In June 2024, Synnovis, a supplier of pathology services to the NHS, was the victim of a ransomware attack. Computer systems were hacked, private patient data was stolen, and IT systems were rendered useless. This resulted in disruption to services at five NHS trusts and local care service providers across several London boroughs, causing delays to over 11,000 out-patient and elective procedure appointments and, tragically, contributed to the death of a patient. For Synnovis itself, the financial impact of the cyber-attack is estimated at £32.7 million.
The internet is one of the greatest engines for creativity and innovation, transforming every part of our lives, from how we communicate to how we book an appointment with our doctor. It is embedded into every part of the critical systems we rely on daily, with huge benefits. However, as the attack on the NHS provider shows, the technology that underpins cyber-space—the invisible world where all our online activity happens—can be attacked and weaponised by those who mean to do us harm.
Vulnerability to cyber-attacks is not limited to the NHS. Last year, over 600,000 UK businesses were subject to a cyber-attack. Independent research commissioned by DSIT—published today—shows the average cost of a significant cyber-attack for a UK business is over £190,000. When taken at the level of the economy, this suggests an estimated annual cost to businesses of £14.7 billion, or 0.5% of the country’s GDP. These statistics and recent high-profile attacks serve as a sobering reminder that cyber-security is not a luxury, and all organisations should take steps to defend themselves.
The Government are taking a wide range of actions to improve cyber-resilience across the economy. This includes:
Writing to leading UK firms asking them to take urgent action on cyber-security. So far, over 130 firms have responded to the letter with details of the actions they are taking, including requiring suppliers to adopt the cyber essentials scheme.
Launching a new cyber action toolkit to help small businesses boost their online defences.
Offering free cyber-security guidance, tools, training and codes of practice.
Offering practical, hands-on cyber-security help to small and medium-sized enterprises via nine regional cyber-resilience centres.
The “Stop! Think Fraud” campaign, which provides advice to the public and small businesses on how to prevent fraud and cyber-crime.
But where organisations provide essential services that the public and businesses rely on every day, we must go further to ensure that appropriate and proportionate safeguarding measures are in place. As the CEO of the National Cyber Security Centre warned,
“the challenge we face is growing at an order of magnitude”.