Third-party applications are the dominant attack vector in NHS cyber incidents. This piece covers the scale of the risk, the real cost of breaches, and how NHS organisations can build the visibility and controls to manage it.
Healthcare organisations operate in an increasingly interdependent technology environment. NHS trusts today work with a complex ecosystem of third-party applications – Electronic Patient Records, Patient Engagement Portals, diagnostic devices, AI-enabled clinical tools, and the wide range of supplier-built systems that connect into those environments. Each integration is a potential entry point.
That dependency is not going away. The clinical and operational benefits of connected systems are real, and the NHS’s digital ambitions require more integration, not less. But the security implications of that ecosystem deserve proportionate attention. The evidence is clear: third-party application security is now one of the most significant cyber risks NHS organisations face.
Third-party connected systems have been implicated in a significant proportion of serious NHS cyber incidents. SC Media reported that 90% of the ten largest healthcare data breaches in 2022 were tied to third-party vendors. More than 70 NHS trusts have been affected by cyber attacks in recent years, including NHS Dumfries and Galloway, University College London Hospitals, Southampton, King’s College Hospitals NHS FT, Guy’s and St Thomas’ NHS FT, and the CareNotes attack that left mental health trusts unable to access patient records.
The consequences extend well beyond systems and data. Surgical procedures have been cancelled. Outpatients turned away. Clinicians left without access to records at the point of care. In the most severe cases, patients have died as a direct result of cyber attacks – specifically due to the inability to carry out critical blood tests when systems were unavailable.
The mechanism in most of these incidents is consistent: a third-party application with access to NHS systems becomes the entry point. Whether through poorly managed APIs, outdated libraries, inadequate patching processes, or social engineering of supplier staff, the trusted third party becomes the weak link.
The assumption that inaction is cheaper than investment does not hold in healthcare cyber security. The financial, operational, and reputational costs of a breach consistently outweigh the cost of proactive protection.
The Wirral University Teaching Hospital NHS Foundation Trust provides a concrete recent illustration. A 2025 analysis found that a cyber attack contributed approximately £3.7 million to the trust’s overall £14.7 million forecasted deficit. Beyond the financial impact, patient wait times extended to a 174-day referral-to-treatment time in the months following the attack, compared to 90 days immediately prior. That is not an abstract metric – it represents real patients waiting significantly longer for care.
When the full cost of a breach is quantified – system recovery, regulatory obligations, patient notification, clinical disruption, and reputational damage – the investment case for proactive protection is straightforward.
When an organisation integrates with an external system, it opens a new path into its environment. Many third-party vendors are security-conscious and well-governed. Not all are. And even reputable suppliers can introduce vulnerabilities through the software they ship, the libraries they depend on, or the staff who manage access on their behalf.
The critical point is that third-party risk is not something that can be assessed once at procurement and set aside. Applications change. Libraries are updated (or not). Supplier staff change. APIs evolve. The risk requires ongoing visibility and governance, not a one-time due diligence exercise.
NHS organisations that are managing third-party risk effectively tend to share a few characteristics.
They have strengthened their procurement policies to embed security assessments earlier in supplier engagement, requiring evidence of security practices before integration is approved rather than after. They have introduced tighter controls around how third-party applications connect to core systems, limiting the scope of access to what each application genuinely requires.
Beyond procurement policy, they have built the technical foundations to inspect, control, and contain third-party application behaviour in production. Zero trust principles applied to supplier integrations mean that even trusted third parties are granted access only to the specific systems and data they need, with that access continuously verified rather than assumed. Network segmentation limits the blast radius if a supplier-connected application is compromised – containing the incident rather than allowing lateral movement across the estate. And real-time visibility into application traffic means anomalies in third-party behaviour are detectable before they escalate.
The combination of policy and technical controls is what distinguishes organisations that contain incidents quickly from those that experience prolonged disruption.
The network infrastructure underneath NHS systems plays a central role in third-party risk management. It is the layer through which supplier traffic flows, where policy can be enforced consistently across all connected services, and where visibility into application behaviour is generated.
A managed network platform that provides segmentation, policy-based access controls, and real-time traffic monitoring gives NHS teams the technical foundation to manage third-party risk at scale – without requiring each supplier integration to be individually re-architected. Crucially, it supports zero trust principles across the full supplier ecosystem, ensuring that trusted status is continuously earned rather than permanently assumed.
Cloud Gateway provides this layer for NHS organisations, delivering the connectivity and security controls that underpin supplier integration without compromising the agility that clinical and operational teams need. For more on how we work with NHS trusts, see our Healthcare sector page and our Protect capabilities.