The NHS is undergoing one of the most significant digital transformations in its history. Connected IoT medical devices are becoming central to patient care, artificial intelligence is beginning to support clinical decision-making, and healthcare organisations are sharing more data than ever before. This momentum is reflected in the UK Government’s 10-Year Health Plan, designed to make the NHS the world’s most digitally accessible and AI-enabled health service. Similarly, the NHS Cyber Security Strategy to 2030 sets a vision for a more connected and resilient health service that can safely embrace digital innovation.
Yet every connected scanner, infusion pump, wearable device, building system, and clinical application expands the attack surface. As healthcare becomes more connected, the boundary between cyber risk and operational risk continues to blur. A cyber incident is no longer just an IT problem. It can delay appointments, disrupt diagnostics, divert ambulances, and interrupt patient care. Therefore, cyber resilience has become a prerequisite for digital healthcare.
However, a hospital’s primary responsibility is delivering uninterrupted patient care, not managing patch cycles. Healthcare organisations must strike the right balance between reducing cyber risk and maintaining safe clinical operations.
Connected Care Requires an Evolution of Cybersecurity
It is not uncommon for healthcare organisations to underestimate the number of connected assets operating across their estates. Many believe they manage around 10,000 devices, only to discover many times that number once complete and accurate inventory is taken. Those assets extend well beyond laptops and servers to include medical devices, imaging systems, laboratory equipment, facilities systems, unmanaged endpoints, contractor devices, and operational technology.
Without a complete understanding of what exists across the network, organisations cannot accurately identify vulnerabilities, understand which systems are most critical, or assess how cyber risks could affect patient care. In healthcare, the same vulnerability may represent different levels of risk depending on whether it affects an administrative device or a system supporting diagnostics, treatment, or emergency care. Security decisions need to be grounded in clinical and operational context.
Visibility is the foundation, but it is not enough on its own.
Go deeper: Connected medical devices are attacked every 20 seconds on average. See all the data
Extending Zero Trust to Medical Devices
Zero Trust has become a familiar concept across enterprise IT. Users are continuously verified, devices authenticated, and access granted according to least privilege principles.
Healthcare must extend that same thinking to every connected asset. Medical devices are often viewed primarily as clinical equipment, but an MRI scanner, imaging workstation, or infusion pump are also network-connected endpoints and should not be implicitly trusted simply because they sit inside the hospital network.
The objective is straightforward: every asset should be known, trusted, appropriately configured and only communicating with the systems needed to perform its role. As hospitals collaborate through integrated care systems and shared digital services, applying consistent policies across IT, IoT, OT and medical device environments becomes increasingly important.
Building Resilience Through Segmentation
No healthcare organisation can realistically expect to prevent every cyber incident. The goal is to ensure that one compromised device doesn’t become a wider disruption to clinical services.
Segmentation is one of the most practical tools available to achieve this. Many medical devices cannot be patched immediately because they require vendor certification, support critical patient services or operate on legacy platforms that remain essential to clinical care.
Rather than relying on patching alone, organisations can limit what systems vulnerable devices are able to communicate with. Dynamic segmentation helps isolate exposed systems, restrict unnecessary communications and adapt access according to device posture, known vulnerabilities and threat context, preventing attackers from moving laterally through the network if a device is compromised. It’s not about preventing every attack, it’s containing the attack and limiting the blast radius.
Managing Cybersecurity at Machine Speed
Artificial intelligence is already transforming healthcare by reducing administrative burdens, supporting diagnosis, and improving operational efficiency. AI is also reshaping the cyber landscape, enabling defenders and attackers alike to accelerate the discovery of software vulnerabilities.
As a result, healthcare organisations are likely to face a growing volume of newly disclosed vulnerabilities across the technologies they rely on.
Security teams cannot treat every vulnerability as equally urgent. They need to understand which vulnerable devices are present, how exposed they are, how they communicate, and what impact exploitation could have on clinical operations, and prioritise remediation accordingly.
Furthermore, as AI enables attacks to become more automated, threats can move from discovery to exploitation and lateral movement faster than manual processes can contain. Defending at that pace requires security automation capable of turning visibility, risk prioritisation and device context into action, from flagging high-risk posture changes to dynamically restricting network access, isolating compromised endpoints and triggering response workflows. Used appropriately, automation helps contain threats at machine speed while preserving clinical judgement and continuity of care.
See how St.Luke’s University Health Network achieves true Zero Trust segmentation with Forescout as its command center in this case study.
Turning ‘Defend as One’ Into Reality
The NHS Cyber Security Strategy to 2030 recognises that defending healthcare cannot be achieved by organisations working independently. Its ‘Defend as One’ vision emphasises collaboration, shared situational awareness and coordinated cyber resilience across healthcare.
Achieving that vision requires a common understanding of the devices being protected, the risks they present, and the actions needed to reduce risk. It also requires the ability to apply consistent security policies, contain threats quickly and coordinate responses across connected environments.
For integrated care systems, this is particularly important. A weakness in one organisation can create risk elsewhere. Shared services, regional collaboration, and connected care pathways all depend on trust in the digital environment. Building that trust requires visibility, governance, and control that extend across organisational boundaries.
Security that Protects Patient Care
Healthcare’s digital future relies on cyber resilience. Connected medical devices, AI-enabled applications, and integrated healthcare systems will continue to transform care delivery, but cybersecurity must evolve at the same pace. By gaining visibility into connected assets, prioritising risk based on clinical impact, and containing threats before they disrupt operations, healthcare organisations can strengthen resilience while maintaining patient care.