Topical Question Time – in the Scottish Parliament at 2:16 pm on 7 May 2024.
Colin Smyth
Labour
2:16,
7 May 2024
To ask the Scottish Government what its response is to reports that a large volume of data has been published on the dark web, following the recent cyberattack on NHS Dumfries and Galloway. (S6T-01965)
Neil Gray
Scottish National Party
The Scottish Government is working with NHS Dumfries and Galloway, Police Scotland and other agencies, as we have done since we were first alerted to the cyberattack, to assess the level of the breach and the implications for the individuals concerned.
At my request, NHS Dumfries and Galloway has briefed local MSPs on the situation and issued a statement to staff and the public. A dedicated telephone helpline is now open to the public, and the Scottish Government continues to provide support to the board as it deals with the on-going situation and the live police investigation.
Colin Smyth
Labour
There is nothing more personal than someone’s medical data, so this serious development will be deeply worrying for patients and staff of NHS Dumfries and Galloway, who will all be asking whether the breach affects them and their loved ones.
NHS Dumfries and Galloway now knows what data files have been released, and that they include a substantial amount of data, including on children’s health. We also know, however, that it will take time for the board to work through its data to identify which individuals are affected. Given how important it is to identify any vulnerable people who might be impacted by the breach, what specific resources is the Scottish Government providing to NHS Dumfries and Galloway to ensure that the search of data is conducted as quickly as possible and that individuals are identified and supported?
Neil Gray
Scottish National Party
I thank Colin Smyth for his question, and I concur with him that for patients and staff across NHS Dumfries and Galloway the incident is very personal and it is a very worrying time. I accept and acknowledge that.
As I mentioned, I am limited in what I can say. However, I can inform Colin Smyth that the Scottish cyber co-ordination centre within the Scottish Government has stood up the Scottish multi-agency cyber incident support arrangements. Those arrangements bring together national agencies, including the National Cyber Security Centre, Police Scotland, the National Crime Agency, the NHS Scotland cyber security centre of excellence and Scottish Government policy leads, to support NHS Dumfries and Galloway to respond to and recover from the incident.
In addition to providing practical advice and support, the Scottish Government has alerted the wider public sector to the incident and has shared relevant information. That will, I hope, enable public sector organisations to take preventative steps to defend themselves against similar attacks.
Colin Smyth
Labour
The ransom demands from the perpetrators of the cyberattack were never going to be met, so it was always highly likely that they would follow through on their threats to release the data and cause maximum disruption and distress. Now that the data is on the dark web, what assessment has the Government made of the likelihood of other criminals being able to access the information, notwithstanding how challenging that is, and then being able to use it to target individuals whose data has been released? That will be a concern for patients and staff in Dumfries and Galloway.
Neil Gray
Scottish National Party
Again, I thank Colin Smyth for his question, because he is absolutely right. A breach of confidential data is an incredibly serious matter, and I reiterate NHS Dumfries and Galloway’s call for staff and the public to be on their guard for any attempt to access their systems, or for any approaches from anyone who claims to be in possession of data relating to them. If anyone finds themselves in that situation, they should contact Police Scotland immediately by calling 101.
Oliver Mundell
Conservative
The worrying attack comes at the worst possible time and is adding more pressure on already hard-pressed staff and on a health board that is struggling to meet huge funding cuts. In addition to making information technology support available, will the Cabinet secretary explore what additional emergency funding can be put in place to ease the pressures on the board and ensure that the chief executive can focus, at this exact minute, on sorting out the issue of the breach rather than having to balance the books?
Neil Gray
Scottish National Party
There has been minimal impact on patient care as a result of the breach. However, I know that the incident has resulted in the need for some staff to change working practices in the short term, so I am very grateful to everyone who is working to ensure that people still receive the best possible care while we work at pace to ensure a return to normal working practices.
The Government has made significant investments in all boards; we have seen a real-terms increase to NHS boards as a result of the most recent budget. Across the country, our teams continue to work with boards on their financial resilience. Should there be particular asks, I would be receptive to at least hearing them, even during the difficult financial situation that we are all facing across the public sector, although I might not be able to commit to being able to realise them fully.
Emma Harper
Scottish National Party
The latest announcement about the cyberattack displays the very real implications for staff and the public of cyberattacks, with personal details now bring freely published on the dark web. We also saw just yesterday that China successfully hacked the United Kingdom Ministry of Defence. Such attacks will continue to happen and will have serious consequences. Can the Cabinet secretary give a commitment that the Scottish Government is examining the cyber resilience of all our public institutions to protect the public and those who work in those vital services? Can the cabinet secretary also reconfirm that the Government is adequately supporting NHS Dumfries and Galloway to have the resources that are needed to assess and act on the cyberattack?
Neil Gray
Scottish National Party
I thank Emma Harper for her question. I can give those assurances. We continually review and regularly audit all health boards’ cyber resilience. I know that Emma Harper will understand that, for security reasons, I cannot go into detail on that. Health boards take part in an annual audit process that assesses their effectiveness against the public sector cyber resilience framework. It allows them to be as resilient as possible in reducing the likelihood and impact of cyberattacks. That has aided their ability to respond promptly when an attack is discovered, thereby minimising the impact on staff and the public.
In the most recent round of audits, the Scottish Health Competent Authority noted that auditors found that NHS Dumfries and Galloway had demonstrated clear commitment to the audit process.
Finlay Carson
Conservative
We know that 91 folders have been published on the dark web, including highly sensitive information from patients’ confidential records and staff details. I appreciate that there will be details of the attack that cannot be discussed and that the Cabinet secretary will be taking advice from the National Cyber Security Centre, but does he know whether the network was exploited because of a weakness in the security system or because someone’s credentials were used? Furthermore, can he set out exactly how NHS Dumfries and Galloway is being technically supported to ensure that all systems are back online and to help to address the anxiety and concerns of patients and staff?
Neil Gray
Scottish National Party
I reiterate what I said in response to Emma Harper, which is that NHS boards go through regular annual audits of their cybersecurity. The authority that conducted that audit noted NHS Dumfries and Galloway’s clear commitment to that audit process. Finlay Carson will understand that I cannot go into significant detail on that, for obvious security reasons.
In answer to his follow-up question, I note that there has been minimal impact on patient services, which have continued as normal: patients should have noticed very little change. However, I am conscious that there is the possibility of further impact, which is why we are continuing to support the health board and ensuring that it recovers as quickly as possible.
Tess White
Conservative
A major cyberattack on NHS Scotland in 2022 crippled NHS systems and disrupted services. What steps were implemented to prevent a major breach like that from happening again and why did they fail?
Neil Gray
Scottish National Party
As I have said in response to previous questions, the audit process for reviewing cybersecurity across all areas of the health service is kept under constant review. It is an annual audit process and, as I have already said, the Scottish Health Competent Authority has confirmed that NHS Dumfries and Galloway co-operated with the process and has done everything possible to stop the attack.
As we have seen from cyberattacks elsewhere, this is an incredibly difficult time to defend against increasingly sophisticated actors that are looking to infiltrate our systems, including that of the Ministry of Defence most recently. All we can do is continue to offer support, learn from the situations that have passed and ensure that our resilience is as strong as possible. That is what the Government will continue to do—not just with NHS Dumfries and Galloway, but with other health boards and public sector organisations.
Question Time is an opportunity for MPs and Members of the House of Lords to ask Government Ministers questions. These questions are asked in the Chamber itself and are known as Oral Questions. Members may also put down Written Questions. In the House of Commons, Question Time takes place for an hour on Mondays, Tuesdays, Wednesdays and Thursdays after Prayers. The different Government Departments answer questions according to a rota and the questions asked must relate to the responsibilities of the Government Department concerned. In the House of Lords up to four questions may be asked of the Government at the beginning of each day's business. They are known as 'starred questions' because they are marked with a star on the Order Paper. Questions may also be asked at the end of each day's business and these may include a short debate. They are known as 'unstarred questions' and are less frequent. Questions in both Houses must be written down in advance and put on the agenda and both Houses have methods for selecting the questions that will be asked. Further information can be obtained from factsheet P1 at the UK Parliament site.
The cabinet is the group of twenty or so (and no more than 22) senior government ministers who are responsible for running the departments of state and deciding government policy.
It is chaired by the prime minister.
The cabinet is bound by collective responsibility, which means that all its members must abide by and defend the decisions it takes, despite any private doubts that they might have.
Cabinet ministers are appointed by the prime minister and chosen from MPs or peers of the governing party.
However, during periods of national emergency, or when no single party gains a large enough majority to govern alone, coalition governments have been formed with cabinets containing members from more than one political party.
War cabinets have sometimes been formed with a much smaller membership than the full cabinet.
From time to time the prime minister will reorganise the cabinet in order to bring in new members, or to move existing members around. This reorganisation is known as a cabinet re-shuffle.
The cabinet normally meets once a week in the cabinet room at Downing Street.