ChannelLife UK - Industry insider news for technology resellers
Story image

UK healthcare sector exposed to mounting ransomware risks

Fri, 28th Mar 2025

Trustwave has released a new report that highlights the significant cybersecurity vulnerabilities within the UK's healthcare sector, placing the country as the third most targeted by ransomware globally.

The study, conducted by Trustwave SpiderLabs, investigates the security challenges faced by the healthcare industry amid the sector's rapid digital transformation. The findings point to increased risks posed by the integration of sensitive patient data, dependency on legacy systems, and the use of interconnected devices.

In light of these developments, the report provides detailed insights and intelligence aimed at helping healthcare organisations enhance their cybersecurity measures. The research elaborates on attack stages and identifies areas where healthcare entities can bolster their defences.

Kory Daniels, Chief Information Security Officer at Trustwave, emphasised the critical nature of these threats, stating, "Healthcare artificial intelligence and technology adoption presents a spectrum of risks that few other industries need to navigate. The risk is not just incredibly sensitive data privacy, but human life and quality of patient care. It's not hard to see how compromised medical equipment like a ventilator or pump could lead to a wrong dose or missed patient alert that results in death. Complex supply chains, lapses in patches and credential management all have consequences too serious for anyone in the healthcare industry to ignore."

The report documents a worrying trend of increasing ransomware attacks on healthcare facilities. With 21% of all ransomware breaches aimed at public health and government healthcare facilities, the threat continues to grow. The analysis also reports that 45% of all attacks exploited public-facing applications, with 56% of these attacks targeting the Log4j vulnerability.

In addition to Log4j's exploitation, a significant portion of ransomware attacks, 51%, targeted US-based healthcare companies, while 9% of the attacks were attributed to the threat group known as Ransomhub.

Trustwave's research highlights the critical role of third-party vulnerabilities, particularly within supply chains, which threaten compliance and operational efficiency. Tackling these supply chain risks is deemed essential to achieving resilient cybersecurity within the industry.

Despite the recent release of the UK Government's plan titled 'Build an NHS fit for the Future', the plan has been criticised for lacking initiatives focused on improving cyber resilience or protecting healthcare systems from cyber threats.

The latest Trustwave SpiderLabs series on healthcare cybersecurity challenges includes extensive research reports, such as the 2025 Trustwave Risk Radar Report for the healthcare sector, and detailed examinations such as "Healthcare Sector Deep Dive: Unmasking Security Gaps" and "Healthcare Sector Deep Dive: Ransomware Trends and Impact". These documents aim to contribute to the broader discussion on enhancing security efforts in healthcare amidst mounting cyber risks.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X