-
Healthcare
-

Why Russia's Grey-Zone Calculus Now Runs Through The Hospital Ward

By
Distilled Post Editorial Team

The scenario security officials in Whitehall have started rehearsing does not begin with a missile. It begins with a login screen that will not load, a pathology lab that cannot process blood samples, and a duty manager somewhere in England discovering, an hour into a night shift, that nobody can say with confidence what has failed or why. That was roughly how the Synnovis ransomware attack unfolded in June 2024, when a criminal group knocked out pathology services across several London hospitals, forced the cancellation of more than ten thousand outpatient appointments, and contributed, investigators later confirmed, to a patient's death through delayed blood test results. It was not a state operation. But it demonstrated, with unwelcome clarity, what a determined actor can achieve against a health system that has digitised faster than it has secured itself.

That distinction between criminal and state actor is becoming harder to lean on for comfort. Western intelligence assessments now describe Vladimir Putin weighing a range of options against Nato states that fall below the threshold triggering a collective military response, from harassment of diplomats to sabotage of ports and warehouses moving equipment to Ukraine. Deniable cyber-strikes on national infrastructure sit near the top of that list, and the logic is straightforward. Russia has already shown its willingness to hit British companies, disrupting production at Jaguar Land Rover and halting online trading at Marks & Spencer, without crossing into anything resembling an act of war. A health service outage carries a political cost that a factory shutdown does not, and it can be inflicted with far less risk of unambiguous attribution than a physical act against a person or a border.

The NHS meets the definition of critical national infrastructure precisely because an attack on it produces harm that is immediate, visible and difficult to separate from ordinary operational failure. UK healthcare recorded a roughly tenfold rise in cyber incidents through the early part of this year, according to sector monitoring, much of it exploiting legacy systems and unpatched clinical software that cannot simply be taken offline to fix without risking patient safety. The National Cyber Security Centre has been explicit that severe attacks on sectors including health can no longer be treated as preventable in every case, and has told operators to plan instead for continuing to function while under attack and recovering from it, a shift in emphasis that itself signals how the threat picture has changed. Parliament's Cyber Security and Resilience Bill, intended to modernise the decade-old NIS Regulations that govern essential services including the NHS, was carried over into the new session in May rather than passed, which leaves the legal architecture for enforcing supplier-level resilience still catching up with the risk.

Layered onto this is a structural dependency that the NHS has chosen deliberately, in pursuit of productivity gains rather than resilience. The Federated Data Platform consolidates patient data across trusts through a single vendor relationship, ambient voice technology is being folded into clinical documentation, and NHS England's dissolution into the Department of Health and Social Care has occurred at precisely the moment this centralisation was accelerating, thinning out the institutional memory built up since the WannaCry attack nearly a decade ago. None of this makes the NHS a more attractive target than the energy grid or financial system. But it does mean that where the health service sits within the government's own critical infrastructure planning has to reflect strategic risk, not only the operational and financial logic that has driven digital transformation until now.

For NHS leaders and the ministers overseeing them, the practical implication is not alarm but sequencing. Supplier assurance, board-level incident response exercising and isolated recovery environments cannot remain items on a five-year strategy document while the geopolitical timeline for a hostile test of Western resolve is being measured, by intelligence officials, in months. A health system that has spent a decade learning to survive ransomware criminals is about to discover whether those lessons transfer to an adversary with different incentives and considerably more patience.