A comprehensive guide to NHS network security for healthcare IT leaders: HSCN connectivity, DSPT compliance, zero trust architecture, firewall modernisation, and cloud connectivity for NHS organisations.
The NHS network security landscape has changed significantly in recent years. The shift from perimeter-based security to continuous assurance models, the growing sophistication of cyber attacks targeting healthcare organisations, and the expansion of cloud and hybrid working have all placed new demands on the infrastructure NHS organisations depend on. At the same time, the DSPT has evolved from a largely self-reported compliance exercise toward a framework that expects evidenced, ongoing security controls.
This guide addresses the questions I hear most often from NHS IT and information security leaders: what HSCN compliance actually requires in practice, how zero trust applies in healthcare environments, when cloud connectivity is appropriate and how to do it compliantly, and what modernising firewall infrastructure looks like for an organisation running a complex, multi-site estate.
The Data Security and Protection Toolkit is the NHS’s primary framework for assessing the security and information governance posture of organisations that access NHS patient data or systems. It applies to NHS trusts, ICBs, GP practices, and the technology suppliers that serve them.
The DSPT has moved toward a risk-based, continuous assurance model. The expectation is no longer that an organisation demonstrates compliance at a point in time and then moves on. Assessors expect to see evidence of ongoing controls: change management records, access governance, patch histories, incident logs, and security posture reporting that is generated continuously as part of normal operations rather than assembled before the submission window.
For network infrastructure, this has direct implications. The network is the layer through which most security controls are implemented and most evidence is generated. An NHS organisation whose network estate is well-managed and generates continuous telemetry is in a materially better position at DSPT assessment time than one where the evidence has to be reconstructed from fragmented sources across multiple vendors.
The specific areas of the DSPT most relevant to network infrastructure include asset management (knowing what is on the estate and keeping it current), secure configuration (demonstrating that network devices are configured to a defined and maintained standard), network security controls (encryption, access management, traffic inspection), vulnerability management (regular assessment and evidenced remediation), and identity and access management with multi-factor authentication for privileged and remote access. Protective monitoring – the ability to detect, log, and respond to suspicious activity – is an increasing expectation across all organisation types.
Compliance-ready infrastructure demonstrates these controls through the normal operation of the managed service, rather than requiring a separate evidence-gathering exercise before each DSPT cycle.
The Health and Social Care Network is the private network connecting NHS organisations, social care providers, and the technology companies that serve them. It is purpose-built for healthcare, which gives it specific advantages over internet-based connectivity for clinical and administrative workloads.
HSCN operates as a multi-supplier framework. NHS England sets the standards and governs the Connection Agreement that organisations must sign before connecting. Accredited Consumer Network Service Providers (CN-SPs), of which Cloud Gateway is one, deliver connectivity to organisations that need it. The CN-SP market is competitive, which has driven improvements in both service quality and pricing since HSCN replaced the single-supplier N3 model.
The HSCN Connection Agreement carries ongoing compliance obligations. Organisations must maintain their security posture in line with the requirements set by NHS England, ensure that changes to the architecture of their connection are managed and approved, and be able to evidence their compliance on request. The Connection Agreement is signed once at the organisational level and covers all sites on the connection, which simplifies multi-site compliance compared to the legacy N3 IGSoC process.
The performance characteristics of HSCN are meaningful for clinical workloads. Predictable latency, dedicated capacity, and routing optimised for NHS services mean that clinical applications perform more reliably over HSCN than they typically do over internet-based connectivity. For electronic patient record systems, clinical imaging, and real-time clinical decision support, this is not a marginal difference.
The growing adoption of cloud-hosted clinical applications raises a specific question: how does a cloud-hosted product connect to HSCN compliantly? The answer is through a cloud-to-HSCN connection delivered by an accredited CN-SP, where the CN-SP manages the private path from the cloud environment to the HSCN fabric and ensures the connection meets the requirements of the Connection Agreement. This is how healthtech companies delivering cloud-hosted products to NHS customers should be thinking about their connectivity architecture.
HSCN and internet-based connectivity are not mutually exclusive. Most NHS organisations use both, directing different traffic types appropriately. Clinical systems requiring access to NHS Spine, NHS Mail, and HSCN-connected services should route via HSCN. Corporate applications, public-facing services, and cloud-hosted tools that do not carry patient data may be appropriately accessed via internet connections.
SASE (Secure Access Service Edge) has become increasingly relevant as NHS organisations support hybrid workforces and cloud-hosted services. A SASE architecture delivers security policy to users regardless of where they connect from, applying consistent inspection and access controls whether a clinician is on the hospital site, working from home, or accessing systems from a community clinic.
The key compliance consideration when using internet-based connectivity alongside HSCN is that the security controls applied to internet-bound traffic must be appropriate for the data and applications involved. For traffic carrying patient data or accessing systems within the HSCN ecosystem, the controls need to meet the same standard as would apply within the HSCN itself. This requires deliberate architectural design and the security evidence to demonstrate it.
Zero trust is widely discussed and not always clearly defined. In a healthcare context, the core principle is that access to systems and data is continuously verified rather than assumed once a user or device is inside the network perimeter.
The traditional model – authenticate once at the network boundary, then trust everything inside – does not reflect how NHS organisations work. Staff access systems from multiple sites, home, and mobile devices. Third-party suppliers connect into clinical systems. HSCN connects multiple organisations into a shared network, which means that a compromise elsewhere on the network is not automatically contained by geography.
Zero trust addresses this by shifting security from the network perimeter to the access decision. Every connection request – from a user accessing an EPR system, a supplier system calling a clinical API, or a medical device communicating with a monitoring platform – is evaluated against identity and device posture before access is granted. Access is scoped to what is actually needed, not to the full network.
In practice, implementing zero trust in a healthcare environment involves several components that are typically adopted in phases rather than deployed simultaneously.
Identity-centric access management is the foundation. Every user needs a verified, managed identity. Multi-factor authentication is required for clinical system access. Role-based access controls need to reflect actual clinical workflows – a ward nurse’s access profile is different from a pharmacy technician’s, which is different from a consultant’s. Privileged access for administrative and emergency functions needs specific controls and audit trails.
Network segmentation separates clinical systems from corporate and guest networks, limits inter-system communications to what is necessary, and monitors east-west traffic (traffic moving within the network rather than in and out of it) for anomalies. Segmentation reduces the blast radius of a compromise: if one system is affected, the segmentation prevents lateral movement across the broader estate.
Device trust requires that access decisions incorporate the security posture of the device making the request. An unmanaged personal device accessing a clinical system from home presents a different risk profile from a managed, patched, encrypted clinical workstation on site. Zero trust access controls should reflect that difference.
Implementation typically follows a phased approach: starting with an assessment of current identity and access management, establishing the authentication and device posture infrastructure, implementing network segmentation progressively across the estate, and then adding monitoring and analytics to detect anomalies against the verified-access baseline.
Legacy firewall infrastructure in NHS environments often predates the current threat landscape by a significant margin. Appliances that were fit for purpose when initially deployed may now lack the inspection capabilities, update cadence, and management visibility that the current environment demands.
The indicators that firewall infrastructure needs modernising are consistent across the organisations I work with: clinical applications experiencing unexplained performance degradation, visibility gaps that make it difficult to answer questions about what traffic is doing on the network, management overhead that absorbs significant engineering time, and gaps in evidence that surface during DSPT assessments or IT health checks.
Next-generation firewall capabilities that are relevant for NHS environments include deep packet inspection of both unencrypted and SSL/TLS traffic, intrusion detection and prevention, application-layer visibility and control, and integration with threat intelligence feeds that are updated continuously. For organisations managing multiple sites, centralised policy management is essential – maintaining firewall rules manually across dozens of sites is both error-prone and difficult to evidence.
Firewall as a Service (FWaaS) is increasingly the appropriate model for NHS organisations modernising their security infrastructure. Rather than maintaining appliances at each site – with the hardware refresh cycles, patch management, and configuration management that entails – FWaaS delivers firewall capabilities from a cloud-based platform, with policy managed centrally and updated continuously. The evidence that DSPT requires – configuration history, policy changes, incident logs – is generated as part of the service.
Medical device compatibility is a specific consideration in clinical environments. Older medical devices may use legacy protocols or have specific network requirements that need to be accommodated alongside modern security controls. Firewall policy needs to be designed with these devices in mind from the outset, rather than discovering the conflict after deployment.
Cloud adoption in NHS environments has accelerated significantly. Electronic patient record systems, diagnostic imaging, analytics platforms, and clinical decision support tools are increasingly cloud-hosted. The connectivity between those cloud environments and the HSCN, and between cloud environments and on-premises clinical systems, is where many of the most important infrastructure decisions now sit.
Private connectivity to cloud providers – AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect – provides dedicated paths between cloud environments and the wider estate, with the performance predictability and security boundary controls that clinical applications require. For high-volume workloads such as imaging data or AI-assisted diagnostics, internet egress is neither the most performant nor the most governable option.
The compliance question for cloud-hosted NHS applications is not just about the application itself, but about the full data path. Where does the data travel? What controls apply at each boundary? Can those controls be evidenced? For a healthtech company delivering a cloud-hosted clinical application to NHS customers, the DSPT assessment of their NHS customer will include scrutiny of the supplier’s infrastructure. The ability to provide evidence of governed, compliant connectivity is increasingly a commercial expectation from NHS procurement teams.
For NHS organisations evaluating cloud-hosted clinical tools from suppliers, the questions to ask about the supplier’s connectivity and security architecture are straightforward: how does the application reach HSCN, who is the accredited CN-SP, what are the security controls at the cloud boundary, and how is the evidence of those controls made available?
The NHS organisations I see managing their network security well share some consistent characteristics. They have a clear picture of their estate – what is on it, how it is configured, and how it connects to HSCN, cloud environments, and third-party systems. They generate compliance evidence continuously through the normal operation of their infrastructure, rather than assembling it before each DSPT cycle. They have visibility across the full estate in one place, not fragmented across multiple vendor portals. And they have a managed service relationship with a provider who understands the NHS compliance environment and can evidence their own posture when asked.
The combination of HSCN connectivity, zero trust access controls, managed firewall capability, and private cloud connectivity – delivered under one operating model with one team generating the evidence – is the architecture that consistently produces the best outcomes for NHS organisations navigating this environment.
Cloud Gateway works with NHS trusts, ICBs, and healthtech suppliers on the connectivity, security, and compliance infrastructure that underpins this architecture. For more on how we work in healthcare, see our Healthcare sector page and Business Connect: HSCN.