NEDP A.I CyberSecurity Scoring
NEDP
Company Information
Website:http://digital.nhs.uk
Employees number:1,238
Number of followers:153,905
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:nhs.uk
NEDP Risk Score (AI oriented)
Between 550 and 599
NEDPHospitals and Health Care
Updated:
30/06/2026
30/06/2026
584/1000
Very Poor
Ca
NEDP Global Score (TPRM)
xxxx
NEDPHospitals and Health Care
Score locked

NEDPVery Poor
Current Score
584Ca (VERY POOR)
01000
2 incidents
-130 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
587
JUNE 2026
584
MAY 2026
575
APRIL 2026
575
MARCH 2026
570
FEBRUARY 2026
564
JANUARY 2026
684
Ransomware
01 Jan 2026 • NEDP
NHS: SonicWall: NHS hospitals hit by 10x cyber attack surge
UK Healthcare Under Siege: Ransomware Reconnaissance Intensifies in 2026
554
CRITICAL-130
NHS1782830096
UK Healthcare Under Siege: Ransomware Reconnaissance Intensifies in 2026
New data from SonicWall reveals the UK’s healthcare sector is facing an unprecedented surge in cyberattacks, with more intrusion attempts per device than any other industry. Between January and May 2026, SonicWall’s Intrusion Prevention System (IPS) logged 264,000 attack events across NHS networks nearly 10 times the total for all of 2025 (27,000). On average, each monitored sensor recorded 11,000 hits, a rate unmatched in other UK sectors.
The threat landscape is dominated by 10 active ransomware families, the highest concentration of any vertical. While no ransomware detonations were detected during the monitoring period, SonicWall warns this lull is deceptive. Instead, attackers appear to be in a prolonged reconnaissance phase, systematically mapping NHS digital infrastructure before launching high-impact strikes. This shift aligns with a broader global trend of precision targeting in critical infrastructure, where threat actors prioritize stealth and preparation over immediate disruption.
### Two Primary Attack Vectors
1. Legacy Infrastructure: 41% of IPS events exploited Apache Log4j2, a vulnerability disclosed in late 2021 but still unpatched in many NHS clinical systems. Another 33% of sensors detected active exploitation attempts against F5 BIG-IP load balancers, highlighting persistent weaknesses in outdated technology.
2. Digital Patient Portals: The rapid expansion of modern web frameworks (e.g., React, Next.js) in patient-facing systems has introduced new vulnerabilities. Attackers are probing these alongside legacy risks, exploiting the gap between old and new infrastructure.
Spencer Starkey, SonicWall’s EVP for EMEA, emphasizes the unique structural challenges facing the NHS: "Zombie tech, ancient unpatched systems, and legacy Java keep haunting the NHS. Administrators can’t just take a critical care system offline to patch it. Meanwhile, the rush to digitize has opened the door to brand-new web vulnerabilities in patient portals."
### A False Sense of Security?
Despite the 87% drop in ransomware activations across UK businesses in 2025 as attackers shifted to fewer, higher-impact targets healthcare remains a prime focus. The absence of detonations in 2026 does not signal improved defenses but rather a calculated buildup. SonicWall’s data suggests attackers are stress-testing NHS systems, probing for weaknesses before executing large-scale attacks.
Past incidents underscore the stakes:
- WannaCry (2017): Cost the NHS £92 million.
- Synnovis (2024): Led to 1,500 canceled operations and was linked to one patient’s death.
- Advanced Computer Software Group (2024): Disrupted emergency prescriptions, ambulance dispatches, and patient referrals across multiple trusts.
### Regulatory and Operational Challenges
The Cyber Security and Resilience Bill, introduced in Parliament last November, aims to extend mandatory security requirements to 1,000 NHS suppliers. However, the bill does not address the core issue: legacy systems that cannot be taken offline for patching. NHS leadership must now determine how to govern persistent risk amid procurement cycles that struggle to match the speed of evolving threats.
Vendors are closely analyzing SonicWall’s findings, seeing opportunities in legacy remediation, Zero Trust adoption, medical IoT segmentation, and large-scale MFA enforcement. Yet the NHS’s complex digital supply chains and critical care dependencies make rapid overhauls difficult.
The data paints a clear picture: the UK’s healthcare sector is under sustained, methodical assault, with attackers biding their time before the next major strike.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
DECEMBER 2025
683
NOVEMBER 2025
682
OCTOBER 2025
681
SEPTEMBER 2025
679
AUGUST 2025
678
JUNE 2025
771
Ransomware
16 Jun 2025 • NEDP
NHS UK (National Health Service UK)
Cl0p Ransomware Group Exploits Oracle E-Business Suite Vulnerabilities in NHS UK and The Washington Post Data Breaches
673
CRITICAL-98
NHS2202122111225
The Cl0p ransomware group claimed responsibility for a data breach targeting NHS UK on November 11, 2026, exploiting critical vulnerabilities in Oracle’s E-Business Suite (EBS) (CVE-2025-61882, CVSS 9.8). The group accused NHS of neglecting security, stating it ignored customer protection, though the volume of stolen data remains undisclosed. The breach aligns with prior warnings from NHS’s cybersecurity division in October 2026 about unpatched Oracle EBS flaws, suggesting Cl0p leveraged the same vulnerabilities NHS had flagged. The attack follows a pattern of large-scale data exfiltration (rather than encryption) by Cl0p, targeting high-value enterprise systems. While NHS has not confirmed the breach, the timing—shortly after The Washington Post (another victim of the same Oracle EBS exploit)—implies a coordinated campaign. Experts warn the stolen data (potentially including patient records, employee details, or financial information) could be leaked or sold, posing risks to privacy, operational continuity, and public trust. The breach underscores systemic vulnerabilities in healthcare IT infrastructure, with Cl0p’s tactics involving prolonged undetected access before public disclosure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for NEDP ??
What was NEDP's A.I Rankiteo Cyber Score in June 2026 ??
What was NEDP's A.I Rankiteo Cyber Score in May 2026 ??
What was NEDP's A.I Rankiteo Cyber Score in April 2026 ??
What was NEDP's A.I Rankiteo Cyber Score in March 2026 ??
What was NEDP's A.I Rankiteo Cyber Score in February 2026 ??
What was NEDP's A.I Rankiteo Cyber Score in January 2026 ??
What was NEDP's A.I Rankiteo Cyber Score in December 2025 ??
What was NEDP's A.I Rankiteo Cyber Score in November 2025 ??
What was NEDP's A.I Rankiteo Cyber Score in October 2025 ??
What was NEDP's A.I Rankiteo Cyber Score in September 2025 ??
What was NEDP's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on NEDP's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with NEDP ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view NEDP's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?