News

10.11.14

Trusts ‘at risk of hacking’ after failing to extend Windows XP support

There are 18 NHS trusts still using Windows XP that failed to sign up to a government agreement with Microsoft to extend security support for the operating system.

In April, the Cabinet Office sent out a letter headed ‘Urgent Action’, telling all trusts that it had negotiated an agreement extending support of Windows XP for the entire public sector, but to benefit from the continued Security Patch downloads, trusts needed to put a ‘Premier Services Agreement’ in place with Microsoft.

The letter said: “If you have not migrated away from Microsoft XP then you must urgently take out a PSA to continue to access critical and important security updates beyond 8 April 2014.

“It is imperative that your organisation clearly understands the risk that is placed on it should the decision be not to take out a PSA,” the letter added.

However, FOI requests and analysis by The Register IT website have recently revealed that while the majority of trusts who still use XP have put an agreement in place, 18 failed to arrange a PSA and therefore have not received Security Patch downloads since April.

The deadline for the PSA was prior to the first full patch release on 13 May.

According to the FOI requests, some trusts have up to 4,500 machines running Windows XP with no security patches in place and a total of 1.1 million PCs and laptops are estimated to be running XP at trusts, GPs and other NHS groups in England.

David Harley, a former NHS IT manager who now works as a senior researcher with net security firm ESET, told The Register that it was impossible to gauge the full extent of the security implications of trusts failing to sign the PSA. The level of risk will depend on the context for which the machines are used, he said.

“If there is an internal network connection (even sneakernet), the risk increases, but that risk may depend on how many non-upgraded machines are on the network, the effectiveness of perimeter defences, the availability of suitable exploits to a potential attacker, and so on. An internet connection on a machine that carries sensitive data itself, or allows access to it, is probably most at risk.”

NHE contacted NHS England for comment but they had not responded by the time of publication.

When the agreement was first signed, a Microsoft spokesman told NHE’s sister title Public Sector Executive: “We have made an agreement with the CCS to provide eligible UK public sector organisations with the ability to download security updates to Windows XP, Office 2003 and Exchange 2003 for one year until 14 April 2015.

“Agreements such as these do not remove the need to move off Windows XP as soon as possible.”

Tell us what you think – have your say below or email [email protected]

Comments

There are no comments. Why not be the first?

Add your comment

national health executive tv

more videos >

latest news

View all News

comment

NHS England dementia director prescribes rugby for mental health and dementia patients

23/09/2019NHS England dementia director prescribes rugby for mental health and dementia patients

Reason to celebrate as NHS says watching rugby can be good for your mental ... more >
Peter Kyle MP: It’s time to say thank you this Public Service Day

21/06/2019Peter Kyle MP: It’s time to say thank you this Public Service Day

Taking time to say thank you is one of the hidden pillars of a society. Bei... more >

editor's comment

26/06/2020Adapting and Innovating

Matt Roberts, National Health Executive Editorial Lead. NHE May/June 2020 Edition We’ve been through so much as a health sector and a society in recent months with coronavirus and nothing can take away from the loss and difficulties that we’ve faced but it vital we also don’t disregard the amazing efforts we’ve witnessed. Staff have gone above and beyond, whole hospitals and trusts have flexed virtually at will to meet demand and pressures and we’ve... read more >

last word

Haseeb Ahmad: ‘We all have a role to play in getting innovations quicker’

Haseeb Ahmad: ‘We all have a role to play in getting innovations quicker’

Haseeb Ahmad, president of the Association of the British Pharmaceutical Industry (ABPI), sits down with National Health Executive as part of our Last Word Q&A series. Would you talk us throu more > more last word articles >

interviews

Matt Hancock says GP recruitment is on the rise to support ‘bedrock of the NHS’

24/10/2019Matt Hancock says GP recruitment is on the rise to support ‘bedrock of the NHS’

Today, speaking at the Royal College of General Practitioners (RCGP) annual... more >

the scalpel's daily blog

Covid-19 can signal a new deal with the public on health

28/08/2020Covid-19 can signal a new deal with the public on health

Danny Mortimer, Chief Executive, NHS Employers & Deputy Chief Executive, NHS Confederation The common enemy of coronavirus united the public side by side wi... more >
read more blog posts from 'the scalpel' >

healthcare events

events calendar

back

September 2020

forward
mon tue wed thu fri sat sun
31 1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 1 2 3 4
5 6 7 8 9 10 11

featured articles

View all News