---
title: The importance of people and process in the fight to secure NHS data
description: The computer virus which affected Northern Lincolnshire and Goole NHS Foundation Trust in November is a further reminder that NHS organisations need to remain constantly on their guard against security breaches.
image: https://blog.fordway.com/hubfs/Blog%20images/nhsdatanarrow.jpg
---

T. 01483 528 200 [How can we help?](https://www.fordway.com/contact-us) [Contact us](https://www.fordway.com/contact-us)

[![fordway-logo](https://www.fordway.com/wp-content/uploads/2019/07/fordway-logo.png "fordway-logo")](https://www.fordway.com/)

- [Home](https://www.fordway.com)
- [Insights](https://www.fordway.com/insights/blog)
- [Cloud Services](https://www.fordway.com/services/cloud)

# Fordway Blog

## [The importance of people and process in the fight to secure NHS data](https://blog.fordway.com/the-importance-of-people-and-process-in-the-fight-to-secure-nhs-data)

 \[fa icon="calendar"\] Jan 28, 2017 12:01:00 AM / by [Navtej Kalkat](https://blog.fordway.com/author/navtej-kalkat)

- [Tweet](https://twitter.com/share)

NHS Cloud and IT Consultancy - Fordway Blog

The computer virus which affected Northern Lincolnshire and Goole NHS Foundation Trust in November is a further reminder that NHS organisations need to remain constantly on their guard against security breaches. As no ransom was demanded, it’s likely to have been a random attack, but reports suggest that [28 trusts](http://www.digitalhealth.net/cybersecurity/48153/28-nhs-trust-ransomware-attacks-reported) have been hit by ransomware attacks in the last year. Additionally, the NHS was the UK’s biggest victim of data breaches in 2015 according to the Information Commissioner’s Office.

![nhsdatanarrow.jpg](https://blog.fordway.com/hs-fs/hubfs/Blog%20images/nhsdatanarrow.jpg?width=711&height=303&name=nhsdatanarrow.jpg)

To help Trusts tackle these threats, the National Data Guardian Review was published in July 2016. The results of the public consultation into its recommendations are still to be published, but the key points made in the Review are relevant to across all sectors. It points out that leadership is vital to data security, and leaders have three areas of responsibility in minimising the security threat: technology, people and process.

Technology solutions are becoming increasingly sophisticated, such as pattern recognition software to track unusual behaviour. However even apparently ‘low tech’ equipment should be considered, as it only needs one back door for an organisation’s security to be compromised, such as the ubiquitous USB data stick.

The importance of people to security is something Fordway’s MD Richard Blanford has discussed on [many occasions](http://www.fordway.com/about-us/blog/entry/developing-a-data-security-strategy). Even the best processes and technology will not work unless people follow the correct processes, so organisations need to define security policy and obtain employee buy-in and commitment before looking for technical solutions.

People generated security breaches can range from an employee accidentally clicking on a malicious attachment to the case quoted in the Review, where an employee was socially engineered by a journalist to release pseudonymised information on hospital statistics which, due to their format, could have been re-identified. Employee education is vital to minimise such risks and, importantly, to ensure that if the worst occurs staff know what to do and who to contact to reduce the damage.

This takes us to the area of policy: security policy should be enforceable, realistic, acceptable to users and should not violate personal privacy laws. Policy should also ensure that organisations take all appropriate steps to prevent data loss, from regular patching to having a cyber security incident response procedure in place, a back-up of all business critical systems and a disaster recovery plan. Automation can be a great help– for example, the Review points out a malware attack resulting from patching not being updated, but organisations can automate their own patching using tools such as SCCM, or buy a cloud-based service such as [Fordway’s PMaaS](http://www.fordway.com/cloud-services/cloud-intermediation-services/patch-management).

Policy also needs to take account of employee behaviour, and be supplemented with technology where appropriate to reduce risks. For example, policy may be that no data can be taken out of the organisation, but all too often staff save documents onto mobile devices to read at a more convenient time. If the device is lost, so is the data. The latest[endpoint protection solutions](http://www.fordway.com/cloud-services/managed-cloud/endpoint) can address this by both ensuring that data is backed up and automatically deleting it on a stolen or lost device – provided that the employee admits to the loss! Thus the three aspects of people, process and technology are the three legs of the security tripod. Fail to address any of them adequately and the results could be disastrous.

 NHS Cloud and IT Consultancy - Fordway Blog

For more comprehensive advice on how to develop your data security strategy you can download our Data Security White Paper: **[How Secure is your Critical Business Data?](http://www.fordway.com/component/rsform/form/15)**.

 

 Topics: [Security](https://blog.fordway.com/topic/security), [Disaster Recovery](https://blog.fordway.com/topic/disaster-recovery), [IT Strategy](https://blog.fordway.com/topic/it-strategy)

![Navtej Kalkat](https://blog.fordway.com/hs-fs/hubfs/Blog%20images/bloggers/91_NavKalkat.jpg?width=100&height=100&name=91_NavKalkat.jpg)

#### Written by [Navtej Kalkat](https://blog.fordway.com/author/navtej-kalkat)

### Get updates directly to your inbox

 

Read more about [Fordway Cloud Services](https://www.fordway.com/cloud-services)

- Recent
- Popular
- Categories

### Lists by Topic

- [Cloud (16)](https://blog.fordway.com/topic/cloud)
- [IT Strategy (13)](https://blog.fordway.com/topic/it-strategy)
- [Security (13)](https://blog.fordway.com/topic/security)
- [IT Transformation (10)](https://blog.fordway.com/topic/it-transformation)
- [Technology (10)](https://blog.fordway.com/topic/technology)
- [cloud intermediation (10)](https://blog.fordway.com/topic/cloud-intermediation)
- [Cloud migration (9)](https://blog.fordway.com/topic/cloud-migration)
- [Cloud Security (8)](https://blog.fordway.com/topic/cloud-security)
- [enterprise cloud (8)](https://blog.fordway.com/topic/enterprise-cloud)
- [Insider (7)](https://blog.fordway.com/topic/insider)
- [Strategy (7)](https://blog.fordway.com/topic/strategy)
- [Cloud Shock (6)](https://blog.fordway.com/topic/cloud-shock)
- [Fordway Managed Services (6)](https://blog.fordway.com/topic/fordway-managed-services)
- [GDPR (6)](https://blog.fordway.com/topic/gdpr)
- [managed cloud (6)](https://blog.fordway.com/topic/managed-cloud)
- [Azure (5)](https://blog.fordway.com/topic/azure)
- [Disaster Recovery (5)](https://blog.fordway.com/topic/disaster-recovery)
- [New Technology (5)](https://blog.fordway.com/topic/new-technology)
- [legacy (4)](https://blog.fordway.com/topic/legacy)
- [tactical (4)](https://blog.fordway.com/topic/tactical)
- [#ChooseToChallenge (3)](https://blog.fordway.com/topic/choosetochallenge)
- [#IWD2021 (3)](https://blog.fordway.com/topic/iwd2021)
- [Cloud Monitoring (3)](https://blog.fordway.com/topic/cloud-monitoring)
- [Data Protection (3)](https://blog.fordway.com/topic/data-protection)
- [Fordway (3)](https://blog.fordway.com/topic/fordway)
- [Governance (3)](https://blog.fordway.com/topic/governance)
- [ITIL (3)](https://blog.fordway.com/topic/itil)
- [Risk Management (3)](https://blog.fordway.com/topic/risk-management)
- [cloud first (3)](https://blog.fordway.com/topic/cloud-first)
- [remote working (3)](https://blog.fordway.com/topic/remote-working)
- [trends (3)](https://blog.fordway.com/topic/trends)
- [Cyber Security (2)](https://blog.fordway.com/topic/cyber-security)
- [Meet the team (2)](https://blog.fordway.com/topic/meet-the-team)
- [Ransomeware, incident response, CISO, Security (2)](https://blog.fordway.com/topic/ransomeware-incident-response-ciso-security)
- [Ransomware (2)](https://blog.fordway.com/topic/ransomware)
- [case study (2)](https://blog.fordway.com/topic/case-study)
- [compliance (2)](https://blog.fordway.com/topic/compliance)
- [technical debt (2)](https://blog.fordway.com/topic/technical-debt)
- [Cloud Paging (1)](https://blog.fordway.com/topic/cloud-paging)
- [Connectivity (1)](https://blog.fordway.com/topic/connectivity)
- [DaaS (1)](https://blog.fordway.com/topic/daas)
- [DraaS (1)](https://blog.fordway.com/topic/draas)
- [Incident Response (1)](https://blog.fordway.com/topic/incident-response)
- [Managed Services (1)](https://blog.fordway.com/topic/managed-services)
- [Microsoft Sentinel (1)](https://blog.fordway.com/topic/microsoft-sentinel)
- [Networking (1)](https://blog.fordway.com/topic/networking)
- [Optimised Infrastructure (1)](https://blog.fordway.com/topic/optimised-infrastructure)
- [Patch Management (1)](https://blog.fordway.com/topic/patch-management)
- [Patching (1)](https://blog.fordway.com/topic/patching)
- [Project Management (1)](https://blog.fordway.com/topic/project-management)
- [Technology Services 2 (1)](https://blog.fordway.com/topic/technology-services-2)
- [Web hosting (1)](https://blog.fordway.com/topic/web-hosting)
- [hyperconvergence (1)](https://blog.fordway.com/topic/hyperconvergence)
- [information security (1)](https://blog.fordway.com/topic/information-security)
- [shared services (1)](https://blog.fordway.com/topic/shared-services)
- [vdi (1)](https://blog.fordway.com/topic/vdi)
- [virtual desktop (1)](https://blog.fordway.com/topic/virtual-desktop)

see all

## [Older Fordway Posts](https://www.fordway.com/blog/archive)

 

[Tweets by @Fordway](https://twitter.com/Fordway)

### CONTACT

01483 528 200

[Privacy Policy](https://www.fordway.com/privacy-policy)  
[Anti-Slavery Policy](https://www.fordway.com/anti-slavery-policy)

 

### This is Ermincloud the Fordway cow

[Find out why she matters to us!](https://www.fordway.com/ermincloud)

[![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/twitter-footer-icon.png)](https://twitter.com/Fordway) [![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/facebook-footer-icon.png)](https://www.facebook.com/Fordway-358130410947628/) [![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/youtube-footer-icon.png)](https://youtube.com) [![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/linkedin-footer-icon.png)](https://www.linkedin.com/company/fordway-solutions)

Copyright © 2020 Fordway Solutions

\[fa icon="chevron-up"\]Back to top

![](https://dc.ads.linkedin.com/collect/?pid=94312&fmt=gif)