Supplier Synnovis was hacked by a Russian-backed gang with sensitive data and front-line services impacted
The recent supply chain attack on the NHS impacted seven major hospitals across two NHS Trusts. The result of the ransomware attack saw operations cancelled, blood transfusion appointments postponed and women in labour sent to alternative hospitals. Alongside these immediate issues, the personal, sensitive data stolen has also caused huge concern, with some of the information reportedly already published.
The attack highlights the threat to the public sector more generally. The data stored within local authorities and the impact cyber-criminals can have on front-line services means that all within the public sector should be seeing the increasing threat and starting to do something about it.
The issue that many in the public sector face, is that no matter how much is invested in cyber-defences if cybercriminals can gain access to data via supply chain partners, then that investment is essentially a waste of time.

Local authorities need to look at new ways of protecting themselves and the data they hold as Rob Smith, CTO at CloudClevr explains.
“The hack on Synnovis meant that cybercriminals gained access to hugely sensitive data residing in the NHS. This saw high levels of disruption to major hospitals and NHS Trusts with appointments, operations, and blood transfusions cancelled and postponed. Alongside this, some of the data stolen already looks to have been published online, with patients now worrying about who has access to their data.
“As the attack originated with a supply chain partner rather than a direct attack on the NHS, cybercriminals were able to circumnavigate any front-line defences in place. Instead, by using the connected systems between Synnovis and the NHS they were able to secure the data they desired and cause havoc as a result.
“Unfortunately, this is the type of threat facing the public sector generally, and certainly one that continues to face local government. We have seen a number of attacks over the past few months that have actively targeted public sector organisations including the Ministry of Defence, Metropolitan Police, Manchester Police and more. In order to better protect themselves local authorities need to look to new approaches and systems that can protect them from vulnerabilities within their supply chain.
“Zero-trust policies can ensure that only those with the correct status and permission can view particular data. Although it sounds, on the face of it, a negative approach, it can quickly identify impersonators, denying them access and keeping data safe.
“Equally, data-driven solutions that can give a clear overview of where vulnerabilities might lie as well as areas where staff might need additional training, helping to ensure that staff know how to handle potential threats.
“For local authorities, much of this seems to be unachievable, both from a manpower and cost perspective. However, some are turning to independent consultancies who can help manage and implement these processes. This takes the strain away from understaffed and under-pressure in-house teams, as well as helping to ensure vulnerabilities are closed and regulation is adhered to,” Smith concluded.
Please follow and like us:




