University Hospitals of Liverpool Group has noted “significant progress on cyber security” and the data security and protection toolkit (DSPT).
The board of directors this month highlighted strong assurance in cyber security management, information risk oversight, information incident management, data quality improvement, clinical coding assurance, and the ongoing digitisation of records. 38 of 41 outcomes were recorded as “standards met” at LUHFT in the DSPT cyber assessment framework submitted last year, it states. An internal audit for DSPT provided an improvement plan for supply chain, identification verification authentication and authorisation, and vulnerability management, with seven of 11 recommendations now implemented.
LUHFT established a risk management forum, including information risk, the group notes, said to help to identify and manage risk to personal data. A digital risk assurance group now meets every month to incorporate all trust site management, discussing and grading risks, and assigning risk scores and mitigations. An information governance group is responsible for overseeing all information governance and cyber security activities, meeting monthly and chaired by the trust’s CDIO/SIRO. A digital oversight committee is responsible for overview and scrutiny of all cyber and information governance risks, and meets on a monthly basis.
From 1 April 2025 to 31 March 2026, digital services identified a total of 37 new risks, according to the group, representing a 31.5 percent decrease on the previous year. 29 of these were labelled “moderate”; seven were “serious”; and one was “significant”. 16 cyber security related incidents were recorded during the 2025/26 reporting period, decreasing from 19 in the previous year, with none requiring external reporting to the information commissioners office. “Following incidents, the Cyber Security Team discuss the impact of these events and possible gaps in controls that could allow a reoccurrence,” the group states. “Opportunities for improvement are discussed at appropriate forums and could result in change in configurations, stricter security/ approval mechanisms, risk logging or where appropriate, all user, communications are issued regarding best practice and reminding staff of their obligation under Trust policy.”
Various tools and services are in use to support the trust’s cyber security defences, the group explains, such as a privileged access management solution, an email gateway solution, Office 365 Security Suite, a vulnerability monitoring service, and NCSC platforms. BitSight is being used to monitor the organisation’s cyber security posture over time.
The procurement process to meet the renewed requirements of the DSPT has been successful, it highlights, but safe implementation and monitoring of solutions requires significant resource from trust teams. The number of malicious emails has continued to increase, and the bulk of these are blocked by trust security solutions, including 250,000 emails per month.
Increased cross-group working is observed across LUHFT and Liverpool Women’s Hospital, the board continues, with consideration for where information sharing helps both organisations maintain a secure environment. Also noted are annual penetration tests, and a “well-established” forum for central review of cyber security. Following a focus on transitioning to digital forms, improving electronic clinical record keeping, and working on real-time scanning for paper-based records, plans are in development for the coming two years, that will reportedly see the trust transform to “digital first intelligent information”, hoped to promote strong governance and timely access to data.
Wider trend: Cyber
For a recent HTN Now webinar, we were joined by digital leaders from across the health sector for a deep dive into cyber security in healthcare, exploring strategic challenges, preparedness, recovery, and how best to embed resilience into clinical, technical, and governance frameworks. Making up our panel were Nasser Arif, cyber security manager at London North West University Healthcare NHS Trust and Hillingdon Hospitals NHS Foundation Trust; Lee Rickles, CIO at Humber Teaching NHS Foundation Trust; and Andy Wilcox, Imprivata’s senior product marketing manager.
Lincolnshire Community and Hospitals Group board recently discussed its cyber landscape, increased operational complexity, plans for cyber resilience, and a pilot for managed security operations. The group acknowledges operating in an increasingly complex cyber security environment, noting progress in strengthening cyber resilience, including work following the transition from AGEM CSU to an internally hosted digital service model, with investment in secure infrastructure and improvements made to backup capability. The group’s expanded role for the wider Lincolnshire system has led to increased operational complexity, with a number of legacy systems and interconnected services, and “particular complexity” in acute settings, it notes.
The government of Alberta has employed Claude AI to locate and fix cyber security vulnerabilities across government systems, said to assess 466 million lines of code, implement fixes, and run continuous security review. Claude Code’s Opus and Sonnet models have been used to analyse systems in all 27 provincial ministries, covering 1,280 applications and 3,400 code repositories, most of which the government notes “has never undergone a systematic security review”, and with accumulated technical debt estimated to cost into the billions of dollars.



