Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

How Protected is NHS Data? New Sophos Survey Reveals Gaps in NHS IT Security

by The Gurus
January 20, 2016
in Editor's News
Share on FacebookShare on Twitter

 
Sophos (LSE:SOPH), a global leader in network and endpoint security, today announced the results of a survey into IT security levels within the NHS. Carried out by Vanson Bourne for Sophos, the new study reveals a gap between the perceived strength of IT security measures in the NHS and the actual level of IT security built into NHS networks.
 
In the study of 250 NHS-employed CIOs, CTOs and IT Managers, three quarters – 76 percent – believe that they have suitable protection against cybercrime and data loss and 72 percent claim data loss is their biggest concern in terms of IT security.
 
However, while 84 percent of respondents state that encryption is becoming a necessity, the Sophos study reveals that encryption levels are worryingly low across the NHS:
 

  • Only 10 percent state that encryption is well established within their organisation
  • Only 59 percent have email encryption
  • Only 49 percent have file share encryption
  • Only 34 percent have encryption of data stored in the cloud

 
According to the Information Commissioners Office (ICO), the NHS was the UK’s number one victim of data breaches last year. Data leakage and loss of hardware, such as USB keys, were two of the most prevalent factors in these breaches.
 
“This study highlights that NHS organisations still face significant IT security issues and that IT decision makers have work to do to address gaps in their security,” said Jonathan Lee, UK Healthcare Sector Manager, Sophos UK and Ireland. “Failure to take the necessary precautions to keep cyber criminals out, to safeguard data and ultimately to protect patients and staff will continue to cause significant problems for NHS organisations. However, budget cuts and changes to working practices, such as the increase in mobile working, all present significant challenges within the sector. ”
 
Commenting on specific findings, Mr. Lee continued, “It’s no surprise that only 10 percent of NHS organisations stated that encryption was well established within their organisation. Most have encrypted laptops and USB sticks because they have been mandated to do so, but, currently, that is often where it stops.”
 
 
Mobile Healthcare – A seismic shift for NHS IT security
The NHS is undergoing a period of significant change – balancing budget cuts while innovating to drive improvements to patient care. As a result, many NHS organisations are driving major operational change, including embracing mobile healthcare.  In the Sophos survey, 42 percent of respondents cite greater use of mobile devices in the community as one of the initiatives driving changes in IT security. This might be, for example, a community midwife using a tablet to record patient data instead of needing to carry around multiple patient files.
 
Health workers are increasingly on the move and using mobile working practices to stay connected. The impact of the widespread use of mobile devices out in the community on the security of an entire NHS organisation’s network should not be underestimated. With this step change in working practices comes new requirements and IT managers need to ensure their organisation’s IT security is joined up to adequately protect users, devices and data at all points.
Consolidation and investment – future plans will drive improvements
The survey also showed that decision makers in the NHS are beginning to understand the importance of consolidation for improved protection. 42 percent state that they are considering consolidating their IT security providers, with over half (55 percent) stating the main motivation for this as cost savings. This is no surprise, considering 96 percent of organisations say they have experienced operational changes in the past year, with the most common change being budget cuts (60 percent). Survey respondents expect the average cut to IT budgets to be 6 percent, so budget will remain core to any investment decisions being made.
 
Of those not considering consolidating their suppliers, 54 percent  said that they have many different requirements and their belief is that a sole provider cannot deliver on all requirements. Many in the industry would argue that this is an outdated perception that can lead to gaps within network security.
 
Jonathan Lee explains: “There is an important shift taking place in IT security. Organisations need a comprehensive security system that encrypts sensitive data, protects all classes of endpoints and communicates with network security systems. Sophos is at the forefront of this shift with a range of solutions offering a synchronized approach to IT security.”

ShareTweet
Previous Post

Yahoo Mail Patches Severe XSS Flaw Affecting 300M Users

Next Post

Duo Security Finds Over 90 Percent of Android Devices Run Outdated Operating Systems

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol