ICB consolidation: what it means for network resilience, security, and system interoperability

NHS England is consolidating Integrated Care Boards from 42 to around 25-28. For ICBs navigating that transition, the infrastructure implications are significant. Here is what to plan for.

The NHS is consolidating its Integrated Care Board structure, reducing the number of ICBs from 42 to somewhere between 25 and 28 through clustering and eventual mergers. The rationale is clear: reduce duplication, consolidate leadership, and create larger, more coherent system footprints that can drive place-based care more effectively.

What is less visible in the policy conversations is the infrastructure underneath. Merging organisations in health is not simply a governance exercise. It combines technology estates, network architectures, data flows, and compliance obligations that were designed and managed independently. Getting that integration right determines whether the efficiency gains the consolidation is designed to deliver are actually realised.

A parallel with local government devolution

What is happening across ICBs closely mirrors the local government devolution experience of the past decade. Combined authorities, elected mayors, and pooled budgets aimed to give regions more control and create more joined-up services. The Greater Manchester Health and Social Care Partnership was an early forerunner of this model, bringing NHS and local government under shared accountability.

The lesson from those devolution programmes is consistent: governance can be restructured relatively quickly, but the digital and infrastructure layer takes longer and is often underplanned. Inadequate focus on data sharing, network interoperability, and shared platforms undercut the early ambitions of several combined authorities. ICB consolidation faces exactly the same risk.

The regional picture

Consolidation is underway across all NHS England regions, with clusters forming at different paces and in different configurations. The Midlands has the most complex consolidation, with eleven ICBs reducing to five or six. The South East, East of England, and South West are each seeing meaningful reductions. London and the northern regions are less dramatically affected but are not untouched.

The practical effect is that ICB digital and infrastructure teams are simultaneously managing live services, preparing for organisational change, and trying to plan a technology estate that does not yet have a final shape.

Three infrastructure considerations that cannot wait

Interoperability across merged estates

Merging ICBs operate across multiple Electronic Patient Record systems, legacy applications, cloud services, and supplier-delivered platforms, each with different configurations, standards, and integration requirements. Creating genuine interoperability across a combined estate requires a connectivity and security layer that can bridge those differences without forcing the replacement of systems that are still fit for purpose.

A phased approach is usually necessary: connecting organisations through a common fabric first, then rationalising systems over time as the merged entity’s architecture becomes clearer. The risk is attempting to solve the systems question before the connectivity question, which tends to delay both.

Security across a changing threat surface

Where there was previously a single organisational perimeter, consolidation creates a federated environment with overlapping access needs, shared data flows, and users from multiple predecessor organisations needing access to the same systems. The attack surface expands significantly during this period.

Consistent security policy across a merged estate is harder to maintain than within a single organisation. Policy gaps at the join between two estates are where attackers look. Zero trust network access, where every connection is verified against identity and device posture rather than inherited from the network position, is particularly valuable during consolidation because it enforces consistent controls regardless of which predecessor organisation’s systems a user is connecting to.

Governance and accountability in shared services

As ICBs span larger geographies and populations, the questions of who controls what data, who is accountable for access governance, and how compliance obligations are met across a merged entity become materially more complex. DSPT obligations, HSCN Connection Agreement requirements, and the evidence expectations that come with those frameworks do not pause for organisational restructuring.

The consolidated ICB inherits the compliance history of its predecessors. Where that history includes gaps, those gaps become the merged organisation’s problem to resolve. A managed service that generates compliance evidence continuously, rather than requiring it to be assembled before each assessment cycle, simplifies this significantly during a period when teams are already stretched.

The infrastructure investment case

The efficiency case for ICB consolidation rests on reducing duplication and creating more coherent operating models. That case only holds if the infrastructure underpinning the merged organisation is designed for scale. Networks that were adequate for a single ICB may not be adequate for a combined system serving a significantly larger population across a larger geography.

The investment in network modernisation, managed security, and operational assurance is not a cost that sits outside the consolidation programme. It is part of what makes the consolidation work. ICB leaders planning the transition should treat digital infrastructure as a first-order consideration alongside governance and workforce, not something to address after the structures are settled.

Cloud Gateway works with NHS organisations on the connectivity, security, and operational assurance layer that supports integration at scale. For more on how we work across the healthcare sector, see our Healthcare sector page.

Related Articles

Want to know more about how we work?