This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.

Search the website
Thought Leadership

Healthcare, resilience and critical national infrastructure: are you prepared for disruption?

Picture of Justin Barrow
Passle image

Healthcare sits at the heart of the UK’s critical national infrastructure. This is the first in a series exploring what that means for organisations across the sector and why cyber resilience has become a board-level priority.

What is critical national infrastructure?

Critical national infrastructure (CNI) refers to the critical assets, facilities, systems, networks, processes and essential workers needed to keep essential services operating. In practice, these are the parts of national infrastructure whose loss or compromise could have a major detrimental impact on the availability, integrity or delivery of essential services, including where disruption could lead to significant loss of life or casualties. It also includes infrastructure whose compromise could significantly affect national security, national defence or the functioning of the state. 

Healthcare is one of 13 designated CNI sectors. It does not operate in isolation - it depends on reliable power, water and telecommunications, all of which are CNI sectors in their own right. A failure in one sector can quickly cascade into another, making healthcare resilience inseparable from the resilience of the wider ecosystem.

Why does this matter?

The healthcare sector faces a perfect storm: increasingly sophisticated cyber threats, complex supply chains, resource constraints and growing reliance on digital and AI-enabled technologies. The question is no longer whether organisations can prevent every disruption, but whether they can keep essential services running when one occurs.

The National Cyber Security Centre has highlighted that a serious cyber incident in healthcare is not just a systems failure. It can delay treatment, disrupt critical services and put patient safety at risk. The 2024 attack on pathology provider Synnovis, which forced the cancellation of thousands of operations and appointments across London NHS Trusts, was a stark reminder of how quickly a cyber incident can translate into real-world impact on patients. 

Who does this affect?

Healthcare CNI is not confined to hospitals or NHS organisations. It spans a wider ecosystem of public bodies, private providers and suppliers whose services, systems and infrastructure support patient care.

  • Public sector: NHS England, NHS Trusts, Integrated Care Boards and other public healthcare providers are subject to specific cyber security requirements, including the NHS Data Security and Protection Toolkit and the National Cyber Security Centre’s Cyber Assessment Framework.

  • Private sector: Technology vendors, independent healthcare service providers, medical device manufacturers, telecoms providers,  and consumables suppliers  all sit within the healthcare supply chain. Their resilience is inseparable from that of the organisations they serve.

The regulatory landscape

The regulatory framework is evolving. Healthcare organisations already navigate a mix of cyber, data and sector-specific requirements, including the NIS Regulations 2018, NHS cyber assurance frameworks (e.g. the NHS Cyber Security Charter for Suppliers), NCSC guidance and data protection obligations. Looking ahead, the Cyber Security and Resilience Bill, which is currently progressing through Parliament, is expected to broaden the UK’s cyber resilience regime, while the EU’s NIS2 Directive remains relevant for organisations operating in or supplying into the EU.

What’s next in this series

Over the coming weeks, we will explore the following issues in more detail:

  1. Connected medical devices – Connected devices can present unique cyber security challenges due to long operational lifecycles, legacy systems and restrictions on patching. This article will examine why traditional IT security approaches often fall short, and why a device-related security incident can quickly become a patient safety and operational resilience issue. 

  2. Supply chain resilience – Healthcare organisations’ growing reliance on external suppliers creates dependencies where a single failure can disrupt patient care. This article will look at how organisations can strengthen resilience through supplier due diligence, contractual protections and assurance frameworks, and the evolving regulatory landscape, including proposed supply chain duties and powers to designate “Designated Critical Suppliers”. 

  3. Telecoms resilience – Communications infrastructure underpins almost every aspect of modern healthcare delivery. This article will explore where telecoms dependencies create pressure points for critical services and patient care, the practical steps healthcare organisations can take to build resilience, and the key cyber, telecoms and data protection requirements to navigate as the regulatory landscape evolves.

  4. AI risk in healthcare – AI is changing the cyber risk profile for healthcare organisations. This article will consider how AI can increase the speed, scale and impact of cyber incidents, why providers need to map where AI is developed, deployed and used across their operations, and what safeguards are needed to protect against vulnerabilities. It also looks at the other side of the equation: how AI can support threat detection, prevention and resilience.

As part of this series, Burges Salmon, KPMG and techUK will bring together senior leaders from across the healthcare sector on 4 November 2026 to discuss these challenges in an interactive workshop covering cyber and AI, supply chain assurance, the legislative landscape, recovery planning and clinical safety.

For queries about the event, or advice on the content of this article, please contact Hamish Corner, Lucy Pegler, Justin Barrow or another member of the Burges Salmon team. 

This article was written by Fraser Campbell and Justin Barrow

Related services

See more from Burges Salmon

Want more Burges Salmon content? Add us as a preferred source on Google to your favourites list for content and news you can trust.

Update your preferred sources

Follow us on LinkedIn

Be sure to follow us on LinkedIn and stay up to date with all the latest from Burges Salmon.

Follow us