Skip to content

Board and executive assurance: cyber security risk (NHSE, 10 June 2026)

Summary

The Government’s 10 Year Health Plan is transforming how services are delivered through greater digitisation. However, increased use of digital tools also brings new and enhanced risks that need to be managed. 

In a letter to providers, NHS England and the Department of Health and Social Care ask boards and executives to assure themselves that cybersecurity risks are being managed effectively, with clear, sustained programmes for improvement..

Content

The Data Security and Protection Toolkit (DSPT) is the standard that all frontline NHS organisations are expected to comply with and is aligned to the National Cyber Security Centre’s Cyber Assessment Framework (CAF).

The DSPT details a range of outcomes, covering the following 5 objectives:

  • managing cyber risk
  • protecting against cyber-attack and data breaches
  • detecting cyber security events
  • minimising the impact of incidents
  • using and sharing information appropriately.
Board and executive assurance: cyber security risk (NHSE, 10 June 2026) https://www.england.nhs.uk/long-read/board-and-executive-assurance-cyber-security-risk/

User Feedback

Recommended Comments

There are no comments to display.

Create an account or sign in to comment

Registered address: Patient Safety Learning, China Works SB203, 100 Black Prince Road Vauxhall, London, SE1 7SJ

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.