Expanding the concept of Secure by Design for health and social care
Atkins’ Sophia Kladaki, Lewis Hodges, and Isobel Drever look at how health and social care organisations can become more cyber resilient by adopting a Secure by Design approach.
Cyber-attacks are on the rise, with the National Fraud Intelligence Bureau reporting that cybercrime during the COVID-19 pandemic cost UK businesses £2.4billion. With the pandemic demonstrating how reliant we are on our health and social care system, ensuring that its vast digital infrastructure is cyber secure is essential to maintaining high-quality services and protecting patient data.
The cyber threat continues to evolve, meaning information systems which were once deemed secure may not be resilient to future attacks. Devices or networks once considered business critical may become less so as new digital solutions are introduced. A Secure by Design approach, which builds and embeds security into systems from the outset, enables organisations to implement a proportionate and risk-based approach which manages security information throughout its entire lifecycle.
Secure by Design – assurance throughout the lifetime of an asset or capability
In 2018 the UK Government published its Secure by Design report and used the term to describe how security controls can and should be embedded into products and services during the design phase. This is sound guidance, but perhaps fails to consider ever-changing environments and threats. Instead, organisations can adopt a broader concept of Secure by Design, one which supports continual risk assessments of assets and capabilities. This approach considers how security threats evolve over time and can make allowances for this in the business case. This broader Secure by Design approach would also better utilise the technical expertise within an organisation, by involving subject matter experts more regularly throughout the risk management process.
At first glance, this might seem like a costly endeavour, but routine risk assessments can improve investment decisions. For example, an NHS Trust might have a long-standing subscription for expensive end-point protection on its computer network – a measure deemed essential for delivering patient care. However, over time, this network may become less critical due to the increased availability of viable alternatives. By reassessing the risk, the system owner can make an informed decision about whether to continue the subscription, make a technical change or decommission the network altogether.
Creating a Secure by Design environment
To implement this approach, there are three key elements that should be considered: a cultural shift towards risk-based decision making, the governance and business processes which enable the approach, and cultivating a digital mindset.
A cultural shift to risk-based decision making: The Secure by Design approach asks system owners to make pragmatic security decisions over the lifetime of an asset, by choosing security measures based on the perceived threat and impact of an attack. This approach doesn’t just ask the system owner to think differently, it also asks the organisation to embrace new ways of working which are characterised by trust and a willingness to deviate from the security checklist when justified. It may feel counterintuitive to abandon the rule book, but if said rules were written five years ago, they may no longer offer the greatest protection. To be proportional, decisions need to be risk based rather than rules based.
Governance and business processes: We recognise the importance of governance and business processes, particularly when patient data and the protection of health may be stake. They play a key role in the Secure by Design approach, but rather than being overly prescriptive, they are used to set safe parameters. They provide a framework for managing security within complex organisations like the NHS, while providing the latitude for effective decision making. Clear governance also has a key role in establishing accountability for through-life security risk management.
Digital mindset: Finally, it would be easy to misinterpret a digital mindset as one which requires a substantial amount of technical understanding. However, in this case, we are referring to a more general awareness within the workforce of the digital ecosystem, including its benefits and its risks. This expands beyond an isolated product or a service. It includes all those who interact with the capability, from the supplier who provided the microchip to the patient wearing the device.
The new Integrated Care Systems (ICSs) and Integrated Care Boards (ICBs) provide a window of opportunity to reassess the risk management approach across the health and social care sector. As regions transform to embrace this new construct, now is the right time for policymakers and healthcare leaders to ensure a Secure by Design approach is advocated to protect both staff and patients alike.
Get the inside track on what MPs and Peers are talking about. Sign up to The House's morning email for the latest insight and reaction from Parliamentarians, policy-makers and organisations.