NHS Cybersecurity Crisis: Who is Actually Protecting Your Medical Records?

NHS cybersecurity is on life support — can we fix it before patients pay the price?

In this episode of Razorwire, host James Rees sits down with Rob Priest (former NHS insider and security expert at Rubrik) and returning guest Richard Cassidy to unpack the real, lived impact of cyber attacks on the UK’s healthcare system — from ransomware crippling hospitals to outdated systems putting lives at risk.

You’ll hear first-hand stories from the frontline: Windows 95 still running in operating rooms, ransomware delaying cancer treatment, and what actually happens when a hospital’s systems go down. This is more than a cyber issue — it’s a public health crisis.

🧠 “The organisations that understand the impact best are the ones who’ve already lived through it. But… does it have to be that way?” – Rob Priest

🎯 Key Talking Points:

  • Why cyber attacks on the NHS lead to real-world clinical emergencies
  • The challenge of patching decades-old systems under constant budget pressure
  • What it will take to fix cybersecurity across 213 NHS trusts — and why most aren’t even close
  • Balancing national security mandates with localised, hospital-level needs

🎧 Listen now on your favourite platform: (https://razorwire.captivate.fm/listen)

🔍 In This Episode:

  • Nation-State Threats – How ransomware and APTs are targeting healthcare
  • Legacy Infrastructure – Why hospitals still run on outdated and unpatchable systems
  • Patient Safety – The direct clinical fallout of cyber incidents on emergency care
  • Supply Chain Risk – Third-party vulnerabilities in the NHS ecosystem
  • CISOs in Crisis – Why most trusts still don’t have dedicated cybersecurity leadership
  • Government Policy Gaps – Where national strategy and local implementation collide
  • Cyber Drills & Playbooks – Practical solutions for building resilience from within
  • Centralisation vs Local Autonomy – How organisational structure shapes security outcomes
  • NHS Reforms – What the 2023–2030 strategy gets right… and what it misses

💡 Mentioned in This Episode:

  • Rubrik (https://www.rubrik.com)
  • NHS, NHS England, NHS Digital
  • NCSC (UK), WannaCry, Synnovis
  • Cyber Security Strategy for Health and Adult Social Care
  • DORA, CAF Framework, BMA
  • The Cyber Sentinels Handbook by James Rees

🎙️ About Your Host
Hi, I’m James Rees, host of Razorwire and founder of Razorthorn Security. With over 25 years in cybersecurity, I’ve helped major organisations — including those in healthcare — navigate today’s evolving threat landscape.

This podcast brings you unfiltered insights from the professionals working to keep our digital and physical worlds safe. Whether you’re a security leader, healthcare worker, or concerned citizen, Razorwire equips you with the knowledge to make better decisions in an increasingly connected world.

📌 Subscribe & Connect
🌐 Website: (https://www.razorthorn.com)
📧 Email: podcast@razorthorn.com
📍 LinkedIn: (https://www.linkedin.com/company/razorthorn-security)
📍 YouTube: (https://www.youtube.com/@RazorthornSecurity)
📍 Twitter/X: (https://twitter.com/RazorThornLTD)