hackers exploited a known single Microsoft vulnerability. Ā The global cyber-attack hit the NHS particularly hard, with 20% of trusts affected.

Rob Shaw, the acting chief executive of NHS Digital, has defended the agency’s response to the cyber-attack and described WannaCry as the ā€œhardest dress rehearsal of what could happen if things really went wrongā€ in a cyber-attack.

Microsoft stopped providing support for Windows XP in April 2014 but according toĀ Digital Health IntelligenceĀ 2015 data on NHS infrastructure, as many as 20% of NHS organisations could still be making use of it, and around 90% are thought to run something on it somewhere in their organisation, often in clinical systems or imaging equipment.

Subscribe to our newsletter

Subscribe To Our Newsletters

3 Comments

  • A major reason Trust’s don’t move from legacy operating systems, is because host applications will break, or be unsupported by the vendor. Vendor lock in, or poorly negotiated contracts play an equal part.

  • It’s a nice idea, but the money and effort from NHS and Microsoft could equally have gone into offering practical support (and perhaps some discounting) to help Trusts ditch XP rapidly to better effect.

  • ā€œLocal organisations should be aiming to have isolated, moved away from or be actively managing any unsupported systems by April 2018.ā€
    Why bother, there’s bound to be yet another extension.

Comments are closed.

Related News

Birmingham Community Healthcare flags cyber security risk

Birmingham Community Healthcare flags cyber security risk

Birmingham Community Healthcare NHS Foundation Trust (BCHC) has flagged an exposed vulnerability that could lead to a cyber attack.Ā 
ā€˜Lessons can be learned’ from DHSC cyber progress, says PAC

ā€˜Lessons can be learned’ from DHSC cyber progress, says PAC

The Public Accounts Committee has said ā€œlessons can be learnedā€ from DHSC’s efforts to improve cyber resilience in public services.
Digital Health Coffee Time Briefing ā˜•

Digital Health Coffee Time Briefing ā˜•

Today's coffee briefing covers a new round of DSIT fellowships and the first real-time 3D "digital twin" of a hospital room in Denmark.