30-second briefing

The assurance brief

  • Keep DSPT as the baseline: use each material assertion to identify the real control, its owner, the care consequence it protects and the evidence that would disprove an assumption.
  • Test a small, risk-based set of controls in operation: recent leavers, privileged authentication, an actual backup restore, a frontline incident scenario and continuity through one critical supplier outage.
  • Record the result, weakness, owner, deadline and retest. The value is the improvement made after the test, not the volume of evidence retained.

The NHS describes the Data Security and Protection Toolkit as an annual self-assessment through which organisations measure performance against the National Data Guardian's data security standards. It remains a necessary assurance route for organisations with access to NHS patient information and for access to services such as NHSmail. The question is not whether providers should move away from it, but how to extract more operational value from it.

A self-assessment records an organisation's answer at a point in time. It cannot, by itself, show that a leaver lost access to every system, a backup can be restored within the care service's tolerance, a night team can use the incident plan, or a central policy operates consistently across every location. Those questions require observation, sampling or exercise.

That distinction is consistent with the framework's origins. The National Data Guardian's 2016 review said leaders should demonstrate the standards through audit or objective assurance. NCSC guidance separately warns that compliance and security overlap but are not identical. The next stage is therefore not a rival to DSPT. It is the evidence loop beneath it.

Evidence in viewReported controls were common; effectiveness still needed scrutinyShare of regulated care providers reporting selected arrangements in DHSC research
Reported controls were common; effectiveness still needed scrutiny
MeasureValue
Formal cyber policy82%
Business-continuity plan covering cyber80%
Backed up data81%

DHSC survey of 575 regulated care providers in England; fieldwork December 2023 to April 2024. Measures are self-reported presence, not independent tests of effectiveness and not live 2026 rates. DHSC's qualitative work recorded concerns about implementation, practical knowledge and backup arrangements.

Evidence: the framework was never meant to be the finish line

DSPT is explicitly an annual self-assessment. Its public guidance says organisations respond to mandatory evidence items and confirm assertions before publication, with requirements tailored by organisation type. That structure provides a common baseline and a disciplined prompt for governance. It should not be described as a guarantee that an organisation is secure or will avoid an incident.

The case for additional proof comes from authoritative sources, not a criticism invented outside the system. The National Data Guardian called for audit or objective assurance when the standards were created. ICO security guidance says organisations need processes to test, assess and evaluate whether their technical and organisational measures remain effective, document results and act on findings. NCSC says a compliance-only approach can create overconfidence and mask weak practice.

Analysis: separate design, implementation, operation and assurance

Take leaver access. Design is the rule that former workers must lose access. Implementation is the workflow linking the manager, HR and system administrator. Operation is whether that workflow ran for each person who left. Assurance is a sample showing that accounts across email, care records, rostering and cloud storage were actually disabled as intended.

The distinction prevents weak evidence from being asked to prove too much. A policy shows intent. A completed ticket shows a process step. A system report or attempted login can show an outcome. A repeat sample shows whether improvement has lasted. Boards should ask which level each dashboard measure represents.

A green policy measure is evidence of intent. Assurance begins when the organisation tests the outcome the control was meant to produce.

Practice: test access where identities and roles change

Start with a small sample of recent leavers, role changes, temporary workers and privileged accounts. Confirm what access each person should have, compare it with the live systems and investigate exceptions. Then identify high-consequence services that can still be reached with only a password, shared credentials or an unmanaged supplier account. Multi-factor authentication is valuable, but the assurance question is where it is enforced, for whom and with what exceptions.

This is primarily an organisational test, not a penetration test. It can be run by a manager with support from IT or the system supplier. Evidence might include the sample definition, date, systems checked, exceptions found, risk decision, corrective action and retest. Avoid retaining unnecessary personal data in the assurance record.

Practice: prove the restore, then compare it with care tolerance

A successful backup job shows that a copying process completed. It does not show that the information is complete, usable or recoverable quickly enough. ICO guidance says organisations must be able to restore access and availability to personal data in a timely manner and regularly test the effectiveness of their security measures. The appropriate test and cadence depend on the organisation, its processing and the risk to people.

Choose one critical dataset and restore it through the real recovery route. Check completeness, integrity, permissions and the time taken. Compare that time with the service's operational tolerance: when will staff next need current medicines, risk, rota or contact information? If the supplier controls the backup, establish what evidence it can provide and what the provider can access while the live system is unavailable.

Record the result honestly. A slow but successful restore may still expose a care-continuity gap; an unsuccessful exercise is useful if it produces remediation before a real event.

Practice: exercise the people who will meet the incident first

NCSC's Exercise in a Box is free, requires no specialist expertise and includes scenarios such as ransomware, phishing and supply-chain incidents. Its purpose is to rehearse decisions, test policies and identify improvement. For care, the scenario should begin with an operational problem rather than technical jargon: the care-record and medicines systems are unavailable, the cause is uncertain and the supplier has no recovery estimate.

Run at least part of the exercise with the frontline or out-of-hours team. Can they recognise that the problem needs escalation, find contacts without the shared drive, reach current contingency information, protect people through the next care activity and record temporary decisions? Success is not a flawless performance. It is a clearer plan, corrected contact route and evidence that the action was completed and retested.

Assurance: sample the edges of the operating model

A multi-site provider should not infer estate-wide performance from head office. Sample recent acquisitions, older locations, different care models and sites with unusual suppliers or connectivity. A smaller provider does not need an internal cyber department: one leaver review, one restore, one device check and one tabletop can reveal more than a large untested policy library.

External suppliers belong in the same evidence model. A provider cannot test every control inside a platform, but it can seek proportionate evidence of authentication, recovery, incident communication and independent assurance; check that certification scope matches the service; and test its own continuity when the service is absent. Exceptions should be visible, approved, mitigated and reviewed rather than quietly normalised.

Governance: retain the learning and close the loop

A proportionate assurance record is short: control and risk, test performed, date and scope, result, weakness, owner, target date and retest. Report consequence as well as percentage. Ninety-five per cent MFA coverage can conceal an unprotected administrator account; a perfect backup-success dashboard can conceal that no restore has been attempted.

For CQC-registered services, Regulation 17 requires effective systems and processes to assess, monitor and improve quality and safety, mitigate risks, maintain secure and accurate records, and evaluate and improve information processing. That does not create a prescribed cyber-test schedule, but it makes an evidence-and-improvement loop relevant to good governance. CQC's current care-home registration guidance also asks applicants for a business-continuity plan covering IT failures and cyber attacks; that specific page should not be generalised beyond its care-home registration context.

The board's final question should be simple: what did we test, what did we learn, what changed and has the change been proved?

Questions leaders should ask now

  1. 01

    Does a current DSPT prove the organisation is secure?No framework can guarantee that. DSPT is an important annual self-assessment and assurance baseline. Operational testing asks whether selected controls work under the provider's real conditions and risks.

  2. 02

    How often should controls be tested?There is no universal UK GDPR cadence. Set frequency by risk, rate of change, previous failures and care consequence. Retest after material system, supplier, workforce or service changes and after remediation.

  3. 03

    Do small providers need penetration testing?Not for every assurance question. Access sampling, a real backup restore, a supported-device check and an incident tabletop can provide meaningful evidence. Specialist technical testing should be scoped to the systems and risks that justify it.

  4. 04

    What evidence should be retained?Keep enough to show scope, result, decision and improvement: date, test, sample or system, result, exception, owner, action and retest. Minimise personal data and protect the assurance record.

  5. 05

    What should the board see?Show the most consequential untested assumptions, failed or overdue actions, exceptions, recovery performance and whether remediation passed retest. Percentages need context about which accounts, systems or sites sit outside the measure.

The Care Circle view

Use DSPT as the start of a learning system

The useful shift is from annual declaration to continuous learning: assertion, control, test, finding, action and retest. That respects the DSPT's role while answering a different question. It also connects cyber assurance to care: the value of a restore is access to information when people need it, and the value of an incident exercise is safer, faster decision-making under pressure.

Providers should resist two extremes. A certificate or dashboard is not proof of every outcome; neither does meaningful assurance require an expensive audit programme. A small number of well-chosen tests, run in real operating conditions and followed through to correction, creates evidence a board can use and a service can feel.

Continuing coverage

Follow the question into the later editions.

An NHS cyber charter signature is a starting point, not a verdict · 10 October 2026

AI is entering care records. Who owns the final account? · 9 October 2026

Beyond the toolkit: rehearse the care-record outage · 9 October 2026

Develop the analysis

Read the connected flagship reports.

Workforce & delivery: turning sector improvement into dependable care

Digital continuity: can the care service depend on its systems?

Operational assurance: suppliers, equipment and resident voice

Sources, method & limitations

How to read this analysis

The rebuild was checked on 27 August 2026 against current public NHS DSPT guidance, the National Data Guardian's originating review, DHSC adult social care research, NCSC risk-management and exercising guidance, ICO security guidance and CQC Regulation 17 and care-home registration material. It distinguishes framework description, legal or regulatory expectation, DHSC evidence and Care Circle analysis.

  • The article does not assess any named provider's DSPT submission or technical controls and should not be used to infer individual compliance or security.
  • DHSC percentages are self-reported results from fieldwork conducted between December 2023 and April 2024, not live 2026 measures of effectiveness.
  • The detailed DSPT question set is tailored by organisation type and changes over time; this article deliberately avoids presenting one testing method or cadence as mandatory for every social care provider.
  • CQC's business-continuity document cited here is registration guidance for care homes. Regulation 17 is broader, but neither source prescribes the ten practical tests suggested in this analysis.
01Data Security and Protection Toolkit: overview and introductory guidanceNHS England · 2026-08-27Access date shown; primary source for annual self-assessment, tailored requirements, mandatory evidence, 30 June annual deadline and social-care organisation guidance.02Data Security and Protection Toolkit 2025-26 version 8NHS England · 2025-09-18Official publication of the last completed assessment year's evidence items and 30 June 2026 deadline; used only as version context, not to prescribe the 2026-27 question set.03Review of data security, consent and opt-outsNational Data Guardian · 2016-07-06Origin of the 10 standards and the expectation that leaders demonstrate them through audit or objective assurance.04Risk management for cyber securityNational Cyber Security Centre · 2023-03-30Primary guidance distinguishing compliance from security and warning against tick-box risk management.05Exercise in a BoxNational Cyber Security Centre · 2026-08-27Access date shown; primary source for the free, non-specialist cyber exercise resource and its improvement purpose.06A guide to data securityInformation Commissioner's Office · 2023-05-19Primary regulator guidance on timely restoration, regular testing and evaluation, documenting results and acting on findings.07The state of cyber security in adult social care: ministerial foreword and report summaryDepartment of Health and Social Care · 2025-03-24Primary source for the survey methodology, control-presence chart and qualitative concerns about implementation and practical knowledge.08Regulation 17: Good governanceCare Quality Commission · 2025-05-16Regulatory guidance on effective governance systems, risk assessment and mitigation, secure records, and evaluation and improvement of information processing.09Business continuity planCare Quality Commission · 2026-02-02Care-home registration guidance explicitly including IT failures and cyber attacks; scope limitation retained in the article.