The cyber welfare of healthcare employees
Watch the TSC webinar on the cyber welfare of healthcare employees, covering the human impact of cyber attacks, duty of care, board-to-ward engagement, lessons from WannaCry and Synnovis, and supply chain and AI risks.
When a cyber attack hits, who protects your people?
Cyber attacks on healthcare are often measured in financial, operational and reputational terms. But behind every breach are people: the employees trying to keep services running, the patients waiting for care, and the individuals left dealing with stress, uncertainty and potential harm. This TSC webinar explores the human side of healthcare cyber security and the duty of care organisations have to support employees before, during and after an attack.
Chaired by former NHS chief executive John Green, with NHS operational executive Helen Beck and health and social care consultant Phil Gady, the panel draws on first-hand experience of WannaCry, the Synnovis ransomware attack and the personal impact of cyber scams on healthcare workers. The discussion makes the case for cyber security as a mindset, not a tick-box exercise, and explains why secure behaviour must be supported from board to ward.
The webinar covers behavioural training, phishing simulations, human factors, leadership ownership, supply chain risk, password security, AI, deepfakes and the need to make cyber security relevant to both employees' personal lives and the patients they support. It is essential viewing for healthcare leaders, information governance teams, security awareness managers and anyone responsible for protecting people as well as systems.
In this webinar, you'll discover:
Turn healthcare cyber welfare into practical security training
This webinar explores why healthcare employees face unique cyber pressures, from high-stress environments to sensitive patient data and constant operational demands. TSC's security awareness training and eLearning modules help your people recognise risks, respond with confidence and build safer everyday behaviours.
View the full webinar transcript
Introduction
Thank you for joining us. My name is Bebe Lees, head of communications at The Security Company. Today's session is very much about the people in your workplace, and about protecting those people should they ever encounter a data breach or a cyber attack. I've been asked to cover the language and terminology we use too. Rather than a formal agenda, we want this to be a discussion, so I'm joined by a panel from senior healthcare backgrounds, chaired by John Green, with Helen Beck and Phil Gady. Please share your questions in the chat as we go.
We could cover several themes: the human impact of cyber crime; cyber security as a mindset; the patient consequences of a scam or breach; and board-to-ward thinking, how engaged leadership is and how those messages reach people on the wards. The poll showed the strongest interest in cyber security as a mindset, so that became our focus.
Meet the panel
John Green: I'm a former NHS chief executive, including of an acute foundation trust in Norfolk, and for the last few years I've done consultancy and advisory work across health and social care.
Helen Beck: I'm an operational executive in the NHS with a 40-year career that started in nursing, and I now take on interim and consultancy roles.
Phil Gady: I'm a management consultant in health and social care, having previously worked with both Helen and John, including as an EPRR manager and a general manager in pathology.
WannaCry: a first-hand account
Helen: Many of you will remember WannaCry, the global attack that hit Microsoft users and spread widely across the NHS in May 2017. It struck the organisation I was chief operating officer of on a Friday afternoon. We thought we were fairly astute, with an electronic patient record and a proactive IT department, and software did alert us so we could shut our systems down and limit the impact. But the impact was still significant. IT staff barely went home all weekend, the whole organisation went into business continuity, our A&E reverted to paper, and tests and investigations were ordered on paper. Even being relatively cyber-aware, we saw a major impact across every part of the organisation and on patient care.
John: I remember it well, I was in my first month as a chief executive. We were at the other end of the spectrum, what we called the "digital desert", one of the least technically advanced trusts, around 90% paper. In a way that protected us; we simply carried on. It shows how exposed we become as we grow more digitally reliant.
The Synnovis attack, and state versus criminal threats
Phil: I'd point to the Synnovis ransomware attack earlier this year, when a Russian group got in, shared a large volume of data on their dark-web site and demanded a ransom. Synnovis is a partnership involving SYNLAB, Guy's and St Thomas' and King's College Hospitals, so it hit several NHS foundation trusts and primary care services across south-east London, Southwark, Lambeth, Bexley, Greenwich, Lewisham and Bromley. WannaCry was effectively a state threat; Synnovis is a useful example of a criminal one. From our perspective it doesn't matter whether it's state or criminal, it's the outcomes you're dealing with that count, though understanding the methodology helps us defend against it.
The human cost: a personal story
John: My story leans into the human effect. As well as advisory work, I coach people, and I got a very panicked call from a nurse in the east of England who believed she'd shared her bank details and fallen for a scam. She'd done all the right things, contacted her bank and the relevant government cyber sites, but the part she had nowhere to take was the worry: had someone taken all her data, emptied her account? She didn't know. She ended up not sleeping and off work for two or three days from the stress. As it turned out she hadn't been compromised, but we often forget that all our staff are open to this on an individual level. As part of our duty of care, there's a real health-and-wellbeing element to getting this right.
Cyber security as a mindset, not a tick-box
Helen: For me this usually sits in mandatory training, and people's hearts sink, I've done more mandatory training than I can shake a stick at. There's a temptation to play the video while doing something more useful and tick the box at the end. The challenge is moving away from "another piece of mandatory training" to genuinely changing the mindset, by asking what's in it for the individual. Is there personal learning they can take into their own life too, so it's a win-win, rather than just protecting the organisation and doing the minimum for internal audit?
John: Exactly. The problem with once-a-year training is the "done it, don't have to think about it again" mentality. We need it to become part of day-to-day work, something people refer back to, like patient safety, rather than a chore done in front of the evening TV.
Where cyber sits on the National Security Risk Assessment
Phil: Let me add some persuasion. The National Security Risk Assessment is a collection of 89 risks the UK deems a threat or natural hazard. Cyber attacks on the health and social care system, telecommunications and transport are all in there, key national infrastructure. The NHS has a huge and increasingly critical ICT footprint, from point-of-care devices and defibrillators to electronic patient records, all of which make care easier but raise the threat level if breached. Cyber attack is judged to have a likelihood of four, a 5 to 25% chance. If I were betting, a one-in-four horse is worth a flutter, so turn that around and it should be quite scary. If we don't change our mindset, we could inadvertently open the door by clicking something we shouldn't.
Behavioural training and phishing simulations
John: There's a good debate in the chat about how we change the mindset, and behavioural training is how we'd recognise doing it. One idea I love, giving a £50 voucher to the first people who spot all ten of a set of phishing emails, taps into people's natural competitiveness. E-learning is great for proving to regulators like the CQC that everyone's been trained, but does it actually do the job? That's the tension.
BB: Tick-box annual training doesn't change behaviour, though e-learning does build knowledge. The real gap is between what people know and what they do. People learn from stories and experiences, so the more we share real examples, including the scams that arrive on our own phones and personal email, the more transferable it becomes to the workplace. Phishing simulations have validity, a safe environment to spot and report, though there are downsides people raised in the chat too.
Human factors and the right environment
Helen: Human factors matter, and they link to how seriously leadership takes this, because a lot comes down to the environment. I remember theatres where everyone logged on in the morning with a single generic login because it was quick. People later realised the risk and locked things down, but then found they couldn't function, or the first person in still logged in and left it. With electronic patient records, clinicians move constantly between devices; if someone has to log in 15 times during one patient encounter, they'll just leave it open. So there's a real question about whether the senior team invests in enough equipment and infrastructure to let people be secure and do their job. Theatres talk about human factors for patient safety, but rarely for cyber security and organisational safety, and there's a real opportunity there.
John: That brings it back to leadership understanding the consequences, and that it's not just about training but about providing the right equipment and environment. I'm minded of Lord Darzi's report: the more we invest in technology, the more we must invest in supporting it, and leaders must be aware of their responsibilities, rather than cutting corners.
Leadership, board ownership and shared responsibility
Helen: There's an organisational message in whether the board has a chief information officer or chief clinical information officer, a board-level appointment. We have a nurse and a medic around the board table for good reason; as digital becomes central to care, that marker in the sand matters. You cannot deliver modern patient care unless your organisation is digitally enabled, and the more enabled you are, the more can go wrong.
Helen: I'm not convinced it's purely a resourcing issue, though. Most digitally enabled organisations have a CIO, and in healthcare a CCIO. The question is whether you've taken that role seriously enough to give them a seat at the board, a voice, and whether you actually listen, rather than just having the person in post.
John: And we're very good at saying "that's someone's role" and leaving it there. We wouldn't say spending money wisely sits only with finance, it's everyone's responsibility because we all work for the taxpayer. Security is the same: one person leads, but everyone has a part to play, and shifting that is part of the mindset change.
BB: One client, a public-sector organisation, made the biggest impact at a town hall when someone asked the chief executive what our biggest risk was, and he said, without hesitation, "there's only one and it's our cyber risk." Acknowledging it publicly made a huge difference. The key is leaders who inspire and motivate everyone else around this agenda.
John: Anecdotes make it real. In the recent London attack, the patient consequences, especially for GP practices that couldn't access results, were profound. A maladministered drug or infected blood would be a national scandal; the consequences of a cyber attack can be just as dangerous, but we haven't yet connected it to patient harm in the same way. As we continue to be breached, and nothing is 100% secure, there will be patient harms, and working that into the narrative matters.
Supply chain risk
John: Supply chain is hugely important, because our greatest vulnerabilities often aren't what we control but what comes into us. Ensuring your whole supply chain is as secure as you are is vital, and really difficult to do.
Phil: Practice isn't a dirty word. Let's practise operating in reversionary mode, so if you're hit, as Synnovis was, you minimise the impact on patients, infrastructure and staff because you've rehearsed it. It's not popular and it's a bit nauseous to go through, but if you've practised it, it becomes muscle memory and you keep services going with reduced impact.
Passwords and personal security
Phil: As individuals, the whole is greater than the sum of its parts. The National Cyber Security Centre has great tips for staying secure and for memorable passwords. John, Helen and I are of an age where we write passwords down, hopefully not on a sticky note under the keyboard. Some keep them on their phone, but if Wi-Fi is on, a phone can be bluejacked or bluebugged and passwords found that way. Whatever system you use, there are vulnerabilities, so it's worth everyone reading the NCSC site.
BB: Please don't write them down, and if you store them on a device, make sure that device is secure. The NCSC rule of thumb, which we advocate, is simple: three random words that aren't linked, then swap a couple of characters for numbers or symbols, and never tell anyone your three words. Something like a colour, a place and an animal gives you a long, strong password you can keep in your head.
AI, deepfakes and new risks
BB: AI is a whole topic of its own. People are becoming familiar with deepfake technology, and senior leaders are particularly exposed because there's video and audio of them publicly available. It takes very little open-source media to fake a voice or face, and someone receiving a message from a "senior leader" who isn't real may feel they must act. So your workforce understanding how technology is evolving, and how criminals use it, is critical, and the more we can expose people to it safely, the better.
John: For those less familiar with AI, two organisations I work with have brought in policies specifically around open AI tools, because of the inability to know where the data is pulled from and what it connects to. In effect it can create unsecured supply lines into your organisation through something that looks helpful and clever. It's the next in a long line of challenges.
Closing thoughts
Helen: The AI conversation is especially relevant because adoption is often efficiency- and finance-driven, sometimes by losing headcount, and organisations aren't always sighted on the risk. I recently joined an organisation after they'd gone live with an AI solution and asked some challenging questions that caused us to step back until we had good answers. That rush for quick financial benefit is the space to watch at board and senior level.
Phil: We've talked about financial, institutional and reputational risk, but let's not forget the impact on individuals, and making sure we have wraparound support if someone is a victim. At the end of the day, humans are at the centre of delivery in the NHS, and while we are the weak link, we can also be the strongest link in the chain with the right support.
John: We've recognised the risk, but unless we act on it, starting with ownership at senior level and filtering through the whole organisation, nothing changes. It's more of a cultural revolution than a tick-box exercise. Understanding how behaviour and behavioural learning work, and making it real for people, whether in their own lives or for the patients in front of them, are the essential ingredients. It's like painting the Forth Bridge: we'll never be finished, so it needs resilience and perseverance.
BB: Thank you to John, Helen and Phil, and to everyone who joined and contributed. We've started painting the bridge, but it's a long journey, so the more we talk and share, the better. We'll send a follow-up with a summary of the key points and signposting to further resources.
Healthcare cyber welfare FAQ
What is cyber welfare in healthcare?
Cyber welfare in healthcare means recognising the human impact of cyber attacks on employees as well as systems. It includes supporting staff who experience scams, breaches or security incidents, reducing stress and blame, and helping people build the confidence to report risks quickly.
Why is cyber security a healthcare duty of care issue?
Cyber security is a duty of care issue because attacks can affect both staff wellbeing and patient safety. When systems fail, results are delayed, services revert to manual processes and employees face pressure, uncertainty and potential distress. Healthcare organisations need to protect their people as well as their data and infrastructure.
How can healthcare organisations build a stronger cyber security mindset?
Healthcare organisations can build a stronger cyber security mindset by moving beyond annual tick-box training, using real stories, practising incident response, running phishing simulations, supporting managers to lead by example and making secure behaviours relevant to everyday clinical and operational work.