Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
NHS England Digital Profession

NHS England Digital Profession Vendor Cyber Rating & Cyber Score

nhs.uk

A community of digital experts who work across the NHS in England. Together, we work on products, services, programmes, IT systems and operations that improve lives for patients, carers, staff and communities. This space is where we can share news and best practice, job opportunities and ideas as well as develop our thinking through collaboration and problem solving. Part of our collective purpose is to transform the NHS – not only by empowering patients but also supporting clinicians, releasing more time to care. This is more about our approach than the technology itself. It is how we work, what it feels like to deliver, how we put our users first, how we experiment, and how we deliver brilliant products, services and programmes.


NEDP A.I CyberSecurity Scoring

NEDP
Company Information
Website:http://digital.nhs.uk
Employees number:1,238
Number of followers:153,905
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:nhs.uk
NEDP Risk Score (AI oriented)
Between 550 and 599
logo
NEDPHospitals and Health Care
Updated:
30/06/2026
584/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
NEDP Global Score (TPRM)
xxxx
logo
NEDPHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

NEDP
NEDPVery Poor
Current Score
584Ca (VERY POOR)
01000
2 incidents
-130 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
587Before Incident
JUNE 2026
584Before Incident
MAY 2026
575Before Incident
APRIL 2026
575Before Incident
MARCH 2026
570Before Incident
FEBRUARY 2026
564Before Incident
JANUARY 2026
684Before Incident
Ransomware
01 Jan 2026NEDP
NHS: SonicWall: NHS hospitals hit by 10x cyber attack surge

UK Healthcare Under Siege: Ransomware Reconnaissance Intensifies in 2026

554After Incident
CRITICAL-130
NHS1782830096
UK Healthcare Under Siege: Ransomware Reconnaissance Intensifies in 2026 New data from SonicWall reveals the UK’s healthcare sector is facing an unprecedented surge in cyberattacks, with more intrusion attempts per device than any other industry. Between January and May 2026, SonicWall’s Intrusion Prevention System (IPS) logged 264,000 attack events across NHS networks nearly 10 times the total for all of 2025 (27,000). On average, each monitored sensor recorded 11,000 hits, a rate unmatched in other UK sectors. The threat landscape is dominated by 10 active ransomware families, the highest concentration of any vertical. While no ransomware detonations were detected during the monitoring period, SonicWall warns this lull is deceptive. Instead, attackers appear to be in a prolonged reconnaissance phase, systematically mapping NHS digital infrastructure before launching high-impact strikes. This shift aligns with a broader global trend of precision targeting in critical infrastructure, where threat actors prioritize stealth and preparation over immediate disruption. ### Two Primary Attack Vectors 1. Legacy Infrastructure: 41% of IPS events exploited Apache Log4j2, a vulnerability disclosed in late 2021 but still unpatched in many NHS clinical systems. Another 33% of sensors detected active exploitation attempts against F5 BIG-IP load balancers, highlighting persistent weaknesses in outdated technology. 2. Digital Patient Portals: The rapid expansion of modern web frameworks (e.g., React, Next.js) in patient-facing systems has introduced new vulnerabilities. Attackers are probing these alongside legacy risks, exploiting the gap between old and new infrastructure. Spencer Starkey, SonicWall’s EVP for EMEA, emphasizes the unique structural challenges facing the NHS: "Zombie tech, ancient unpatched systems, and legacy Java keep haunting the NHS. Administrators can’t just take a critical care system offline to patch it. Meanwhile, the rush to digitize has opened the door to brand-new web vulnerabilities in patient portals." ### A False Sense of Security? Despite the 87% drop in ransomware activations across UK businesses in 2025 as attackers shifted to fewer, higher-impact targets healthcare remains a prime focus. The absence of detonations in 2026 does not signal improved defenses but rather a calculated buildup. SonicWall’s data suggests attackers are stress-testing NHS systems, probing for weaknesses before executing large-scale attacks. Past incidents underscore the stakes: - WannaCry (2017): Cost the NHS £92 million. - Synnovis (2024): Led to 1,500 canceled operations and was linked to one patient’s death. - Advanced Computer Software Group (2024): Disrupted emergency prescriptions, ambulance dispatches, and patient referrals across multiple trusts. ### Regulatory and Operational Challenges The Cyber Security and Resilience Bill, introduced in Parliament last November, aims to extend mandatory security requirements to 1,000 NHS suppliers. However, the bill does not address the core issue: legacy systems that cannot be taken offline for patching. NHS leadership must now determine how to govern persistent risk amid procurement cycles that struggle to match the speed of evolving threats. Vendors are closely analyzing SonicWall’s findings, seeing opportunities in legacy remediation, Zero Trust adoption, medical IoT segmentation, and large-scale MFA enforcement. Yet the NHS’s complex digital supply chains and critical care dependencies make rapid overhauls difficult. The data paints a clear picture: the UK’s healthcare sector is under sustained, methodical assault, with attackers biding their time before the next major strike.
INCIDENT DETAILS -
TYPE
Reconnaissance
MOTIVATION
Precision targeting of critical infrastructure for future high-impact ransomware attacks
IMPACT
Systems Affected: NHS networks, clinical systems, patient portalsOperational Impact: Potential future disruptions to critical care systems, canceled operations, and emergency servicesBrand Reputation Impact: Potential future reputational damage to NHS and UK healthcare sector
DECEMBER 2025
683Before Incident
NOVEMBER 2025
682Before Incident
OCTOBER 2025
681Before Incident
SEPTEMBER 2025
679Before Incident
AUGUST 2025
678Before Incident
JUNE 2025
771Before Incident
Ransomware
16 Jun 2025NEDP
NHS UK (National Health Service UK)

Cl0p Ransomware Group Exploits Oracle E-Business Suite Vulnerabilities in NHS UK and The Washington Post Data Breaches

673After Incident
CRITICAL-98
NHS2202122111225
The Cl0p ransomware group claimed responsibility for a data breach targeting NHS UK on November 11, 2026, exploiting critical vulnerabilities in Oracle’s E-Business Suite (EBS) (CVE-2025-61882, CVSS 9.8). The group accused NHS of neglecting security, stating it ignored customer protection, though the volume of stolen data remains undisclosed. The breach aligns with prior warnings from NHS’s cybersecurity division in October 2026 about unpatched Oracle EBS flaws, suggesting Cl0p leveraged the same vulnerabilities NHS had flagged. The attack follows a pattern of large-scale data exfiltration (rather than encryption) by Cl0p, targeting high-value enterprise systems. While NHS has not confirmed the breach, the timing—shortly after The Washington Post (another victim of the same Oracle EBS exploit)—implies a coordinated campaign. Experts warn the stolen data (potentially including patient records, employee details, or financial information) could be leaked or sold, posing risks to privacy, operational continuity, and public trust. The breach underscores systemic vulnerabilities in healthcare IT infrastructure, with Cl0p’s tactics involving prolonged undetected access before public disclosure.
INCIDENT DETAILS -
TYPE
Data BreachRansomware AttackExploitation of Vulnerability
MOTIVATION
Financial GainData ExtortionReputation Damage to Targets
IMPACT
The Washington Post: 183GBOracle E-Business Suite (EBS)BI Publisher Integration ModulePotential Disruption to Healthcare Services (NHS UK)Compromised Journalistic Operations (The Washington Post)High (Accusations of Negligence by Cl0p)Erosion of Trust in NHS UK and The Washington PostPotential (Dependent on Stolen Data Types)
DATA BREACH
Potentially High (Enterprise Software Data)Confirmed (183GB for The Washington Post)Claimed for NHS UK (Volume Undisclosed)Potential (Not Specified)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for NEDP ?
?
What was NEDP's A.I Rankiteo Cyber Score in June 2026 ?
?
What was NEDP's A.I Rankiteo Cyber Score in May 2026 ?
?
What was NEDP's A.I Rankiteo Cyber Score in April 2026 ?
?
What was NEDP's A.I Rankiteo Cyber Score in March 2026 ?
?
What was NEDP's A.I Rankiteo Cyber Score in February 2026 ?
?
What was NEDP's A.I Rankiteo Cyber Score in January 2026 ?
?
What was NEDP's A.I Rankiteo Cyber Score in December 2025 ?
?
What was NEDP's A.I Rankiteo Cyber Score in November 2025 ?
?
What was NEDP's A.I Rankiteo Cyber Score in October 2025 ?
?
What was NEDP's A.I Rankiteo Cyber Score in September 2025 ?
?
What was NEDP's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on NEDP's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with NEDP ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view NEDP's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?