Adult social care has achieved something significant.
By the 30 June 2026 deadline, 22,429 CQC-registered adult social care services in England had an up-to-date Data Security and Protection Toolkit, representing almost 76.5% of the sector.
That included 12,887 care homes and 9,562 home-care services.
Almost 14,500 services had published the DSPT for at least three consecutive years, while only 15% of the sector had a current submission when the Better Security, Better Care programme began in 2021.
That progress should not be understated.
A sector often portrayed as digitally immature has embedded a national information-governance framework across tens of thousands of services in only a few years.
The DSPT has helped make conversations about:
data security;
information sharing;
staff responsibilities;
supplier management;
business continuity;
and cyber risk
part of routine care-provider governance.
But success creates the next question.
And it is a harder one.
Can the organisation prove that the controls described in its DSPT are actually operating when nobody is completing the DSPT?
That is the next stage of cyber maturity.
Not more paperwork.
Not another policy.
Not a longer compliance declaration.
Evidence that the safeguards the organisation believes it has really work in everyday care.
The sector is already moving from declaration to verification
Digital Care Hub’s latest work makes this shift unusually clear.
Following a pilot earlier this year, Digital Health Checks are now being rolled out across England to help adult social care providers examine whether their data-protection and cyber-security arrangements work in practice.
Digital Care Hub explicitly distinguishes the two activities.
The DSPT is an annual self-assessment.
The Digital Health Check is designed to explore whether the arrangements described in that assessment are actually being used and where practical improvements may still be required. The review can look at staff awareness, information flows, policies, passwords, software updates, devices and business-continuity arrangements, including a limited technical check where the provider agrees.
That distinction is extremely important.
It tells us where the sector is going next.
The first phase was:
Do we have the right arrangements?
The second is:
Can we demonstrate that they operate effectively?
This is not unique to social care.
The National Cyber Security Centre makes exactly the same distinction in its board-level guidance.
It warns organisations against treating cyber risk as a tick-box compliance exercise and states plainly that compliance and security are not the same thing. A business can meet a common standard while still carrying weak security practices if nobody questions whether the controls genuinely address the organisation’s actual risks.
For adult social care, this is especially important because cyber controls do not exist in isolation.
They sit inside busy, human environments where:
staff change;
agency workers arrive;
devices are shared;
people need information immediately;
suppliers update software;
and managers make daily trade-offs between ease of access and security.
A control can look excellent on paper and behave very differently at 7am on a Saturday morning.
There are four levels between having a policy and having assurance
Care providers may find it useful to think about cyber control in four stages.
The first is design.
The organisation decides what should happen.
For example:
Former employees must lose access promptly.
The second is implementation.
A leavers process exists.
HR tells IT.
Accounts are supposed to be disabled.
The third is operation.
When somebody actually leaves, does the process happen every time, across every relevant system?
The fourth is assurance.
Can the provider test recent leavers and show objectively that access was removed as intended?
That final stage changes the conversation.
A policy is evidence of intention.
A completed checklist is evidence that a process was followed.
Testing is evidence that the control achieved its purpose.
That is what “prove your cyber controls work” really means.
Start with access: who can still see the care system?
Access control sounds technical.
In practice, it is largely an organisational question.
Who currently works here?
What should they be able to see?
What do they no longer need to see?
When should access change?
Care providers have unusually fluid workforces.
Employees:
join;
move between services;
change roles;
go on extended leave;
work bank shifts;
leave;
and sometimes return.
Agency workers may require temporary access.
Managers may support several locations.
Central teams may require wider permissions.
Suppliers may need remote administrative access.
This creates constant movement in the access model.
A provider may truthfully say that it has a leavers procedure.
The more useful assurance is to test it.
Take the last ten people who left the organisation.
Can any of them still access:
email;
care records;
cloud storage;
rostering;
payroll;
or other systems?
Then take employees who changed role.
Did their access reduce where it should have?
A care worker promoted to manager may need additional access.
A manager moving into a different role may need privileges removed.
Cyber risk often accumulates not because somebody deliberately creates excessive access but because access only ever gets added.
Good governance also removes it.
Multi-factor authentication is only useful where it is genuinely present
Multi-factor authentication has become one of the most familiar cyber controls.
Its value is well established because a stolen password alone becomes less useful to an attacker where another authentication factor is required.
But “we use MFA” can conceal a surprising amount of variation.
Does it protect email?
Administrator accounts?
The digital care system?
Cloud storage?
Payroll?
Remote access?
The supplier’s support account?
What happens when staff replace a phone?
Are exceptions created because particular accounts are difficult to configure?
Are shared accounts bypassing the individual authentication model entirely?
The NCSC’s current guidance continues to emphasise strong authentication for access to sensitive information and privileged systems.
For the provider, the assurance question is therefore not:
Do we have MFA?
It is:
Which high-consequence systems can still be reached with only a username and password?
That produces a much clearer risk picture.
A backup is not proven because yesterday’s job showed green
Backups are one of the clearest examples of the difference between control existence and control effectiveness.
A dashboard may say:
Backup successful.
Every night.
For months.
That proves the system performed a copying process.
It does not prove that the provider can recover the information required to run the care service.
The NCSC’s current guidance tells organisations that after creating backups they need to know how to restore them and check that they contain all important data.
That is a much higher standard.
Imagine a ransomware incident takes the care home’s shared drive offline.
The provider discovers it has a backup.
Excellent.
But how quickly can it be restored?
Who has authority to do it?
Where are the credentials?
Does the backup contain yesterday’s information or last week’s?
Does it restore attachments as well as records?
Can the provider recover one file without restoring the whole system?
Has anyone ever actually tried?
And if a third-party supplier controls the backup, what happens when the supplier itself is unavailable?
This is why the most useful backup evidence is not a screenshot showing successful completion.
It is a documented restoration test.
We removed access to this information, recovered it through the agreed process, checked its integrity and confirmed the operation could use it.
That is assurance.
Restore time matters as much as restore success
There is another layer care providers need to consider.
A backup can be usable and still fail the operational requirement.
Suppose the care system can be restored successfully in three days.
Technically, the recovery process works.
Operationally, the service may need current medication and risk information within an hour.
The NCSC’s Cyber Assessment Framework approaches resilience in exactly this way: backups need to be sufficiently frequent and restoration needs to recover essential functions within a suitable timeframe, with routine testing to confirm that both the process and the backup data are usable.
Adult social care therefore needs to connect backup assurance with care tolerance.
How long can the medication process operate without the live system?
How long can home care coordinate calls without the rota?
How long can managers work from an emergency care summary before the information begins becoming outdated?
The answer determines whether the technical recovery arrangement is adequate for the care service.
Software-update policies are easy. Knowing the estate is harder.
Most organisations now understand that unsupported or unpatched software creates risk.
The practical problem is knowing what exists.
A provider may have:
desktop computers;
laptops;
tablets;
mobile phones;
routers;
care technology;
telecare devices;
printers;
smart televisions;
door systems;
and other connected equipment.
Some are organisation-owned.
Some belong to landlords.
Some are supported by suppliers.
Some may have been installed years earlier and quietly forgotten.
The NCSC advises organisations to keep devices and software current and to replace software that no longer receives security updates.
The challenge is not writing the patching policy.
It is answering:
Which device in this service is currently outside that policy?
That requires asset visibility.
A provider cannot prove patch management works if it cannot say what needs patching.
This is another reason cyber maturity eventually becomes an information-quality exercise.
The organisation needs an accurate picture of its own technology environment.
Training is not proven by attendance
Care providers are familiar with this distinction from clinical and care training.
Someone can complete a moving-and-handling course without demonstrating competence in practice.
Cyber training is no different.
A training dashboard can show 100% completion.
That proves everyone finished the course.
It does not prove the workforce knows what to do when an unusual message arrives.
Or when a laptop is lost.
Or when an employee receives an unexpected MFA approval request.
Or when the digital care system suddenly begins behaving strangely.
The government’s latest Cyber Security Breaches Survey found that phishing continued to dominate cyber crime, accounting for 93% of businesses that experienced a cyber crime. It also found that only a minority of UK businesses had formal incident-response arrangements in place: 39% had assigned incident roles, 34% had written guidance on who to notify and 25% had a formal incident-response plan.
The overall survey is not specific to care providers.
It still reinforces a broader organisational lesson.
Cyber resilience depends on people recognising a problem and escalating it quickly enough for somebody else to act.
The strongest test is therefore not:
Did staff complete cyber training?
It is:
When presented with a realistic incident, do staff recognise what matters, stop the risk getting worse and know exactly who to contact?
Test the night shift, not just the management team
There is a simple reason cyber exercises can produce false reassurance.
The people most involved in creating the plan are often the people most likely to be present during the exercise.
They know:
where the continuity plan is;
who the IT supplier is;
which director needs calling;
where the offline records sit;
and what the policy says.
A real incident may begin when none of them is on site.
At 2.20am.
With one senior carer and three care workers on duty.
That is the test that matters.
Can the night team recognise that the issue may be more serious than “the computer isn’t working”?
Do they know who to call?
Are emergency contact details available when email and the shared drive cannot be accessed?
Do they know where current care information is held?
Can they explain the problem clearly enough for support staff to act?
Cyber resilience needs to survive beyond office hours because care does.
The incident plan should be rehearsed, not admired
The NCSC provides a free resource called Exercise in a Box specifically to help organisations practise their response to cyber incidents in a safe environment. The exercises include ransomware, phishing, supply-chain attacks, vulnerabilities and other common scenarios, and the NCSC describes exercising as a way to identify whether defences and decision-making actually work before a real incident occurs.
This is particularly well suited to adult social care because the test does not have to be highly technical.
A useful care-home exercise could begin with one sentence:
The digital care record and eMAR supplier has confirmed a cyber incident. Both platforms are unavailable and the supplier cannot yet estimate recovery time.
Then watch what happens.
Who takes control?
Who thinks first about residents?
Who phones the supplier?
Who finds the contingency information?
Who informs senior management?
Who considers whether the data itself may be compromised?
Who records decisions?
Who thinks about the next medication round?
Who contacts families if disruption becomes prolonged?
The exercise will almost certainly identify gaps.
That is a successful exercise.
The purpose is not to prove the plan was perfect.
It is to find weaknesses while nobody is being harmed by them.
CQC already expects continuity arrangements to be more than theory
Cyber resilience is increasingly linked directly with care continuity.
CQC’s current care-home registration guidance requires a business-continuity plan explaining how the service will keep running during and after serious disruption. Cyberattack and IT-system failure are explicitly among the scenarios providers are expected to consider, alongside issues such as power loss and other emergencies.
This should change how providers think about cyber assurance.
A continuity plan should not be judged only by whether it contains the right sections.
It should be judged by whether staff could use it.
Is the information current?
Are contact details valid?
Can the plan be reached if the main network is down?
Do temporary working methods still reflect the service as it operates today?
Has the plan been updated since the provider introduced eMAR or changed care-record supplier?
Has it been tested after an acquisition?
Every major digital change potentially changes the continuity model.
The control needs to evolve with the service.
Supplier assurances need testing too
Our previous feature, Your Supplier Is Part of Your Attack Surface, examined how external providers extend the organisation’s cyber environment.
The same principle applies here.
A supplier may state that it maintains:
backups;
disaster recovery;
security monitoring;
penetration testing;
and strong access controls.
Those statements may be completely accurate.
The care provider still needs to understand what they mean for its own operation.
What is the expected recovery time?
When was recovery last tested?
What information can the provider access if the platform is unavailable?
How will the supplier communicate during a major outage?
Do support arrangements operate overnight?
Can administrators from the supplier access the provider’s environment, and how is that access controlled?
A provider cannot personally test every control inside a major technology supplier.
It can ask for proportionate evidence and understand the service commitments on which its care model relies.
Assurance should follow criticality.
The supplier storing the lunch menu does not require the same level of scrutiny as the organisation controlling the electronic medication system.
Policy exceptions may tell you more than the policy itself
Every real organisation contains exceptions.
An old laptop that cannot run the latest software.
A shared account retained because one application does not support individual users.
A senior employee who needs wider access.
A device that cannot support MFA.
A supplier requiring a particular remote-access method.
The existence of an exception does not automatically mean cyber governance is weak.
Uncontrolled exceptions do.
A mature provider knows:
what the exception is;
why it exists;
who approved it;
what additional risk it creates;
what compensating control is in place;
and when it will be reviewed.
This is often where practical assurance provides much more insight than a policy audit.
The standard process may be strong.
The residual risk is frequently concentrated in the few places where the standard process could not be followed.
Cyber metrics can look reassuring while hiding the real risk
Boards increasingly receive cyber dashboards.
Training compliance: 98%.
Updates completed: 96%.
Backup success: 100%.
MFA enabled: 95%.
Open cyber incidents: zero.
All of those measures can be useful.
None is conclusive on its own.
The NCSC warns boards to use risk metrics carefully because numerical measures can be misinterpreted without context.
A 95% MFA figure sounds strong.
What if the missing 5% includes the administrator account capable of controlling the complete network?
A 96% patching rate sounds excellent.
What if the unpatched device is the internet-facing server?
A 100% backup-success rate sounds reassuring.
What if nobody has successfully restored one in 18 months?
The board therefore needs to understand consequence as well as percentage.
The best cyber dashboard does not merely say how many controls are complete.
It shows where the most important ones remain uncertain.
Care Circle Network Intelligence Insight
The next cyber question is not who has a DSPT. It is what the DSPT now tells us to ask.
Care Circle Network’s Provider Intelligence Observatory gives us a useful perspective on this next stage of cyber maturity.
The Observatory brings together more than 30,000 care-related locations with service model, provider structure, scale, bed capacity, estate and connectivity context, DSPT organisation and status information and wider operational themes including cyber/data governance and connectivity/digital care resilience.
This matters because the same cyber framework operates across organisations with very different operating realities.
Our intelligence includes independent single-location services, small groups and much larger multi-site providers. It also includes examples where current DSPT evidence sits alongside materially different property, connectivity, care-model and supplier-resilience contexts.
That means the presence of a DSPT should not become the end of the Care Circle Network cyber conversation.
It should help determine the next question.
For a single-location provider, that may be whether an outsourced IT company has too much knowledge concentrated in one relationship and whether backups have ever been restored.
For a multi-site provider, the greater risk may be inconsistent control implementation between locations.
Head office may enforce MFA.
One acquired service may still have legacy shared accounts.
A central patching policy may exist.
One older site may contain unsupported technology nobody has brought into the corporate asset register.
A home-care provider may have good central governance while staff operate across personal mobile devices and variable connectivity.
A residential service may have much deeper dependence on local Wi-Fi, eMAR and connected equipment.
The Provider Intelligence Observatory does not declare an individual provider cyber secure because a DSPT record exists, nor does a missing matched DSPT entry prove poor security. Current technical controls, suppliers, implementation and operating practice require direct qualification. That distinction is part of the Observatory’s governance approach.
Its value is something more useful.
It allows us to understand where different forms of operational evidence are likely to matter most.
The same compliance framework can sit above very different cyber-risk environments.
That is exactly why practical assurance needs to be proportionate to the provider.
Large groups need evidence of consistency
Large providers often have stronger central cyber capability.
They may have dedicated IT staff, formal governance and sophisticated systems.
Their challenge can be consistency.
Thirty locations mean thirty physical environments.
Acquisitions may introduce legacy systems.
Different services may use different devices or suppliers.
Local managers may implement central policy differently.
The existence of a corporate control therefore does not prove that the control operates identically at every location.
A multi-site provider should be able to sample.
Not inspect everything constantly.
Sample intelligently.
Test:
different regions;
recent acquisitions;
older buildings;
different care models;
and locations with unusual supplier arrangements.
If the organisation says every leaver loses access within a defined period, test it across several services.
If it says all devices receive updates, test the oldest sites rather than only head office.
The objective is not to catch local managers out.
It is to establish whether central governance survives decentralised operation.
Smaller providers should not be expected to build a cyber department
The opposite mistake is to assume that meaningful assurance requires sophisticated security teams and expensive external audits.
It does not.
Digital Care Hub’s new Digital Health Check model is deliberately aimed largely at small and medium-sized providers and describes itself as practical, supportive and not pass-or-fail.
The NCSC’s Exercise in a Box is free and specifically designed so organisations do not need specialist expertise to use it.
Good assurance for a small provider may be remarkably straightforward.
Can we restore the backup?
Did the last employee who left lose access?
Are our laptops supported and updated?
Can staff explain what they would do after a phishing message?
Do we know who to call if the care software stops?
Can we operate if it remains down until tomorrow?
These tests cost far less than recovering from the weaknesses they may identify.
Cyber maturity is not measured by the size of the cyber budget.
It is measured by how well the organisation understands and manages its real exposure.
Evidence should be retained with purpose
One danger of moving towards stronger assurance is creating another huge compliance archive.
That is not the objective.
Evidence should be proportionate.
If the provider tested backup recovery, retain:
the date;
system tested;
result;
time taken;
problem identified;
and corrective action.
If leaver access was sampled, retain the sample and outcome.
If a tabletop exercise took place, record:
what scenario was used;
which decisions were difficult;
what failed;
and what changed afterwards.
The record is valuable because it demonstrates organisational learning.
Not because it makes the cyber folder thicker.
The strongest assurance evidence answers:
What did we test, what did we discover and what became safer afterwards?
The cyber control should eventually produce a care outcome
This is where the subject returns to what matters.
The reason to remove old access is not to achieve a green governance score.
It is to prevent unauthorised people reaching sensitive information.
The reason to update software is not to complete the patch dashboard.
It is to reduce exploitable vulnerability.
The reason to restore backups is not to satisfy an audit.
It is to make sure the service can recover information when people depend upon it.
The reason to practise cyber response is not to perform well in an exercise.
It is to reduce confusion when a real incident threatens continuity.
Care providers should resist allowing cyber security to become an independent compliance industry operating beside the service.
Its value must ultimately be visible in:
safer information;
stronger continuity;
faster response;
less operational disruption;
and greater confidence that people can continue receiving appropriate care.
Ten tests every care provider could run
- Take the last five leavers. Can any still access a work system?
- Choose one important account. Is MFA genuinely enforced, including for privileged users?
- Take the oldest device still in use. Is it supported and receiving security updates?
- Restore one critical backup and confirm the recovered information is usable.
- Ask a frontline worker what they would do after receiving a suspicious MFA request or phishing message.
- Simulate loss of the digital care system during a medication round. Does the continuity process work?
- Choose one critical supplier and establish exactly how an incident would be communicated outside office hours.
- Check one location against the central cyber policy. Does local practice match corporate intent?
- Review every known cyber exception. Is the risk documented, controlled and still necessary?
- Ask the board what cyber control it is least confident has actually been tested.
The point is not to score ten out of ten.
The point is to discover what the organisation previously only assumed.
The strongest cyber question is changing
For several years, the sector’s most important question was:
Have we got the DSPT in place?
That work has produced an important change.
More than 22,000 services now have a current submission.
That is a foundation worth protecting.
But mature governance does not stop once the framework is established.
It moves from:
policy to practice;
practice to evidence;
evidence to testing;
and
testing to improvement.
The rollout of Digital Health Checks across England is a clear signal that adult social care is already moving in this direction.
The NCSC’s guidance makes the underlying principle even clearer: tick-box compliance can create overconfidence, and security has to be understood through the risks the organisation is actually trying to manage.
That gives care providers an opportunity.
The next stage of cyber resilience does not require rejecting the DSPT.
It requires getting more value from it.
Take the statement made in the annual self-assessment.
Find the control underneath it.
Then test the control where real care happens.
On the shared device.
At the remote branch.
With the night team.
At the older service.
Through the supplier.
During the restore.
And when something fails.
Because the most dangerous cyber weakness is sometimes not a control that does not exist.
It is a control everyone believes exists because nobody has ever tested it.
DSPT tells the organisation what good arrangements should look like.
The next step is proof.
And in a sector where digital systems increasingly support medicines, care records, communications and continuity, that proof is becoming part of good care governance itself.
Frequently Asked Questions
Is the DSPT still important for adult social care?
Yes. The DSPT remains an important annual self-assessment for data security and information governance. By 30 June 2026, 22,429 CQC-registered adult social care services had a current DSPT. The point of this feature is not to replace it, but to build practical assurance on top of it.
What is the difference between the DSPT and a Digital Health Check?
Digital Care Hub describes the DSPT as an annual self-assessment. Its new Digital Health Check is a separate practical support service intended to examine whether data-protection and cyber arrangements are working in everyday practice and where improvement may be useful.
Does passing a cyber standard prove an organisation is secure?
No standard can prove that an organisation will never suffer an incident. The NCSC specifically warns that compliance and security are not identical and that tick-box compliance can create overconfidence if the organisation does not consider its actual risks.
How can a provider test backups?
A practical test involves restoring data through the actual recovery process and checking that the recovered information is complete and usable. The NCSC explicitly advises organisations to know how to restore backups and verify that important information is present.
Do small care providers need penetration testing and complex cyber audits?
Not necessarily. Assurance should be proportionate to risk. Simple access reviews, backup restorations, staff scenarios, device checks and tabletop exercises can provide meaningful evidence. Digital Care Hub and the NCSC both provide practical resources suitable for smaller organisations.
Why test incident-response plans?
Because possession of a plan does not establish that people can use it. The NCSC’s Exercise in a Box is specifically designed to help organisations rehearse decisions, test policies and identify areas requiring improvement before a real incident.
Is cyber still a major business issue in 2026?
Yes. The government’s 2025/26 Cyber Security Breaches Survey found that 43% of UK businesses identified a breach or attack in the previous 12 months; the equivalent figure for the health or social care business category was 33%, although that sector estimate was based on a relatively small sample and should be interpreted with appropriate caution.
Care Circle Network Intelligence Insight
This feature has been informed by Care Circle Network’s Provider Intelligence Observatory, our sector-wide intelligence capability bringing together provider structure, care model, estate and connectivity context, DSPT information and wider operational indicators across more than 30,000 care-related locations. The Observatory can help shape provider-specific cyber conversations by service model, scale and available readiness evidence, but it does not treat a current DSPT as proof of control effectiveness or infer an individual organisation’s live technical position without direct qualification.
Editorial sources
This feature draws on Digital Care Hub’s July 2026 DSPT adoption figures and its current Digital Health Checks programme, which is being rolled out across England specifically to help providers test whether their arrangements operate in practice. It also uses the National Cyber Security Centre’s current guidance on avoiding tick-box compliance, testing backups and exercising cyber response, alongside the government’s 2025/26 Cyber Security Breaches Survey and CQC’s current business-continuity expectations for care homes.
