BIC Sidebar Button Advert
LEADER Ad_Poet Systems
M-SParc_Sidebar Button Advert - 450 x 460

CS Connected Button Advert_white logo

Button Ad_Cyber Wales

button Ad_Poet Systems

Route 3 - Sidebar Button
29 August 2024

Simple Housekeeping Can Protect Healthcare Systems From Cyber Failures


Written By:

Rachael Medhurst
Senior Lecturer in Digital Forensics and Cyber Security
University of South Wales

The issue surrounding Crowdstrike cybersecurity software demonstrated how an IT update can cause havoc. It shows how vital our computer systems are to the everyday operation of systems we all rely on.

One glitch in the update caused worldwide problems, hitting, among others, trains, shops, airports and pharmacies – with airlines forced to cancel flights and some GP surgeries in Britain affected.

While this technology was introduced to enhance efficiency, it is only when things go wrong, and the failures impact millions of people, that we ask serious questions about how good the systems really are.

Although the Crowdstrike problem wasn’t a criminal issue, it did show how a problem with vital computer systems – either through criminal intent or expert oversight – can have a major impact.

For our health systems, making sure they are free of problems is vitally important, and one that needs to be taken incredibly seriously by those who operate them.

As one commentator noted about our increasingly connected world: “The Internet of Things (IoT) is integrated with medical devices, enabling improved patient comfort, cost-effective medical solutions, quick hospital treatments, and even more personalised healthcare.”

Great as this is, this connectedness also causes many concerns, which were put into sharp focus by a statistic which was recently revealed by a systems expert.

According to Yaroslav Goortovoi, a Technical Writer at software specialist Altoros, 46% of medical IoT devices have a vulnerability.

This means that almost half of the machines which we may rely on for our medical safety could be at risk from hackers, who could access our data, impact our wellbeing, or affect the operation of our healthcare systems.

It would be great if this 46% figure just painted a picture of a worse-case scenario – but, unfortunately, we have seen what impact that malign influences can have on healthcare systems.

In May 2017, in what is known as the WannaCry attack, major issues were caused by a ransomware attack on the NHS – when a criminal group encrypted healthcare systems and files, then demanded a ransom in exchange for details of how to return the systems to normal functioning.

This impacted more than 80 of the UK’s NHS Trusts and involved the failure to carry out a software update, which was then used by hackers as a way to get into the systems.

According to an NHS spokesperson “due to the unpatched operating system, this has infected more than 230,000 computers in at least 150 countries”. It led to an estimated cost of £92 million to fully recover.

Further hacks have seen phishing emails used to access healthcare systems, with others leading to the cancellation of potentially life-saving operations, patient data sold for profit on the dark web, and thousands of appointments cancelled.

The need for those operating in the healthcare sector to take systems security seriously is there for all to see, but some research has suggested that the warnings are not heeded.

Statistics from software industry specialists Capterra found that less than half (43%) of health practices say they always change default passwords on connected medical devices, and less than a third (32%) always update them when a patch is available.

These figures highlight that there is large part of the healthcare sector that is not actioning basic security recommendations, which ultimately leads to increased vulnerabilities and susceptibility to cyber-related attacks.

By following these basic security mechanisms – such as regular updates, using patches, changing default passwords, carrying out regular audits, risk assessments, regular training, and competence testing of every employee using the devices – those who use these systems will be able to further enhance the security of the industry and help to protect it against the dangers of widespread failures.

The Wannacry attack and the recent Crowdstrike debacle show how vital it is to learn lessons from these episodes, otherwise we’re bound to repeat them.



Podcast Thumbnail_TECH

Columns & Features:


6 May 2026

1 April 2026

20 March 2026

Related Posts:

Business News Wales //