Skip to main content
NFRisk Non-Financial Risk advisory Start a Conversation
NFR-0038 Evidence-controlled risk scenario

National Health Service in England

When patching gaps became front-line service disruption

WannaCry affected at least 80 of 236 NHS trusts in England and exposed gaps in patching, preparedness and national response coordination.

Operational Resilience Technology & Change Risk Cyber security

Documented impact

Service disruption At least 80 of 236 trusts affected
19,494 Approximately 19,494 appointments estimated cancelled

Authoritative findings

The documented event

The WannaCry ransomware attack affected NHS services in England from 12 to 19 May 2017. The NAO reported that at least 80 of 236 trusts were affected: 34 were infected and locked out of devices, while 46 were not infected but reported disruption. NHS England identified 6,912 cancelled appointments and estimated approximately 19,494 in total. Five accident and emergency departments diverted patients. Most infected NHS devices were unpatched supported Windows 7 systems; unsupported Windows XP devices were a minority of identified issues.

Hypothetical institutional scenario

How might the same control pattern appear?

Critical service providers receive security alerts and patches, but cannot demonstrate implementation across distributed estates, embedded devices and local organisations before a rapidly spreading incident tests the gap.

Stress-test questions

Questions for challenge and assurance

  1. Risk committee

    Can management prove critical patches are implemented, not merely distributed?

  2. Operations

    Which essential services depend on unpatchable or embedded devices?

  3. Audit

    Can the organisation coordinate safely when email and core systems are unavailable?

NFRisk practitioner interpretation

Control implication

NFRisk view: cyber resilience is an evidence problem as well as a technology problem. Boards need verified patch status, exception ownership, dependency visibility, workable isolation and tested service-continuity communications.

Evidence register

Primary and supporting sources

  1. UK National Audit Office

    Investigation: WannaCry cyber attack and the NHS (opens in a new tab) 27 October 2017 · Authoritative primary source

Publication note

A documented external event—not an NFRisk client engagement.

The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.

Return to the Risk Scenario Library

From scenario to mandate

Test the equivalent control assumption in your environment.

NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.

Start a conversation