← Insights & Resources

A quarter-century of NHS cyber, data & digital change

Two adjacent journeys: how governance and cyber regulation have evolved, and how local digital estates have (and often haven't) kept pace from 2000 to 2025.

Before 2000 — the set-up

In the 1990s, the NHS laid the foundations for modern information governance: the Caldicott report and early confidentiality principles, paper-heavy records, and centrally driven programmes for data standards. Cyber security as we now know it barely existed — but the idea that every organisation is a guardian of patient data was already being formed.

Cyber security, data & governance

Regulation · Accountability · Assurance

2000–2003 — Early information governance era

Caldicott principles and early Information Governance (IG) standards embed the idea that each NHS organisation is responsible for protecting patient information. Boards begin to recognise data as a risk in its own right.

2004–2009 — Trusts, Foundation Trusts and local accountability

Acute and community organisations move toward Trust and Foundation Trust status, with greater autonomy. Accountability for data and cyber risk increasingly sits with local boards, SIROs and Caldicott Guardians rather than a purely central model.

2010–2013 — Maturing IG Toolkit and formal risk roles

The IG Toolkit becomes the primary way NHS organisations self-assess compliance. Senior Information Risk Owner (SIRO) and Caldicott Guardian responsibilities are mainstreamed, but focus is still heavily on paper and data protection rather than technical cyber resilience.

2014–2016 — Growing cyber threat awareness

High-profile breaches and CareCERT guidance start to shift thinking from 'information governance' to 'cyber security'. Organisations are pushed to improve incident reporting, patching and basic technical controls, often on ageing infrastructure.

2017 — WannaCry: the inflection point

The WannaCry ransomware attack impacts large parts of the NHS, forcing cancellations and emergency response. It exposes the risks of legacy systems, flat networks and inconsistent patching, and triggers significant national investment and scrutiny.

2018 — GDPR, Data Protection Act 2018, NIS & DSPT

The EU GDPR comes into force, alongside the UK Data Protection Act 2018. The Network and Information Systems (NIS) Regulations 2018 designate NHS providers and ICBs as Operators of Essential Services. The Data Security and Protection Toolkit (DSPT) formally replaces the IG Toolkit as the main assurance mechanism.

2019–2021 — DSPT embeds as the baseline

DSPT compliance becomes a contractual requirement and a key part of commissioners' assurance. Boards are expected to own cyber and data security risk, report serious incidents, and demonstrate progress against the National Data Guardian's 10 data security standards.

2022–2023 — National strategies and integrated care

Government and DHSC publish cyber security strategies aligned to 2030, emphasising cyber as patient safety. Integrated Care Systems (ICS/ICBs) gain a role in coordinating cyber resilience across local health and care, not just individual Trusts.

2024–2025 — CAF-aligned DSPT and outcome-based assurance

The DSPT is re-engineered to align with the NCSC Cyber Assessment Framework (CAF). Assurance shifts towards outcomes and risk-based, expert judgement rather than 'tick-box' compliance. Data protection, clinical safety and cyber are pulled together more tightly.

Digital & technology in local providers

Infrastructure · Cloud · Collaboration

2000–2005 — On-premise everything

Local providers run almost entirely on-prem IT: Windows Server estates in data centres and comms rooms, locally hosted line-of-business apps, and early EPR pilots. Networks are simple 'trusted vs untrusted' perimeter models with basic firewalls.

2006–2010 — National programmes, local legacy

National Programme for IT and Spine-based services grow, but most Trusts still operate their own data centres and bespoke systems. Digital maturity is patchy, and technical debt starts to accumulate in infrastructure and clinical systems.

2011–2013 — Windows, Cisco and flat networks

Windows Server and Windows client estates dominate, with traditional Cisco networks and relatively flat VLAN structures. Active Directory is the de-facto identity platform. Device management is largely via SCCM/MECM on-prem.

2013+ — Cloud First (on paper)

The Government introduces a 'Cloud First' policy, expecting cloud services to be evaluated before other options. In practice, most NHS estates remain on-prem due to complex clinical applications, integration challenges and risk appetite.

2014–2016 — Early cloud pilots and partial convergence

Some organisations trial cloud-hosted apps and shared data centres. IT/OT convergence slowly appears, particularly where building management, imaging and clinical devices sit on the same flat networks, often without strong segmentation.

2017–2018 — Post-WannaCry upgrades and Windows 10

The response to WannaCry accelerates patching programmes and OS upgrades. Deals with Microsoft support migration to Windows 10, and many Trusts begin large-scale endpoint refresh, though legacy clinical devices remain a constraint.

2019–2021 — National CSOC, M365 and Exchange Online

A national Cyber Security Operations Centre (CSOC) capability matures. Millions of NHSmail mailboxes are migrated to Exchange Online and M365, giving access to Teams and modern collaboration tools while core clinical apps remain largely on-prem.

2020–2022 — Pandemic-driven remote work and hybrid estates

COVID-19 forces rapid scaling of VPNs, remote clinics and collaboration tools. Estates become 'hybrid by accident': a mix of legacy on-prem, hastily adopted cloud services and multiple overlapping network security patterns.

2021–2024 — Secure Boundary, Defender for Endpoint and central visibility

National services such as NHS Secure Boundary and Defender for Endpoint feed telemetry to the CSOC, improving central visibility across millions of endpoints. However, local architectures often remain flat and perimeter-centric.

2024–2025 — NHS.net Connect and slow modernisation of the fundamentals

NHSmail evolves into NHS.net Connect with a nationally funded M365 suite. Many local providers still run predominantly on-prem Windows Server estates, Active Directory for identity, SCCM/MECM for device management and only co-managed Intune at best. Merged organisations often retain multiple AD forests, overlapping networks and duplicated technology stacks, limiting the benefits of consolidation.

2025–2030 — where this is heading

From 2025 to 2030, the direction of travel is clear: every health and social care organisation is expected to achieve cyber resilience by 2030, with CAF-aligned DSPT, stronger use of NIS, and an assumption of hybrid or cloud-native architectures rather than purely on-prem estates.

Many local providers, however, still run on-prem Windows estates, flat Cisco networks, and AD-centric identity, with cloud adoption constrained by legacy apps, cost shocks and unfinished mergers. The next five years are about closing that gap: modernising the foundations, not just adding more tools.

Accelerated resilience and trusted AI solutions

Services

Company

Cyber Essentials certifiedCyber Essentials Plus certifiedBSI ISO/IEC 27001 Information Security Management certifiedCrown Commercial Service supplier
© 2026 onionio.com. All rights reserved.