Cybersecurity
Published on: 27th January 2017 | Updated on: 12th August 2026
Cybersecurity is about protecting data, systems and networks from online threats. Effective cybersecurity is essential for every pharmacy because cyber attacks can disrupt services, compromise sensitive information and affect patient care.
Cyber criminals increasingly target organisations of all sizes. Ransomware attacks remain a significant threat, and incidents across the health sector have shown how cyber attacks can have serious operational, financial and reputational consequences. Pharmacy owners and teams should take practical steps to protect their systems, patient information and business continuity.
Ten steps to improve cyber security
We recommend that pharmacy teams review:
- Community Pharmacy England briefing: Ten steps to cybersecurity within your pharmacy;
- Cybersecurity tips IT factsheet; and
- Relevant guidance from the National Cybersecurity Centre (NCSC) and NHS England’s cyber and data security teams.
See: cpe.org.uk/dstemplates.
Several organisations provide guidance and support to help health and care organisations strengthen cyber security.
National Cybersecurity Centre (NCSC)
The NCSC is the UK’s national technical authority for cyber security. It provides guidance, alerts, practical tools and advice for organisations, including health and care providers.
NHS cyber and data security services
NHS cyber teams provide:
- cybersecurity alerts and incident information;
- cybersecurity guidance and resources;
- training and awareness materials;
- incident reporting arrangements; and
- specialist cybersecurity services to support the health and care sector.
Many NHS systems rely on nationally defined technical standards.
The Warranted Environment Specification (WES) sets out supported software and technical requirements, including:
- operating systems;
- web browsers;
- supported software components and security requirements; and
- authentication and smartcard-related components.
Pharmacy teams should ensure their IT equipment and software remain within supported versions and receive security updates from suppliers.
Community Pharmacy England continues to engage with NHS organisations on cybersecurity matters affecting community pharmacy.
This includes discussions about:
- cyber resilience across the sector;
- security standards and requirements;
- lessons learned from cyber incidents;
- cyber awareness and training; and
- future digital and cyber policy developments.
We also continue to highlight the importance of practical, proportionate cybersecurity arrangements that support patient care while protecting pharmacy systems and data.
The UK Government’s Cybersecurity and Resilience Bill aims to strengthen the country’s cyber defences and improve the security of essential services and digital infrastructure. The Bill was introduced to Parliament on 12th November 2025 and continues to progress through the parliamentary process.
Key themes include:
- stronger cybersecurity requirements;
- improved incident reporting;
- enhanced protection for critical services and infrastructure;
- greater supply chain security; and
- improved national cyber resilience.
Pharmacy owners should continue to monitor developments as future requirements may affect healthcare organisations and suppliers.
Cyber threats continue to evolve. Common threats include:
- ransomware;
- phishing emails;
- malicious attachments;
- fraudulent websites;
- password attacks; and
- supply chain compromises.
One of the simplest ways to reduce risk is to remain cautious about unexpected emails, attachments, links and requests for information.
Case study: WannaCry ransomware attack
Quite some time back, a ransomware attack known as WannaCry affected organisations worldwide, including parts of the NHS.
The attack highlighted the importance of:
- applying software security updates promptly;
- maintaining secure backups;
- using supported operating systems; and
- ensuring effective business continuity arrangements.
Although WannaCry is now a historical example, it remains a useful reminder of the potential impact of cyber incidents on healthcare services.
If you suspect a computer or system has been infected by malware, ransomware or another cyber threat:
- Follow your organisation’s cyber incident procedures;
- Disconnect the affected device from the network if advised by your IT support provider;
- Contact your IT support provider or helpdesk immediately;
- Avoid taking actions that could worsen the situation unless instructed by your IT support provider; and
- Follow any supplier or NHS guidance relating to the incident.
Always seek advice from your IT support provider before taking action that could affect pharmacy systems or data.
NHS England also provides cyber incident reporting and support arrangements for health and care organisations.
To help reduce the risk of ransomware and other cyber attacks, pharmacy owners should ensure that:
- Staff receive regular cybersecurity awareness training;
- Unsolicited emails, attachments and links are treated with caution;
- Operating systems, antivirus software and security tools are kept up to date;
- User permissions are restricted to the lowest level necessary;
- Critical data is backed up regularly;
- Backup arrangements are tested periodically;
- At least one backup is protected from the main network; and
- Business continuity and disaster recovery plans are maintained and reviewed.
The NCSC and NHS England both provide practical guidance on protecting organisations from ransomware attacks and improving cyber resilience.
Read more:
- Community Pharmacy England briefing: Ten steps to cybersecurity within your pharmacy;
- Cybersecurity tips IT factsheet;
- NHS England cyber and data security guidance;
- National Cybersecurity Centre guidance and resources;
- Little Book of Cyber Scams (City of London Police and partners).
For more information on this topic please email it@cpe.org.uk












