Defending the NHS Against Cyberattacks with Matthew Gould
Matthew Gould, former national director of digital transformation for the National Health Service (NHS) for England, dives into the challenges of defending the NHS from a wave of cyberattacks aimed at exfiltrating patient data.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Matthew Gold, who has a lot of experience working on cybersecurity issues in England, and particularly the National Health Service.
And if you've been following things lately, well, the National Health Service in England is under a steady stream of cyber attacks. And we're gonna get into what can we learn from this and maybe what should we be doing elsewhere in healthcare organizations? 'cause there's probably more of this to come.
Matthew, welcome to show. Thank you very much for having me, Mike. Alright.
For those who don't know you and are not familiar with what's going on, kinda lay the land here for us, but, um, we've seen this wave of attacks and I think it's becoming a pattern. Yeah. Um, so look, I, um, for, for several years I was the chief executive of what's called NHSX, which was the, the body in the NHS tasked with digital transformation.
But I also, um, carried or owned the, the cyber risk for the National Health Service. So, um, I spent a lot of my time and, uh, my sleepless nights thinking about, um, how, uh, the, the levels of vulnerability, uh, to cyber attack and what we could be doing about them, and particularly how we could ensure that, um, cybersecurity wasn't a, a, a vector to undermine public confidence in the, the sort of information sharing that we need to happen. Uh, if we are going to deliver maximally efficient, effective public services, It seems like we have little control over the attackers, so they're gonna just do what they're gonna do.
So what should organizations like the NHL be doing to kind of make their environments more resilient to these attacks so that we don't lose that confidence? So look, I think you're right. The first thing is these attacks are not going to go away.
They're clearly a fact of life, and any large organization, particularly, uh, organizations with a a, a pretty serious attack surface can expect to be, um, constantly bombarded and attacked. Uh, and so the question is not how do you make yourself hermetically secure, but what can you do to mitigate any damage to make sure that your crown jewels are properly protected and that the, the confidence that you need in your users and customers to, to underpin the system is preserved despite the, the, the wider security environment. And I think it comes down to several things.
I mean, first of all, and this is just the sort of inescapable fact of life for everyone online, is there are certain key basic things that everyone should be doing in terms of good cyber hygiene, in terms of best practice, in terms of making sure, for example, that, um, you are controlling your accesses, making sure that the, the really basic elements are in place that you don't have an open door for attackers. And in the UK there's a program called Cyber Essentials, uh, which is a government backed program, uh, supported by the National Cybersecurity Center. Um, that is really, uh, an accreditation that you are doing those basic things, right?
I think secondly, you need, uh, to create cultures of secure practice where people understand why it's important they don't, for example, click on the link that looks a bit weird, um, and potentially open up a, um, a hazard for the wider organization by doing so. But then there's a third element, which I think is really important in healthcare, which is to be really careful with people's personal health data. Because if you are a patient of the NHS, if you are a patient of any hospital, you are really sensitive to the idea that people who aren't authorized or people with malign intent might have access to your health data, like financial data.
It's something people are really, uh, have a really low threshold of tolerance for, um, misuse or, um, it, it, it going astray. So I think particularly when you get to, um, looking at sharing health data, health health data across different health entities between, um, health and other sectors, you need to have in place really strong, um, technologies, structures, uh, systems and culture to make sure that when you do that data sharing, it's done, it can be done in a way that gives confidence to the people whose data it is. Did we kind of fall into a trap where somehow or other organizations seem to think that the data they collect is theirs, when in actuality they're kind of stewards for data that actually belongs to somebody else?
And we have to have a different mindset when we think about it in those terms because suddenly it's a trust and it's a responsibility versus something that I'm just trying to protect. And we're the only ones that are affected if something goes wrong. Yeah.
So, um, I mean, well, interestingly, the UK still follows the basic, uh, GDPR EU model, which doesn't have a concept of data ownership. It has a concept of data controllership, uh, which is in the UK health system, uh, primarily the the general practice doctors, the the family doctors in primary care. Um, but despite that, the reality is that people feel they own their own health data.
They feel strong sense of, um, uh, rightful authority over it and will react very badly if they feel that their data is being in any way treated with carelessness or, um, proper security. And one of the things we find over and over in the UK is well-intentioned schemes to share data, uh, um, crash on the rocks of concern by people about their, their own privacy. So if we, we are, I'm really clear they've done the jobs, I've done that.
If we want to deliver effective health services, effective public services, you need to be able to share data safely and appropriately. You need to be able to share it between primary care and secondary care. You need to be able to share it between, um, health and social care, for example.
Um, but you can't do that if you don't do it in a way which keeps public trust with you. So I think it starts, we started with cybersecurity, but actually it comes down to how do we do data sharing that will allow us to offer really good, effective, efficient services in a way that keeps public trust. This is, this is existential as far as I can see for delivering effective health services.
Is the conversation among cybersecurity teams starting to change where you hear a lot more about the phrase, you know, cyber resiliency. Um, what does that exactly mean though? I mean, am I trying to just limit the, the scope of an attack?
Or am I trying to prevent an attack? Well, I think resilience comes down to, to some degree, to all of that. But I think it starts from the basis that you can't, uh, deliver efficient, in this case, efficient health services without being, while being a sort of hermetically sealed fortress for data, which means in turn that there will always be an element of, um, risk of attack.
And therefore it's not just about sealing yourself off from the world. It's about ensuring that were the worst to happen as far as possible. The things that most needed to be protected have maximum levels of protection and the things that are, um, most need to be able, the services that most can need to be able to continue to be offered, for example, um, emergency care can still function.
Um, so cyber resilience is an incredibly important concept in healthcare. Um, and really, I mean, that's why, I mean, some of my continuing involvement in this space is looking at technology which can allow data sharing or, um, the use of data, particularly across different institutions with the level of confidence that's needed. So I'm working with a, a, a US startup called, uh, duality Technologies who developed, I, I mean really strong trustworthy techniques including, um, uh, homomorphic encryption to allow, um, data to be interrogated safely, but in a federated way.
And that's the sort of technology I think that can give confidence to be able to share data that keeps the public with you. We of course, are all tracking the rise of ai. What impact do you think this is gonna have?
Because it seems like we're in some sort of arms raise here. The good guys are clearly gonna use ai, but so are the bad guys and is that gonna change the nature of the threats that we face? Uh, uh, we are always in an arms race.
I mean, I think cybersecurity has been an arms race from the start. Um, and I think AI turbocharges that, I don't know, I suspect it will create both opportunities for attack and opportunities for defense in ways we haven't even thought about yet. It will speed everything up.
Um, it will, um, certainly I think for those, for the unprepared will present, um, uh, a serious new angle or depth of threat. But, um, it fundamentally doesn't change what's needed, which is good cyber practice, effective defense, but also the ability to share data across institutions with real confidence based on the technology that underpins it. Do you think we need some sort of, particularly in the healthcare space, maybe something that feels like a, a Manhattan project for improving cybersecurity?
Because it is, touches everybody. It is such a broad thing and that the data that is in those systems is probably more valuable than even what's in my banking system. So, you know, what do we collectively all need to do together that's gonna be different?
So it's a really good question, and I think like financial data, health data is incredibly important to the people whose data it is. Unlike the financial sector which has invested huge amounts into cybersecurity, the health sector is always cash strapped. And, um, I would say certainly in the UK hasn't had the level of investment that the financial sector has had.
So, um, and then on top of that, and I don't know if it's the same in the US but certainly in the uk you have real issues around a multiplicity of legacy systems, data sharing across numerous systems, both within and between institutions, all of which makes the problem much more complex. So what can we do differently? I mean, firstly, there is an irreducible amount of investment that's required to do this properly.
Um, secondly, um, I've always been, um, a fan of the approach where the good guys work together to share what they know and create a, as far as possible, a sort of common approach to, uh, to the threat. And it's one of the reasons why, um, we set up the National Cybersecurity Center in the uk was to allow a sort of safe pooling of what people know, um, but together with, with, with governments and the agencies. And then the third thing is, and it does come back to data sharing, it's finding ways and technologies to allow data to be shared between healthcare institutions with confidence.
Because until you can do that, you are never going to be able to deliver the services that are needed. In the absence of all that though, what's your best advice to the average cybersecurity IT team working in the healthcare sector? It's really good.
It's a really good question. I mean, I think number one, um, they need to be friends with their board and boards need to be on top of the cyber risk. Um, if a board isn't asking questions, interrogating cyber resilience and key indicators around cybersecurity, they're not doing their job.
I think number two, and it's the same theme of senior leadership, is making sure that they translate the threat from the technical to language that their chief executives and C-Suite leadership understand. 'cause I think one of the continuing issues around cybersecurity has been, it's seen as an issue for the IT guys in the basement when it has to be an issue for leadership. I think the third thing is just grind through the basics.
Make sure that the checklist of things that are needed in the UK SI cyber essential scheme is constantly met and remet. And that's a never ending task. Uh, it sounds straight forward.
It's not, it's not glamorous, it's not sexy, but it, uh, it, it is the foundation of cyber defense. And then finally, um, and this is where I think it starts to be a bit more interesting, is look at what technology can allow you to deliver the services that are needed. Um, how can you share data with the confidence that needed that's needed based on technological solutions that's proably secure.
All right, folks, you heard it here. I think we all know the bad guys are not going away anytime soon. The only question is, is how are we gonna respond to it?
Hey, Matthew, thanks for being on the show. It's been a real pleasure talking to you. Thanks, Mike.
All right, I'm back to you guys in the studio.