Cyber security Budget 2017-22
Reference: 23-24278
Date response sent: 10/10/2023
Details of enquiry
- In 2023, what annual cybersecurity budget has been allocated to your NHS Trust?
- Can you also provide your Trust’s annual cybersecurity budget for the years:
- 2022
- 2021
- 2020
- 2019
- 2018
- 2017
- In 2023, how is your annual cybersecurity budget spent:
- What percentage goes towards cybersecurity training for employees?
- What percentage goes towards technology investments?
- What percentage goes towards employee resources for your cybersecurity team?
- How many employees work in your NHS Trust?
- How many employed, full-time members of staff make up your NHS Trust’s cyber/infosecurity team?
- How many hours of cybersecurity training are employees of your NHS Trust required to undertake every year?
- Has your NHS Trust paid any ransom demands to cybercriminals in the last five years?
- If yes, how much did you pay in total?
- Has your NHS Trust had any patient records compromised / stolen by cybercriminals in the last five years?
- If yes, how many records were compromised / stolen?
Response sent
- In 2023, what annual cybersecurity budget has been allocated to your NHS Trust?
This is not a separate budget, it is included within the whole IM&T budget
- Can you also provide your Trust’s annual cybersecurity budget for the years:
- 2022
- 2021
- 2020
- 2019
- 2018
- 2017
Not applicable. See our response to Q1 above
- In 2023, how is your annual cybersecurity budget spent:
- What percentage goes towards cybersecurity training for employees?
- What percentage goes towards technology investments?
- What percentage goes towards employee resources for your cybersecurity team?
Not applicable. See our response to Q1 above
- How many employees work in your NHS Trust?
This information is publicly available and may be reached via the following link: https://digital.nhs.uk/data-and-information/publications/statistical/nhs-workforce-statistics
- How many employed, full-time members of staff make up your NHS Trust’s cyber/infosecurity team?
We do not have a dedicated Cyber security/Information Security Team. Cyber Security and information security tasks are undertaken as part of the Business as Usual activities of the ICT Infrastructure Team and the Information Governance Team.
- How many hours of cybersecurity training are employees of your NHS Trust required to undertake every year?
Annual average is 4-5 hours per year, but varies (upwards) according to launches of additional cyber training/awareness programs.
Additionally, all new starters undertake a mandatory cyber security session, which must be refreshed every 3 years, in addition to all other cyber security training.
- Has your NHS Trust paid any ransom demands to cybercriminals in the last five years?
- If yes, how much did you pay in total?
No
- Has your NHS Trust had any patient records compromised / stolen by cybercriminals in the last five years?
No