FOI finds 1 in 4 NHS trusts have no staff with cyber qualifications

  • 19 December 2018
FOI finds 1 in 4 NHS trusts have no staff with cyber qualifications

Nearly a quarter of NHS trusts that responded to an FOI request have no employees with data security qualifications, with trusts employing just one qualified security professional per 2,582 employees on average.

NHS organisations were approached by cyber security firm Redscan with a Freedom of Information (FOI) request which quizzed them on their cyber security training and expenditure.

Trusts were asked how many members of staff held professional data security or cyber security qualifications, as well as the number of employees to had completed security training over the last 12 months.

Twenty-four of the 108 trusts that responded reported they had no employees with security qualifications, despite some employing as many as 16,000 full and part-time personnel.

It also found that only 12% of trusts had met the NHS Digital’s mandatory information governance (IG) training requirements, which state that 95% of all staff must pass IG training every 12 months.

A quarter had trained less than 80% of their staff, while some trusts reported that less than 50% of employees had been trained.

Redscan pointed out that NHS employees tend to be trained at different intervals throughout the year, and trusts do not have to maintain their 95% target for the full year. However, it added that the fact trusts were falling short of training targets at certain points in the year could still be ā€œcause for concernā€.

Mark Nicholls, Redscan director of cyber security, said the findings ā€œshine a light on the cyber security failings of the NHS, which is struggling to implement a cohesive security strategy under difficult circumstances.ā€

ā€œIndividual trusts are lacking in-house cyber security talent and many are falling short of training targets,ā€ Nicholls added.

ā€œThe cyber security skills gap continues to grow and it’s incredibly hard for organisations across all sectors to find enough people with the right knowledge and experience. It’s even tougher for the NHS, which must compete with the private sector’s bumper wages.ā€

Redscan’s FOI also asked trusts how much money they had spent on data security training during the last 12 months, including any GDPR-related training.

Trusts spent an average of Ā£5,356 on data security training, although Redscan pointed out that a ā€œsignificant proportionā€ of organisations provided in-house training at no cost, or only used free NHS Digital training tools.

Spending on training varied significantly between trusts – ranging from Ā£238 to Ā£78,000 – with the size of each trust not always proving a determining factor. For example, of mid-sized trusts with 3000-4000 employees, training expenditure ranged from Ā£500 to Ā£33,000.

Nicholls said: ā€œInvestment in security and data protection training is patchy at best. The extent of discrepancies is alarming, as some NHS organisations are far better resourced, funded and trained than others.ā€

ā€œWannaCry severely disrupted critical healthcare services across the country in 2017, costing the NHS an estimated Ā£92m. The Government has subsequently increased funding for cyber security in the NHS by Ā£150m, while introducing a number of new security policies.

ā€œThere are certainly green shoots of progress, but this doesn’t mask the fact that the NHS is under tremendous financial pressure, is struggling to recruit the skills it needs and must continue to refine its cyber security strategy across the UK.ā€

Subscribe to our newsletter

Subscribe To Our Newsletters

Related News

Birmingham Community Healthcare flags cyber security risk

Birmingham Community Healthcare flags cyber security risk

Birmingham Community Healthcare NHS Foundation Trust (BCHC) has flagged an exposed vulnerability that could lead to a cyber attack.Ā 
ā€˜Lessons can be learned’ from DHSC cyber progress, says PAC

ā€˜Lessons can be learned’ from DHSC cyber progress, says PAC

The Public Accounts Committee has said ā€œlessons can be learnedā€ from DHSC’s efforts to improve cyber resilience in public services.
Digital Health Coffee Time Briefing ā˜•

Digital Health Coffee Time Briefing ā˜•

Today's coffee briefing covers a new round of DSIT fellowships and the first real-time 3D "digital twin" of a hospital room in Denmark.