In a world where cyber threats are becoming increasingly sophisticated, primary care remains exposed. The NHS has made significant strides at improving the digital infrastructure across secondary care, but GP practices, often operating with limited IT support and small budgets, are sometimes left to fend for themselves. The question we must ask is this: in the broader NHS cybersecurity environment, are GP surgeries the weakest link?
Unfortunately, the answer is often yes.
We’ve seen this play out before. The 2017 WannaCry attack crippled over 80 NHS trusts and hundreds of GP practices, not due to cutting-edge hacking techniques, but because of outdated systems and a lack of basic cyber understanding. Today while many surgeries have moved to more secure cloud-based clinical systems and cyber training is more widespread, the underlying risks haven’t gone away, they’ve evolved.
The Human Factor
The most common cyber threat to general practice isn’t a mysterious hacker in a darkened room, it’s a convincing phishing email and a busy staff member on a Friday afternoon.
Most data breaches in primary care are not technical failures but human ones: clicking on a malicious link, responding to a spoofed email, or downloading an attachment from an unverified source. These attacks are increasingly personalised and difficult to detect. A recent NHS England Digital bulletin showed a sharp rise in phishing attempts that mimic official NHS branding or supplier communications.
In many practices, the pace is relentless. Staff are juggling patient care, admin duties, and constant IT alerts. Under pressure, vigilance slips. Cybersecurity begins to feel like a distant IT issue rather than a clinical or operational risk, which is exactly what cybercriminals rely on.
Outdated Systems and Inconsistent Support
Despite initiatives like the Data Security and Protection Toolkit (DSPT) and NHSmail, some surgeries still run on outdated operating systems, use unsupported browsers, or rely on local servers with limited backup protocols. When a security patch is missed, or a system is overdue for replacement, the practice becomes a target.
Whilst ICBs and CSUs have improved standardisation and support, the level of cyber resilience across practices remains inconsistent. Some benefit from proactive ICB-level IT services; others depend on ad hoc contractors or internal admin staff to handle digital threats.
The Ripple Effect of a Breach
It’s easy to assume that a single breach at one surgery is an isolated issue, but this isn’t how today’s interconnected NHS operates. One compromised GP practice can become an entry point to wider systems, affecting other practices, local health teams, or even hospital links. Think about the reputational damage and patient trust erosion that can follow.
Patients trust their GP with the most intimate details of their lives. A data breach isn’t just a technical failure—it’s a betrayal of that trust.
So, What Can Be Done?
First, we need to reframe cybersecurity as a clinical safety issue, not just an IT concern. Cyber resilience should be on every practice’s risk register, discussed in team meetings, and treated with the same seriousness as infection control or safeguarding.
Second, training must evolve. Mandatory IG training is a baseline, not a solution. Staff need scenario-based refreshers, phishing simulations, and regular briefings on emerging threats which are delivered in language that makes sense to busy front-line staff.
Third, investment is essential. Cybersecurity isn’t glamorous and doesn’t always feel urgent, until it’s too late. National funding streams must ensure practices have access to secure infrastructure, accredited cyber tools, and centralised support without cost barriers.
Lastly, there’s a cultural element. We must foster a "see something, say something" mindset. Encourage staff to report suspicious activity without fear of blame.
A Collective Responsibility
GP surgeries aren’t alone in this. ICBs, IT providers like the CSUs, and NHS England all have a role to play in making cybersecurity fit for the digital age of general practice, and it is vital that practices hold these partners to account, however it is important to understand that taking action starts at ground level recognising that every receptionist, clinician, and practice manager is a potential front line in the defence against cyber threats.
Cybersecurity is no longer an optional add-on. It’s integral to patient care, continuity of services, and the future of digital healthcare. Let’s stop treating it like someone else’s problem.
Because in primary care, we are not the weakest link unless we choose to be.
By Sharon Forrester-Wild, Data Protection Officer

