New Mandatory Cybersecurity Requirements for Medical Devices

News just in: the 2021 NHS DSPT (Data Security and Protection Toolkit) has specified that healthcare organisations must maintain an up-to-date inventory of medical devices connected to their network.

What is the DSPT?

The NHS Data Security and Protection Toolkit is an online self-assessment tool that allows organisations to measure their performance against the National Data Guardian’s 10 data security standards. All organisations that have access to NHS systems and patient data must adhere to this toolkit and ensure that they are practising good data security and correctly handling confidential information.

As of September 2021, NHS Digital amended the DSPT to make it mandatory that all NHS organisations keep an up to date record of medical devices.

What are the top 3 data security and protection risks in healthcare?

Healthcare organisations are particularly vulnerable to cyberattacks as they use indispensable devices that are constantly in operation and can’t be easily replaced or updated. What’s more, with thousands of devices connecting to a hospital network, it’s becoming increasingly challenging to manage  and secure the IT environment. Security weaknesses can’t be rectified if nobody knows that they exist.

It boils down to one key issue: in the world of healthcare, a cybersecurity issue is a patient safety issue.

  • Outdated operating systems

 

Devices that are running out-of-date, unsupported software and no longer receive security updates (‘patches’) pose significant risks. Hospitals have thousands of devices connected to the IT network, from computers and smartphones to medical and IoT devices. All it takes is for one of them to have an exploitable hardware or software vulnerability, leading to all manner of issues – from the disruptive to the devastating.

Although the NHS has been migrating devices from Windows XP and Windows 7 to a current operating system for some time, compatibility issues can still arise. There are also financial repercussions when machines cannot be updated and have to be replaced.

Hospital IT teams don’t have the time or resources to manage and manually update every single device. Even if a device can be updated, it may be a lengthy process, which means the vulnerability remains on the system for some time.

 

  • A lack of Advanced Threat Protection

 

Advanced Threat Protection (ATP) refers to a category of cybersecurity solutions that recognise and defend against complex malware, ransomware and cyberattacks that target sensitive data.

Storing vast amounts of patient, financial and medical research data, the NHS holds powerful and lucrative information, making it a primary target for malicious attacks. The global WannaCry ransomware attack of 2017 was a chilling reminder of what can happen without adequate ATP measures, disrupting 80 out of 236 NHS hospital trusts.

 

  • Outdated anti-virus/anti-malware software

 

If the anti-virus or anti-malware software is not up to date, it may as well not exist. It is not enough to have a ‘tick box’ approach to anti-virus software – organisations must ensure that it’s fit for purpose and can tackle the latest and most prevalent attacks out there.

The solution? Cylera

DSPT compliance will prompt many healthcare organisations to rethink their cybersecurity posture and make changes to align with NHS Digital requirements. This doesn’t have to be a gruelling task thanks to a game-changing platform that’s revolutionising the future of healthcare cybersecurity: Cylera.

‘Built with hospitals, for hospitals’, Cylera solves the complex technological and operational cybersecurity challenges that hospitals face. It’s the only centralised cybersecurity solution that protects the entire connected healthcare IoT environment.

  • Cylera protects and manages the complete healthcare IT environment including connected medical devices, operational technology, and IoT devices.
  • It delivers 360-degree visibility, insight, and protection for all managed or unmanaged connected devices, so users have a comprehensive record of devices on the network.
  • It identifies and quantifies connected device risks, pinpointing vulnerable devices and their clinical use cases. These devices are ranked based on tangible threats to patient safety and care delivery.
  • It has scalable, clinical-grade technology to support dense, high-traffic and multi-site deployments.
  • It poses zero impact to existing systems and processes during deployment or ongoing operation, so users don’t need to worry about disruptions to patient care.
  • Thanks to real-time threat detection, it quarantines hostile threats with industry-leading accuracy rates.

Securing IoT and medical devices will define the future of healthcare. As long as outdated software and operating systems exist, healthcare organisations will be vulnerable to attacks. As we move towards a more digital NHS, organisations must be prepared to tackle these cybersecurity challenges head-on

Contact our expert team today to learn more about how Cylera can protect your healthcare organisation from cyber threats.

Jan 20 2026

Join Us in Supporting the Great Gloucestershire Mouse Hunt

Core to Cloud is proud to support the Great Gloucestershire Mouse Hunt, a county-wide campaign collecting essential computer peripherals to help improve access to...
Jan 14 2026

From Defence to Resilience: A Strategic Framework for Ransomware Preparedness

Ransomware has evolved into a highly organised and commercially driven threat, capable of bypassing traditional cyber security controls. As attacks become more...
Nov 11 2025

Core to Cloud Partners with The ITSA Digital Trust to Empower Digital Inclusion and Support Sustainable Technology

At Core to Cloud, we’ve always believed that technology should make a positive difference by protecting people, enabling innovation, and building a more inclusive...
Oct 27 2025

Human-led, AI-Enhanced MDR: Rethinking the Balance of People and Technology

By Phil Howe, CTO at Core to Cloud It’s getting colder and wetter outside, and to some the security landscape may feel more complex than ever. Threat actors are faster,...
Oct 22 2025

From Warning to Action: The NCSC Calls on UK Organisations to Build Resilience

In its 2025 Annual Review, the UK’s National Cyber Security Centre (NCSC) issued one of its clearest warnings to date: organisations must prepare for a day when their...
Jun 25 2025

Think You’re Ready for a Cyberattack? Prove It.

In the face of increasing cyber threats, most organisations have invested heavily in technology - firewalls, antivirus, endpoint protection, and cloud security. But...
Jun 13 2025

Secure & Strong Partners with Women in Tech & Cyber Hub (WITCH)

At Core to Cloud, we believe the future of cybersecurity is inclusive, empowering, and community-driven. That’s why we’re proud to announce a meaningful new partnership...
Jun 13 2025

Core to Cloud Expands Strategic Partnership with Vectra AI to Strengthen 24/7 SOC Capabilities

Cirencester, UK, 13 June 2025: Core to Cloud, a leading UK-based provider of cybersecurity services, is deepening its strategic partnership with Vectra AI, the...
May 19 2025

Supply Chain Cyberattacks: Lessons from a Retail Incident

In early May 2025, the UK retail sector experienced a wake-up call. A ransomware attack targeting a retailer’s IT infrastructure disrupted supply chains, impacted...
Mar 14 2025

Rev Up Your Security: Why Cybersecurity is a High-Speed Race, Not a Sunday Drive

Picture this: You’re on the starting grid. The engines roar. The stakes are high. In the relentless Grand Prix of cybersecurity, there’s no cruising—only speed,...

Trusted by CISOs and IT teams at over 150 organisations