Fortune Favours The Brave

Understanding cyber risk in social care

Howden Insurance Brokers Ltd

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 30:50

As digital technology becomes increasingly embedded in the delivery of care, cyber security has become a critical business risk for social care providers of every size. From electronic care planning and medication management systems to payroll, rostering and resident records, a cyber incident can have far-reaching consequences for operational continuity, financial stability and, most importantly, the people who rely on care services every day.

In this latest episode of Fortune Favours The Brave, Richard Lawson, Senior Account Executive, Howden, is joined by Neil Hare-Brown, cyber security expert and CEO of STORM Guidance, alongside Jonathan Taylor, Divisional Director, Head of Corporate Risks, Howden, to explore the growing cyber threat facing the social care sector and discuss practical steps providers can take to strengthen their resilience. 

Together, they examine the current cyber risk landscape, the most common attack methods targeting care organisations, and the potential impact of data breaches, ransomware and phishing attacks. The discussion also covers how providers can build a stronger cyber security culture, improve incident preparedness, understand the role of cyber insurance, and meet increasing expectations from regulators, insurers and stakeholders. 

Whether you're a care home owner, director, registered manager or risk professional, this episode offers practical insights to help you better understand today's cyber risks and the actions you can take to protect your organisation. 

Welcome And Meet The Guests

SPEAKER_00

Welcome to Howden's podcast, Fortune Favours the Brave. We all take risks in our everyday life, and business is no different. In this podcast, we're speaking to the experts about the topical challenge or issue and what business leaders can do to overcome it.

SPEAKER_02

Hello and welcome back to this episode of Fortune Favours the Brave. My name is Richard Lawson. I'm one of the senior execs here at Howden Health and Care, and in this episode, we're going to be discussing cyber. And I'm joined today by my guests, Jonathan Taylor and Neil Hare Brown. I'd first of all say hello, Jonathan. Good morning. Good morning. And good morning, Neil. How are we today?

SPEAKER_01

Fine, thank you very much. Good morning to you, and uh thanks very much for inviting me on the show.

SPEAKER_02

Now, if we could start off uh Neil by giving a short overview of yourself and introducing Storm Guidance and what you do.

SPEAKER_01

Thanks very much. So yeah, I I head up Storm Guidance. Storm is actually an acronym for strategic, tactical and operational risk management, and that's essentially what we do. We help clients manage cyber risk at those three level, three organizational levels: the strategic, the tactical, and the operational. We essentially work in three areas or cover three areas in cyber. Our main work is an incident response. We respond to hundreds of incidents or have responded to hundreds and hundreds of incidents over the last uh 15 years. And those are incidents affecting every type of organisation in every type of sector, including the care sector, every type of organization in terms of size as well and revenue. And we essentially provide everything that those organizations need, should they have an incident. So not only the technical, all of the technical skills, the digital forensics, the malware analysis, etc., threat intelligence, but also all of the, if you like, non-technical capabilities, the legal advice, the crisis PR advice, uh, if you need it, ransom negotiation, even settlement, um, as well as uh even trauma counselling and systems recovery, that kind of stuff. So everything that an organization would need if they have an incident. We also help organizations with planning for and testing their incident response plans. And we run tabletop exercises. We're a NCSC, um, a short service provider for um cyber incident exercising as well as the incident response. And then the final area is in assessments, and we provide a range of different types of assessment depending on the organization and what they would like to focus on to help the senior management and the operational team better understand cyber risk. So that's really also a core competency for us.

SPEAKER_02

And uh Jonathan, if you mind introducing yourself and what you do here at Howden.

SPEAKER_03

Yeah, thanks, Rich. So yeah, Jonathan Taylor, so I head up all things corporate health and care. Um 20 plus years now in the uh health and care sector for

A Bravery Story And Cyber Core

SPEAKER_03

my sins, man and boy. Um so yes, I look after social care charities and everything in that healthcare space for Howden Insurance.

SPEAKER_02

Neil, as a uh guest here on the Howden Podcast, uh, is tradition that we ask when the last time you did something brave, whether that's in your work or personal life, and did it pay off?

SPEAKER_01

Probably thinking, yeah, in terms of work, I I think that in cyber there is a lot of fear, uncertainty, and doubt that's spread by various vendors. And I've been in cyber for 40 years now, and I've worked a lot uh with the the first computer crime unit in the police, um, did a lot of early date early data forensics or digital forensics work, um, set some case law with my team, got some both police and judicial commendations for our work investigating pedival rings. So I've been in the field for a long time, and I think now something that's quite hard to do is to try to change people's mindset given the fact that the cybersecurity industry wants to drive, you know, that the the the general sort of velocity of the cybersecurity industry is to drive customers or clients in a particular direction, and so one of the areas that we've been working on very recently is to is to help organizations get a very different perspective on cyber risk and help them get a much clearer perspective and to use that to challenge what they are being told and what they are being sold. So that's something which we've been working on, it's called Cyber Core, and it essentially helps organizations to change their perspective and to think about cyber risk in terms of protecting their critical assets from the perspective of a critical asset. So, and the results of that mean that you can actually calculate risk financially and then use those results to figure out what your actual budget needs to be for cybersecurity and also how much you want to insure and what that insurance looks like, what the limits are, etc., what the cover is. So that's something which I've been doing recently, and it is breaking the mould a little bit, and I'm finding a lot of excitement and a lot of acceptance from certain people, and a little bit of a kickback from others. So that's that's my point.

What Counts As A Cyber Attack

SPEAKER_02

Well, uh, that leads us on quite nicely because today we will be discussing cyber attacks, uh, the risk to the care sector, what care providers can do to protect themselves and to ensure that they're covered for these risks uh the best they can be. Um, I'm gonna come back to you, Neil, first of all. So, what do we mean by cyber attacks? And are there different types of attacks? And can you give examples to start with?

SPEAKER_01

So, generally people think about cyber attacks as being something malicious, and generally it is malicious. There are some accidental type uh cyber incidents which occur. Some people might remember a couple of years ago the CrowdStrike incident, which was not malicious, but it still caused a lot of outage. So there are the occasional non-malicious, but the general thrust is that um cyber attacks are driven by criminals, and essentially, really, these attacks are another type of fraud, a modern fraud-type crime. And it's just that the internet, um, the fact that countries are bound by their own local jurisdictional laws and practices which enable international criminals to skate around or to avoid being caught and being brought to justice, so that's another big driver for cybercrime. Another driver is the fact that there is cryptocurrency, and cryptocurrency has really been the big driver for a lot of international cybercrime, especially ransomware. So, really, it is just another type of fraud, and as long as it's not state-on-state attacks, then the results of a cyber attack is always for the criminals to find some way to monetize, and that'll either be through a straight man in the middle fraud. For instance, many people may know of business email compromises where the the criminals get into uh their victims' mailboxes and then they pretend to be either the victim themselves or representing the victim company or a third party and they manage to get in the middle of a transaction and divert that payment. And then there is another type of uh of attack which is called ransomware, and that's uh an extortion type attack where the criminals are um extorting their victims for the recovery of their data and to get assurance that the data that's been stolen uh it's called double extortion. So there's one part of it which is uh the causing the uh the destruction of the victims' systems and their data, and the other part of it is stealing that important data before it's destroyed or encrypted, and then holding that data to ransom essentially by saying if you don't pay us, we're gonna release all of this data into the public domain. So business email compromise and ransomware account for about 90% of all cyber incidents, and then there are other types of incidents such as insider misuse. We still see that, even things such as lost devices which fall into the wrong hands or have stolen, um denial of service attacks, other types of more sophisticated cyber attacks. So yeah, that's that's essentially the the if you like the the picture of cyber attacks and what it means.

SPEAKER_02

Thank

Why Care Providers Are Targeted

SPEAKER_02

you. And John, following on from that, what are we seeing in the care sector specifically in regards to cyber attacks? And does cyber insurance link to the CQC or Care Quality Commission, the local authority expectations around safety and governance?

SPEAKER_03

Yes, very much so, Rich. So um we are definitely seeing a huge increase in cyber criminals and cyber activity. We normally see a spike whenever there is some kind of a political impact. So we've um obviously some wars of of recent nature, so that generally means we see uh a spike in claims. Um we are seeing a massive increase, and generally those claims seem to be in phishing. Um, that seems to be the kind of 80-90% of the claims we see seem to be in that that's based on um cyber criminals perpetrating to be someone else they're not, for example. Um, can you pay this invoice um and changing bank details? Um very much so we're starting to see local authorities, commissioners, um, CQC, etc., very much starting to look at cyber. Um, we are seeing a lot of care providers starting to move on a digital basis. So the CQC are very interested, charity commission, etc., any commissioning bodies are very interested in looking at how providers are looking after their cyber um security, data records, etc. Um, so it's very much high on the agenda. We're also starting to see tenders and the requests of cyber insurance as part of that tender submission as well.

SPEAKER_02

Well, thank you. And Neil, back to you. With the care sector becoming more and more reliant on digital care planning, online staffing systems, cloud storage, amongst other things, what are the heightened risks facing the sector?

SPEAKER_01

I mean, the main risks are, as I've already mentioned, the the the theft of funds, and though that might be funds from you know the the the victim organization's operational uh accounts, you know. So, for instance, as John just mentioned there with phishing um, and one of the reasons why we're seeing a lot of phishing spike is because AI is being used to create much more convincing deception. So, for instance, yeah, just the st the the theft of funds from the the victim organization's bank accounts. Generally, the attackers will pretend to be a supplier um or some other party that uh with which the the organization is is expecting to do business with, and then as John was saying, you know, that the part of that deception will be to divert the funds to a fraudulent beneficiary account. Um, that's mainly now that the UK uh is using confirmation of payee a lot more now, um the listeners may uh may know that when they're setting up a payment to um a an organization inside the UK, they'll there'll be a check to make sure that the account uh number matches up with the organization name. And that was a method prior to uh confirmation of pay a few years ago, it was a uh a system that was regularly abused by criminals because there was no cross-correlation between the account name and the and the account number. Amazing to think, right, that we were still operating that system. Um but now there is, it means that the criminals now are starting to get a little bit more savvy and to figure out whether or not the victim organization is making payments or expects to make payments to international organizations. And at the moment, the confirmation of payee doesn't work outside of the UK, so there's no none of these account checks, and so it's much easier for um for the criminals to give a false account name, which sounds very convincing, something that the victim organization is going to expect, but actually to have a fraudulent beneficiary account number and other details and to divert the stolen funds to. So, yeah, so definitely theft of funds.

The Real Risks: Money And Data

SPEAKER_01

And then the other thing which really affects, especially organisations in the care sector, is the uh breach of very sensitive data. So that might be medical data, it might be other types of sensitive personal information, and and and so it's really going to be uh a big problem for victim organizations that have data stolen uh about the those that they are caring for, and that could potentially destroy that organization. You know, they may lose contracts, they may lose trust, um, and it may mean that uh that that you know that that they would no longer be a trusted organization. And I remember many, many years ago, uh the Terence Higgins Trust were uh had a it was in it's in the news, so it's not it's not uh anything other than in the public domain, but they had an issue a very simple issue, which um was that one of their um employees completely accidentally put a whole list of of email addresses into uh a very sensitive medical advisory message which should have gone to the recipients on a on an individual basis, and instead of using the BCC field, they they they put the the um hundreds and hundreds of email addresses into the CC field, and uh so a good example of a completely accidental type of data breach, but that really did hurt you know, did take Terrence Higgins Trust a little bit of time to build back that trust with their donors in the wake of that incident. So, yeah, so definitely data breaches are a really big issue for care service providers.

SPEAKER_02

I mean, a simple mistake there at the end that that you know has cost a an organisation a huge amount of reputational damage. Uh John, we've seen over the last five years or so a huge increase in reliance on digital setups in care, online governance, training, record keeping. Have we seen the same increase on uptake and interest in protecting and ensuring this ever increasing risk?

SPEAKER_03

I would say we are seeing more uh more of an interest in uh uh cyber insurance policies are certainly much better than they were five or six years ago. What I would say is we do tend to see um a thought process from providers um that when they outsource their IT, that the outsource provider will pick up any um costs, any risk associated with that. Um so often we're having lots of discussions with providers around that generally isn't the case, and contracts often very much mitigate and reduce that risk for that provider. Um, in terms of uptake and cyber insurance though, Rich, yes, we're definitely seeing an increase, albeit I would like to see a lot more, and it's probably top of our list in terms of when we talk to clients in terms of risk. Um, from our perspective, it's definitely overtaking the the standard trips and slips and car accidents, cyber um cyber threat is probably, if not, the number one threat we're seeing in the sector at the moment.

SPEAKER_02

Neil, what do care providers risk by not taking these steps to protect their business and its cyber risks?

SPEAKER_01

I think um, well, obviously, as I mentioned earlier, the whole aim of cyber criminals is to monetize and steal steal funds. So certainly financial loss, uh, and that can be in many different ways. It could be the cost just the cost of responding to an incident is uh you know can be excessive uh depending on the incident itself. It may take many, many man hours to both investigate and recover. Um, then there are uh the potential for fines and judgments against the organization, data protection and notwithstanding, but there may be other contractual obligations that an organization has which puts them uh you know, which makes them liable if they have a cyber incident, and uh and so there's a potential financial loss there. Um then there is then there is reputational harm. Um could that could an incident begin to impact relationships with donors? And that could obviously have a very big impact on the organization themselves. So certainly there are the there are a number of points around the financial loss, and then there is the data protection, so the loss of data itself. Um I've already mentioned the the potential regulatory exposure, but uh certainly losing data can uh have quite a devastating effect on an organization's operations day to day, and it can be very hard for them to operate and to deliver the care and the services that they would do so on a on a business as usual basis. Um, and then there if there is an outage of systems, then that also can cause uh a loss of productivity and that can really seriously affect the delivery of services, as we've seen with cyber incidents, for instance, it affecting the National Health Service over the last uh well even 10 years, um, from WannaCry all the way through. There have been some significant outages and the scattered spider cybercrime gang, which are in court in July 2026, they were responsible for some significant attacks on the NHS, potentially putting lives at risk as well. So there is, if you like, the the most extreme area of loss that can potentially occur.

SPEAKER_02

Yeah, thank you. And uh, John, what can our listeners, clients, and otherwise

Insurance, Outsourcing Myths, And Exposure

SPEAKER_02

do moving forward to prepare themselves?

SPEAKER_03

I think for me it's really much understanding where your cyber threats are. There are a lot of tools out there um that will help you understand your cyber threat analysis, whether it's the likes of Storm Guidance or your cyber insurer, many of which will offer tools that will give you um an understanding how you compare to your peers, what type of level insurance you might consider purchasing, and um it can also go into real serious depth in terms of what threats are out there, if you've got any open ports, any email addresses out there, anything further than that, we are seeing tools where it'll tell you if there's any chatter on the dark web about your organization. Um, some of which those tools can give you alerts. So if you're a kind of a C-suite leader and haven't got time to be looking at everything, you can just get an alert if your organization is mentioned on that dark web. Um, so I said that there's plenty of tools out there with understanding what you've got. Often you're paying your IT provider or your free and cyber insurance, and there's lots of bells and whistles that we don't see clients making the most of. So I would definitely advocate chatting to your insurance broker or your IT provider.

SPEAKER_02

And Neil, I I imagine that time is key in the event of a cyber attack. So if a care provider is hit by a cyber attack, what should they do in the first few hours?

SPEAKER_01

Okay, yeah, absolutely you're absolutely right. Uh, you know, the response is the way in which you respond, the speed and the quality of that response is not just about speed, but it's it's also about quality, um, is very, very material to the to the loss. So we have what we call the golden hour, and that is essentially from the point of detection um through the investigation and through to the beginning of the recovery, or certainly the planning of the recovery. We really want to um optimise in that first golden hour what needs to happen, how the coordination needs to work, and just having the technical skills or some of the other skills that I mentioned earlier, just having those skills available is not necessarily going to um mean that you have a uh a successful response. It's always a good idea to um proactively plan for cyber incidents to make sure that you've got a plan. Um, obviously, as the as the saying goes, no plan survives versus contact. Um so the plan doesn't have to be perfect, but certainly if you've got if you've already understood what your critical assets are, what your critical data is, um, how your um payment processes work, who is involved, who would be involved uh in various uh different incident scenarios. Um and that isn't just your internal staff, it's also third parties. Increasingly now, I think someone mentioned earlier, we rely increasingly on third parties to provide various services to us. So if we needed them to if we need their assistance in responding to an incident, then we need to actually understand um who you know how best to actually make that make that work. And then there are other organizations, there's regulators there, there are um potential uh if if you if you're with the MHS, then uh there's a uh hotline to call there to report incidents. Um if you're interfacing with the NHS at all, there is uh the data protection. Um the the information commissioner's office for data protection you might need to report to. So all of these various um entities need to be brought together or certainly considered it when an incident occurs, and really what you want to have when that happens is someone who is very experienced with dealing with incidents. You don't you definitely it's not the time for first name introductions and and rookies. Uh you definitely need someone who is really has seen many incidents before and is really going to help guide you through the rocks to hopefully the best possible outcome that you can you can have. So yeah, that's that's the best way to respond in that initial period. I should just say one more thing that we find in pretty in many in many different incidents, we find that there is often um a conflict between the need to investigate an incident and the need to recover. And again, planning properly for incidents helps you to resolve that potential conflict and to sort of head it off at the pass. Certainly, if everyone knows what role they play and what they need to be doing, then that can really help. But certainly, in those early hours, it's really important to preserve the digital scene to make sure that you've got all the information you need to do a thorough investigation. With the main objective of the investigation, is to understand how the incident occurred. Because until you actually understand the root cause, you can't really ever then be certain that you have, for a start, um contained and eradicated um

The Golden Hour Response Playbook

SPEAKER_01

the attackers from your networks and prevented any further damage, and you don't want them to come back and uh on a rebound attack either. So, understanding how the attackers got into your networks um is a is a really critical thing to do.

SPEAKER_02

Alright, wonderful stuff there, Neil. Thank you ever so much. Um, I suppose final question to you both, and um, we will start with Neil. What does the future hold for um the care sector from a cyber point of view? As discussed earlier in the podcast, we are seeing ever increasing risks to providers, and maybe not as quickly the growing uptake on the protection. Now, I know that the average uptake, not just care, but across all industries, is about eight percent of businesses are covering cyber from an insurance point of view. So, where does that leave uh providers if not insured or not taking those protections?

SPEAKER_01

It leaves them in a place where they can really only manage there's there's four ways to manage risk, whether it's cyber or any other type of risk. Um uh so there's um there's risk mitigation uh or reduction, there's risk transfer, there's risk acceptance and risk avoidance. So assuming that an organization uh is not is not actually insuring, that only leaves them with three because uh risk transfer is is for insurance. Um there are some other um ways of transferring risk, but let's just put that to one side. So that leaves you with uh mitigation uh or reduction, um acceptance or avoidance. Avoidance is essentially this thing is so risky, we're not gonna do it. And obviously, most organizations want are in business to do whatever it is that they need to do, especially in the care sector. So that leaves us with two. Um, and so we're now in a situation where we're either reducing or mitigating our risk or accepting that risk. And I think a lot of organizations are um unknowingly accepting too much risk, um, and they're not really aligning the cybersecurity steps that they're taking to the amount of risk that they actually have. So, and that's really where you know, referring back to the risk transfer and the insurance piece, that's really where if organizations were to think about things, probably hats more scientifically, then they would realise that actually there is a large chunk of risk that they have, which if they were to try and address that directly with only risk mitigation, only cybersecurity, their cybersecurity budget would have to be extensive, and they'd also need extensive skills uh capability as well. Um, and that's the sort of area where cyber insurance can really help them to to if you like to to address that big chunk of of risk.

SPEAKER_02

And John, any anything to add there further, really, with the as I say, the increased risk, but not always the increased protection.

SPEAKER_03

Yeah, absolutely. I I think Neil knocked it very much on the head there. I think for me, um, chatting to a lot of providers is making sure they understand what that cyber risk looks like. Every single provider now is heavily data-led and very much high-value data. Um, so it's a case of they cannot live without IT, cannot live without that data. Um, it's not like when MS went down, they can still sell you your uh your nice steak, whereas a care provider still needs to provide care and has to have those records. Um, what we're often seeing is people have got an over-reliance on an outsource provider or that a very small in but beautiful internal team, um, and they don't necessarily understand what that cyber threat is. So I think for me it's very much before we even consider risk transfer and buy the insurance, do they do providers understand what that threat looks like? How capable are they of defending that threat? Um, very much I would advocate looking at that and pulling that top of your list, it should be on everyone's BCP and making sure they understand that. Um

Future Risk Choices And Next Steps

SPEAKER_03

we often talk to many providers and it it gets a bit of a chuckle in terms of you've got a business continuity plan for your IT, where is it? It's on the server, how are you gonna get that if you can't even get on the server because your IT's down or you've heard your uh system tacked? So um simple things like that. We talk to uh talk to clients a lot about, but I suppose for me it's advocating understanding where that risk is and what your cybersecurity looks like compared to your peers.

SPEAKER_01

It's uh it's also kind of about about appreciating that there are certain things that you're not going to know. I think a lot of organizations, especially care providers that are that are on the smaller side, they have a real challenge because they have to understandably rely on um various providers for their information technology, whether it's uh an information uh, you know, whether it's an IT service provider that's looking after their desktops or their their computing, or whether it's a cloud service provider and the very all the various services they use. And they have to rely on those on those um those various providers. And in some cases, those providers, unfortunately, are not very experienced uh or qualified in cybersecurity and cyber risk management, and so that essentially what we see quite a lot is that those vendors do, you know, in the best, you know, using the best terms, mislead their their customers into perhaps a false sense of security that they've they've got it covered from an IT perspective, and that generally isn't the case, unfortunately.

SPEAKER_02

Wonderful. Well, thank you so much. I think we've hit some really interesting points and the topic I think we could talk about for the next couple of hours, but unfortunately, that's all the time we have for this episode. Uh, I'd like to thank you both for joining us. Neil, first of all, uh could you give us some information or the people listening? Uh, where they can find you, where they can find StormGuidance, etc.

SPEAKER_01

Absolutely, yeah. Stormguidance.com. And yeah, you can reach out to us there, or certainly through John as well. He'll he'll be happy to put you in touch with us. And yeah, look forward to hearing from you if you need any assistance.

SPEAKER_02

Wonderful. And uh thank you ever so much, John, for joining us today. More than welcome, thank you.

SPEAKER_03

And thank you very much, Neil. Very long-standing uh partner and friend of Raz at Halden, and uh very much advocate people chatting to live uh understand your cyber risk and cyber threat.

SPEAKER_02

And to our listeners, thank you ever so much, and until next time, goodbye.

SPEAKER_00

Thank you for listening to this episode of Fortune Favours the Brave from Howden. To hear more episodes and subscribe to our channel, search Fortune Favours the Brave on your favourite podcast app.