NHS Highland staff ‘poor practice’ sparks fears of heightened risk of a major cyber attack


NHS Highland is at heightened risk of falling prey to a major cyber attack in part due to “poor practice” by some staff members. The warning, contained in a report to the board assessing risk levels faced in a range of areas against what is deemed an acceptable level of risk, comes as the busy winter period for the NHS – when demand on services soars – is beginning to bite.

It states that here is “a risk of poor practice across cyber-security, information governance” as well as other areas such as health and safety and infection control “due to poor compliance with statutory and mandatory training requirements resulting in possible data breaches” as well as “injury or harm to colleagues or patients, poor standards of quality and care, reputational damage, prosecution or enforcement action.”

Read more…
Source: The Inverness Courier News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • London Fire Brigade block almost 340,000 cyber attacks

    October 8, 2024

    The London Fire Brigade, the fire and rescue service for the UK’s capital, has been targeted by nearly 340,000 cyber-attacks over the past year. The data was collected under the Freedom of Information Act (FOI), and analysed by the Parliament Street think tank, observing the number of blocked email attacks by the department. In total, the ...

  • UK’s Sellafield nuclear waste processing plant fined £333K for infosec blunders

    October 4, 2024

    The outfit that runs Britain’s Sellafield nuclear waste processing and decommissioning site has been fined £332,500 ($440,000) by the nation’s Office for Nuclear Regulation (ONR) for its shoddy cybersecurity practices between 2019 and 2023. Sellafield, located in Cumbria, England, manages more radioactive waste than any other nuclear site in the world, and decommissioning work happening at ...

  • Northern Ireland police fined $1.29m over ‘serious’ data breach

    October 3, 2024

    Northern Ireland’s police authority was on Oct 3 fined £750,000 (S$1.29 million) over a data breach that saw the personal details of police and intelligence officers posted on a website. The identities of all 9,483 staff members of the Police Service of Northern Ireland (PSNI) were mistakenly published online on Aug 8, 2023, after a freedom ...

  • Cyber Security Bill will prevent future attacks on NHS

    October 2, 2024

    New legislation to improve UK cyber defences and protect public services will prevent attacks similar to the ransomware attack impacting London hospitals, according to the Department of Science, Innovation and Technology (DSIT). The Cyber Security and Resilience Bill, which is due to be introduced to Parliament in 2025, was first announced in the King’s Speech on ...

  • UK unmasks LockBit ransomware affiliate as high-ranking hacker in Russia state-backed cybercrime gang

    October 1, 2024

    The U.K.’s National Crime Agency has linked a long-standing affiliate of the LockBit ransomware group to the notorious Russia-backed Evil Corp, a cybercrime gang with links to the Russian government. The NCA said on Tuesday that it had unmasked the LockBit affiliate, known as “Beverley,” as Russian national Aleksandr Ryzhenkov, who British authorities believe to be ...

  • UK data watchdog investigating MoneyGram data breach

    September 27, 2024

    The U.K.’s data protection regulator has confirmed it’s investigating MoneyGram after receiving a data breach report from the U.S.-based money transfer giant. The U.K.’s Information Commissioner’s Office, which requires that organizations report data breaches within 72 hours of discovering the incident, confirmed to TechCrunch on Friday that the watchdog had received a report from MoneyGram following ...