Cybersecurity

Published on: 27th January 2017 | Updated on: 12th August 2026

Cybersecurity is about protecting data, systems and networks from online threats. Effective cybersecurity is essential for every pharmacy because cyber attacks can disrupt services, compromise sensitive information and affect patient care.

Cyber criminals increasingly target organisations of all sizes. Ransomware attacks remain a significant threat, and incidents across the health sector have shown how cyber attacks can have serious operational, financial and reputational consequences. Pharmacy owners and teams should take practical steps to protect their systems, patient information and business continuity.

Ten steps to improve cyber security

We recommend that pharmacy teams review:

Templates and policies

Supporting organisations

Several organisations provide guidance and support to help health and care organisations strengthen cyber security.

National Cybersecurity Centre (NCSC)

The NCSC is the UK’s national technical authority for cyber security. It provides guidance, alerts, practical tools and advice for organisations, including health and care providers.

NHS cyber and data security services

NHS cyber teams provide:

  • cybersecurity alerts and incident information;
  • cybersecurity guidance and resources;
  • training and awareness materials;
  • incident reporting arrangements; and
  • specialist cybersecurity services to support the health and care sector.

IT system standards

Many NHS systems rely on nationally defined technical standards.

The Warranted Environment Specification (WES) sets out supported software and technical requirements, including:

  • operating systems;
  • web browsers;
  • supported software components and security requirements; and
  • authentication and smartcard-related components.

Pharmacy teams should ensure their IT equipment and software remain within supported versions and receive security updates from suppliers.

NHS cyber work

Community Pharmacy England continues to engage with NHS organisations on cybersecurity matters affecting community pharmacy.

This includes discussions about:

  • cyber resilience across the sector;
  • security standards and requirements;
  • lessons learned from cyber incidents;
  • cyber awareness and training; and
  • future digital and cyber policy developments.

We also continue to highlight the importance of practical, proportionate cybersecurity arrangements that support patient care while protecting pharmacy systems and data.

Cybersecurity and Resilience Bill

The UK Government’s Cybersecurity and Resilience Bill aims to strengthen the country’s cyber defences and improve the security of essential services and digital infrastructure. The Bill was introduced to Parliament on 12th November 2025 and continues to progress through the parliamentary process.

Key themes include:

  • stronger cybersecurity requirements;
  • improved incident reporting;
  • enhanced protection for critical services and infrastructure;
  • greater supply chain security; and
  • improved national cyber resilience.

Pharmacy owners should continue to monitor developments as future requirements may affect healthcare organisations and suppliers.

About specific threats

Cyber threats continue to evolve. Common threats include:

  • ransomware;
  • phishing emails;
  • malicious attachments;
  • fraudulent websites;
  • password attacks; and
  • supply chain compromises.

One of the simplest ways to reduce risk is to remain cautious about unexpected emails, attachments, links and requests for information.

Case study: WannaCry ransomware attack

Quite some time back, a ransomware attack known as WannaCry affected organisations worldwide, including parts of the NHS.

The attack highlighted the importance of:

  • applying software security updates promptly;
  • maintaining secure backups;
  • using supported operating systems; and
  • ensuring effective business continuity arrangements.

Although WannaCry is now a historical example, it remains a useful reminder of the potential impact of cyber incidents on healthcare services.

If you believe your system has been impacted by a threat or virus

If you suspect a computer or system has been infected by malware, ransomware or another cyber threat:

  1. Follow your organisation’s cyber incident procedures;
  2. Disconnect the affected device from the network if advised by your IT support provider;
  3. Contact your IT support provider or helpdesk immediately;
  4. Avoid taking actions that could worsen the situation unless instructed by your IT support provider; and
  5. Follow any supplier or NHS guidance relating to the incident.

Always seek advice from your IT support provider before taking action that could affect pharmacy systems or data.

NHS England also provides cyber incident reporting and support arrangements for health and care organisations.

Preventing ransomware attacks

To help reduce the risk of ransomware and other cyber attacks, pharmacy owners should ensure that:

  • Staff receive regular cybersecurity awareness training;
  • Unsolicited emails, attachments and links are treated with caution;
  • Operating systems, antivirus software and security tools are kept up to date;
  • User permissions are restricted to the lowest level necessary;
  • Critical data is backed up regularly;
  • Backup arrangements are tested periodically;
  • At least one backup is protected from the main network; and
  • Business continuity and disaster recovery plans are maintained and reviewed.

The NCSC and NHS England both provide practical guidance on protecting organisations from ransomware attacks and improving cyber resilience.

Further info

Read more:

Return to the Pharmacy IT hub

For more information on this topic please email it@cpe.org.uk

Latest Digital & Technology news

View more Digital & Technology newsSee all