-
Healthcare
-

Britain's Missile Stocks Are Not The Only Thing Running Low

By
Distilled Post Editorial Team

When the Wirral University Teaching Hospital NHS Foundation Trust declared a major incident this year, the language was clinical and the consequences were not. Outpatient appointments cancelled, patients turned away unless facing genuine emergencies, staff reduced to systems that would not respond. It was one entry in a pattern that has become almost routine. Inc Ransom, a ransomware group with documented links to Russia, has claimed breaches of NHS Scotland and of the Alder Hey Children's Hospital Trust, one of Europe's largest paediatric hospitals, allegedly extracting years of patient and procurement records. SonicWall's telemetry recorded roughly 264,000 intrusion attempts against UK healthcare networks between January and May this year, against 27,000 for the whole of 2025. No other sector it monitors has seen anything close to that acceleration.

This week's reports of Russian threats against Britain, following Andy Burnham's pledge to help Ukraine produce its own long-range missiles, sit inside a wider pattern that Whitehall now takes seriously: a rise in hybrid attacks across Europe aimed at states supporting Kyiv, ranging from cyber intrusions to drones and arson at sites linked to the war effort. The public conversation about this threat has concentrated almost entirely on Nato's eastern members, on Patriot interceptor shortages and on whether Moscow might test alliance resolve with a limited strike on a Baltic state. Britain's own most exposed civilian institution rarely enters that conversation, despite already absorbing the kind of pressure the threat assessments describe.

The NHS did not need Moscow's help to become an attractive target. Legacy infrastructure, unpatched systems and a sprawl of connected medical devices have made it structurally vulnerable for years, a fact underlined by WannaCry's disruption of roughly nineteen and a half thousand appointments in 2017. What has changed since is not the underlying weakness but the value of what sits behind it. The Federated Data Platform, still working through governance disputes over its Palantir contract, is consolidating patient data at national scale. Through discussions, ambient voice technology is becoming more widespread. Trusts are being asked to run more of clinical life through networked systems than at any point in the NHS's history. Each of those initiatives widens the surface a hostile state or its proxies can probe, and none of them was designed with a wartime threat model in mind.

Parliament has moved, cautiously. The Cyber Security and Resilience Bill, introduced last November, would bring roughly a thousand service providers, many of them NHS suppliers, into a regime requiring stronger defences and faster incident reporting. That is a sound response to a threat picture that was already deteriorating before this week's headlines. What it does not resolve is money, and money is where the argument now collides with the calendar. John Healey delivers his first Budget as Chancellor on 28 October, inheriting a defence investment plan with a reported £4.7 billion shortfall and a manifesto commitment to lift defence spending toward 3% of GDP by 2030. The King's Fund has already warned that drawing defence spending from NHS capital budgets would delay hospital building and equipment investment, exactly the categories that fund the infrastructure upgrades cybersecurity depends on.

That is the choice hiding inside next month's fiscal statement. A government preparing the country for a more hostile security environment has strong reason to spend more on conventional deterrence. It has equally strong reason to treat the NHS's digital estate as part of that same security perimeter, not as a domestic spending line competing against it. Ministers who frame resilience narrowly, as missile stocks and troop readiness, will have answered only half the question Moscow's hybrid tactics are designed to ask. The other half is already being tested, quietly, in trust IT departments that have spent this year fighting off ten times the intrusion attempts of the year before. Whether the Budget treats that as a coincidence or a warning will say a good deal about how seriously Britain has understood the threat it now says it is facing.