Every day, cyber criminals are targeting NHS systems that hold some of our most sensitive data - patient records, medical histories, and critical care systems. That's why the Cyber Security Operations Centre (CSOC) runs protective monitoring across the NHS around the clock, watching for threats that could put patient care at risk.
We see the CSOC as the digital shield to national services. We protect more than 37 million NHS App users and safeguard the integrity of around 60,000 NHS 111 calls every day, ensuring trust, resilience, and uninterrupted care at national scale.
What we're watching for
Our analysts monitor NHS systems at all times for cyber-attacks, continuously analysing to identify and respond to potential threats - everything from unusual activity within nhs.net email accounts to suspicious remote access software installation on clinician's devices. We're looking for stolen credentials, large data transfers, suspicious programs or changes to our cloud environments - all potential signs that cyber criminals are trying to break in.
The variety of threats is enormous. There's a huge range of searches and hunts running across monitoring tools, feeding data from across the NHS into our team for review, supported by partnerships across government and commercial sector to provide external visibility.
Speed saves lives - and systems
When we detect something suspicious, speed is everything. Swift, decisive action is far more effective than trying to delay, which can allow attackers to spread across more of the network and compromise more systems.
I've seen this first-hand. Two NHS organisations were targeted by malicious files delivered through email links. Due to having our national security tools in place, one was able to act quickly on our alert and rapidly remove any potential threat. The second, that had yet to deploy these resources, was unable to respond in the same timeframe. The criminals had longer to try and achieve their objectives and we had to deploy our National Cyber Security Centre (NCSC) accredited forensic teams in a much more complex recovery.
Your role in cyber security
You don’t need to be a cyber security expert to make a big difference. The most effective defence comes when IT teams and frontline staff work together.
It’s important to be clear we don’t expect clinical staff to become cyber security experts. Just like you wouldn't expect to have to check the jet engines before boarding a plane, we don’t expect nurses and doctors to configure firewalls or deploy antivirus across thousands of devices on top of everything else. But that doesn’t mean cyber security isn’t part of your role.
Skilled IT teams work behind the scenes to do the heavy lifting of security, and our goal is to make cyber defences almost invisible, reducing the load on clinical staff so you can focus on patient care. But the most effective defence comes when IT teams and frontline staff work together.
There are simple, powerful ways everyone can help. Understanding why multi-factor authentication matters. Yes, it can be frustrating to enter codes or check an authenticator app, but it adds a critical layer of protection to help stop criminals using brute force to access our systems. And staying alert to fraud - if a 'colleague' suddenly emails asking you to buy gift vouchers, think twice. When everyone plays their part, we build a safer NHS together.
Supporting digital transformation
It's exciting to support NHS digitisation and the efficiency savings that it brings. We're not just securing big initiatives like the Single Patient Record - we're also ensuring CSOC has good visibility of Electronic Patient Record systems being deployed across different trusts.
We've been supporting the NHS App since it launched, working closely with security architects to build monitoring and security controls into new systems from the ground up – making security part of the design process from the outset, rather than introducing it later.
Working together
Our central monitoring can only work with local teams. While we provide oversight and specialised services at all times, we cannot know every detail about each organisation's clinical operations. We rely on strong links with local IT teams whose knowledge of their own systems helps complete the picture during investigations.
Clinical staff can support this work by highlighting the IT systems they depend on for patient care and ensuring local IT teams are aware of these dependencies. When we helped an NHS trust recover from a near-miss ransomware attack, having clinicians prioritise which systems needed to be restored first was crucial to minimise impact on patient care.
Cyber security is everyone's responsibility, not just the responsibility of IT teams. By working together, we can keep NHS systems safe while enabling the digital transformation that will improve patient care for everyone.
Author
Latest blogs
Last edited: 2 September 2026 5:16 pm