
In January to May 2026, UK healthcare providers logged 264,000 attack events, against 27,000 for the whole of 2025. That is a tenfold jump in five months, according to SonicWall’s telemetry across NHS-linked sensors, and it occurred on a sector where the gap between what boards think they know and what is actually protected has never been wider.
The Long Tail of a Single Attack
The clearest illustration of what that gap costs sits two years in the past and is still unresolved. The June 2024 ransomware attack on Synnovis, the pathology provider serving South East London hospitals, exposed data from roughly a million NHS patients and forced more than 10,000 outpatient appointments and 1,700 elective procedures to be postponed. As of April 2026, South London and Maudsley NHS Foundation Trust was still processing pathology results without fully restored systems, and the incident has been linked to a patient death at King’s College Hospital. Nearly two years is not a recovery timeline any board signed off on. It is what happens when governance treats cyber resilience as an IT programme rather than a clinical safety issue.
Reactive Versus Mandated: Two Governance Models
The UK’s surge sits inside a largely reactive governance model, where boards respond to incidents and regulators tighten guidance after the fact. Abu Dhabi has taken the opposite route. Its Healthcare Information and Cyber Security standard, now in its second version, is built around six pillars, and governance is listed first, ahead of resilience, capability, partnerships, maturity and innovation. Every hospital, insurer and medical device maker operating in the emirate has to comply, and the standard explicitly frames cyber security as an organisation-wide responsibility covering people and process rather than a narrow technology control bolted onto IT. It is a mandated structure built before the incident, rather than a review commissioned after one.
Why the Stakes Keep Rising
The economics make the governance question harder to defer. Healthcare ransom demands have climbed sharply, with one widely cited industry analysis putting the average demand at $16.9 million, up from $577,800 the prior quarter, and healthcare remains one of the most targeted sectors globally, with 77 per cent of organisations reporting a ransomware attempt in the past twelve months, because attackers know disrupted care creates leverage no other industry carries. A board that treats a green status on a cyber dashboard as sufficient assurance is trusting a number it has usually never interrogated.
What Boards Should Actually Be Asking
Two different regulatory paths, one shared conclusion. Cyber governance in healthcare cannot sit exclusively with a CISO or an IT director reporting up through a technical channel. It needs a named board-level owner who can answer, in plain terms, three questions: which clinical services stop if this system fails, how long the organisation can run on manual process before patient safety is affected, and when that assumption was last tested rather than assumed. The Synnovis timeline suggests most boards do not currently have confident answers. The Abu Dhabi model suggests what building toward one actually looks like, governance treated as the first pillar of resilience rather than the last line of a post-incident report.