Cyber security has become a strategic priority for the NHS as increasingly sophisticated threats, including AI-enabled attacks and state-sponsored actors, drive greater investment and stronger accountability across the health sector.

According to NHS leaders, the cyber risk landscape has changed significantly in recent years, leading to cyber security being elevated on the NHS risk register and becoming a central focus of future technology investment.

A Changing Threat Environment

Although the NHS has avoided a major publicly reported cyber attack over the past year, concerns remain about the vulnerability of complex healthcare systems and interconnected digital services.

The challenge is compounded by the scale of NHS technology infrastructure, with hundreds of organisations operating diverse systems and services. This creates multiple potential entry points for attackers and highlights the importance of maintaining effective cyber controls throughout supply chains.

Governance and Accountability

A key feature of the NHS response is an increased focus on organisational accountability.

NHS England is requiring trusts to strengthen cyber governance arrangements, including appointing executive-level cyber leads and increasing board oversight of cyber risks. Trust boards are being encouraged to view cyber security as a strategic risk rather than solely an IT issue.

Strong governance helps organisations to:

  • Understand and manage cyber risks.
  • Ensure appropriate investment in security controls.
  • Monitor compliance with security standards.
  • Strengthen incident response capabilities.
  • Improve organisational resilience.
Strengthening Assurance

The NHS is also introducing more rigorous assurance measures. From September, Trusts will need to provide evidence of compliance with key cyber security requirements through external assessment, replacing some previous self-certification arrangements.

Alongside this, NHS England continues to undertake cyber exercises and penetration testing to identify vulnerabilities and assess preparedness.

This reflects a growing recognition that effective cyber security requires not only technical controls but also robust governance, monitoring and assurance arrangements.

Managing Third-Party Risks

Supply chain risk remains a significant concern.

NHS organisations are being encouraged to strengthen supplier oversight and ensure appropriate security standards are maintained throughout their supply chains. While registration with the Data Security and Protection Toolkit (DSPT) continues to increase, audits have identified organisations that either fail to meet required standards or provide insufficient assurance information.

This reinforces the importance of effective third-party assurance, contract management and ongoing risk monitoring.

Lessons for All Organisations

Although these developments relate specifically to the NHS, the lessons apply across public, housing, education and not-for-profit sectors.

Organisations should consider whether they have:

  • Board-level oversight of cyber risks.
  • Clear accountability and ownership arrangements.
  • Effective incident response and business continuity plans.
  • Comprehensive asset and supplier registers.
  • Strong access controls and multifactor authentication.
  • Independent assurance over cyber security controls.

As cyber threats continue to evolve, governance, risk management and assurance arrangements must keep pace.

The Role of Internal Audit

Internal audit can provide valuable independent assurance over cyber security arrangements, helping organisations assess:

  • Cyber governance and oversight.
  • Security policies and control frameworks.
  • Third-party risk management.
  • Incident response preparedness.
  • Regulatory compliance.
  • Overall cyber resilience.

By identifying weaknesses and opportunities for improvement, assurance activity enables informed decision-making and strengthens resilience against emerging threats.

Looking Ahead

With NHS England committing significant funding towards cyber resilience and requiring stronger organisational oversight, cyber security is firmly established as a board-level governance issue.

For all organisations, the message is clear: effective cyber security depends on strong governance, robust risk management and ongoing independent assurance.

At TIAA, we support organisations across the public, health, housing, education and charity sectors through internal audit, cyber assurance, governance and risk management services. Independent assurance remains a critical tool in helping organisations protect their systems, data and stakeholders in an increasingly complex threat environment.

Learn more about TIAA’s cyber assurance and internal audit services. 

Source: HSJ Intelligence, “Cyber security finally becomes a priority for the NHS”, published 20 July 2026.