News

NHS England plans NHS cyber risk rating platform

NHS England has opened a market engagement stage, ahead of an upcoming NHS Cyber Risk Rating Platform tender, designed to support NHS organisations to “better understand their security posture” and their management of threats that could impact on operations and organisational data.

A webinar for suppliers is to take place later this month, a session that will focus on offering suppliers an insight into NHS England’s plans, intended outcomes, and timelines for the procurement process, as well as highlighting the scope of the future solution, “enabling suppliers to start preparing their offerings” ahead of the tender publication.

The platform will support NHS providers assess and support the management of risk, NHS England states, with the webinar intended to share “a deeper understanding of our evolving service outcomes and insights into how we plan to roll out the platform to new and existing users”.

The webinar is scheduled for Tuesday 26 November 3-4pm, and interested parties are encouraged to register here.

NHS cybersecurity: the wider trend

In October, we asked our audience what the biggest priority should be for health and care cyber security – board level buy-in, workforce education, funding and resources, or mandating supplier compliance? The top spot was an even split between funding and resources and mandating supplier compliance, with each option attracting 34 percent of the vote.

A HTN panel discussion with experts from the cyber security, privacy and governance field, discussed the most significant cyber security threats currently facing health and social care organisations, how organisations can prioritise their resources to address emerging threats, the outlook for the next 5-10 years, and more.

The Health Sector Cybersecurity Coordination Center (HC3) warned healthcare providers about Trinity Ransomware group and its focus on targeting patient data, with CEO at OmniIndex Simon Bain speaking out on the “growing threat” of this type of attack and its potential to hold hospital infrastructure “hostage and immobilised”.

And Cheshire and Merseyside ICS announced that it had selected Cynerio’s Healthcare Cybersecurity Platform for implementation at all 17 trusts within its footprint as part of the ICS investing in defences to better protect patient data, minimise vulnerabilities and reduce disruptions to care.

Be sure to check out HTN’s 2025 event schedule for upcoming events on cybersecurity and more, here.

More news on procurement 

The last few weeks has seen procurement news from across the NHS, including a contract notice from Digital Health and Care Wales for a Network as a Service solution worth in excess of £2 million, designed to enable the department to “strategically interconnect its physical datacenter estate, public cloud platforms, and consumer base using a resilient underlay/transit network”.

Cambridgeshire and Peterborough ICB shared a market engagement prior information notice indicating plans to deliver a digital front door to act as a single entry point for citizens and provide access to a range of products, services and partners supporting the coordination of personalised, centralised and efficient care.

And NHS England published a contract notice with an estimated total value of £13.3 million for an “experienced, multi-skilled, rapid response intervention service also known as a Tiger Teams service” to support EPR delivery across England.