It is 6.15am.
The night team tries to open the digital care record.
Nothing loads.
The electronic medication system is unavailable.
The rota cannot be accessed.
Email is down.
The provider’s software supplier has posted a short message confirming that it is investigating a security incident.
There is no estimated recovery time.
The morning medication round starts shortly.
One resident’s insulin changed yesterday.
Another person’s swallowing guidance was updated following a speech and language review.
A third resident communicates pain through behaviour rather than speech.
An agency worker has just arrived for their first shift at the home.
The technology team may describe what is happening as a cyber incident.
For the registered manager, it has already become something else.
It is a care-delivery incident.
That is the point at which the conversation about cyber security in adult social care needs to change.
For years, the sector has understandably focused on passwords, phishing, malware, data protection and preventing unauthorised access.
Those controls remain essential.
But the extraordinary pace of digitisation means the more difficult question is now becoming:
What happens to the people receiving care when the technology on which safe care increasingly depends is suddenly unavailable?
This is not theoretical.
On 28 July, the National Cyber Security Centre published new guidance specifically for organisations facing highly disruptive cyber attacks. Its warning is significant: serious incidents can disable critical systems, prevent normal operation and take weeks or even months to recover from. Organisations may have to introduce temporary workarounds while rebuilding towards what the NCSC calls minimum viable operations before full service can eventually return.
For a care home, that raises one defining question.
What does minimum viable care look like?
Adult Social Care Has Become Digitally Dependent
The benefits of digital care are increasingly well established.
CQC says good digital records can help staff capture information at the point of care, respond more quickly to changing needs, share important information securely and reduce safety risks. It also acknowledges that digital systems will increasingly become essential to how care information is captured and shared.
The national adoption figures show how far that transition has progressed.
As of March 2026, an estimated 83.7% of CQC-registered adult social care provider locations in England had a digital social care record, compared with 76.8% a year earlier. An estimated 92% of people receiving regulated adult social care were covered by one.
Inside a modern care home, that digital dependency usually extends much further.
The care record may contain information about personal routines, mobility, nutrition, communication, capacity, behaviour and safeguarding.
eMAR may guide medication administration.
Rostering software tells managers who should be working.
Learning platforms hold competence records.
Incident systems support safeguarding and quality oversight.
Cloud email connects services to GPs, pharmacies, commissioners and families.
Sensors, nurse-call systems and telecare may help detect events requiring urgent intervention.
The care home has therefore not simply digitised its paperwork.
It has moved parts of its operating memory into technology.
That creates enormous opportunity.
It also changes what system failure means.
A server outage is no longer merely inconvenient if the information stored behind it influences what medicine somebody receives, whether two staff are needed for a transfer or how employees should respond when a person becomes distressed.
Cyber Risk Is Already a Material Sector Issue
The most care-specific national research remains the Department of Health and Social Care’s study of cyber security in adult social care.
A third of participating providers reported experiencing a cyber incident or unsuccessful attack during the preceding three years. Among those affected, phishing was by far the most common type, while impersonation was also significant.
Perhaps most importantly, 44% of reported attacks among affected providers originated from a third-party organisation, rather than entirely within the provider’s own systems. The research also identified sector vulnerabilities including highly sensitive personal data, uneven digital maturity and dependence on a relatively small number of technology suppliers.
That study should not be treated as a live measurement of today’s attack rate; its fieldwork predates 2026.
But more recent national evidence points in the same direction.
The government’s Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses overall identified a cyber breach or attack during the previous 12 months. For the grouped health and social care sector the figure was 33%. The sector estimate was based on a relatively small sample and should therefore be interpreted cautiously, but it provides a current indication that cyber exposure remains an active operational issue.
Cyber is therefore not a hypothetical future concern being imported into social care from banking or technology.
It is already part of the operating environment.
The Most Dangerous Assumption Is That a Cyber Attack Will Be Short
Many continuity plans are built unconsciously around the idea of inconvenience.
The internet fails for an hour.
The software supplier experiences a morning outage.
Staff temporarily write something down.
The system returns before the next shift.
A highly disruptive cyber event can be fundamentally different.
The NCSC’s new guidance explicitly describes recovery in terms of hours, days, weeks and potentially months.
The early objective may not be restoration of business as usual.
It may simply be restoring enough capability for the organisation to operate at a minimum viable level while the investigation, containment and rebuild continue.
For a care home, this distinction is enormous.
A workaround that is acceptable for 45 minutes may become unsafe over three days.
A printed care summary may support an emergency shift but become increasingly unreliable as:
- medication changes;
- new incidents occur;
- people’s health deteriorates;
- wounds change;
- risks are reassessed;
- and temporary care decisions accumulate outside the unavailable digital system.
The longer the outage lasts, the more the problem changes.
At first it is about accessing information.
Then it becomes about maintaining a new reliable version of the truth.
Minimum Viable Care Is Not Minimum Quality
The NCSC’s language of minimum viable operations is extremely useful for adult social care, provided it is interpreted correctly.
For a care home, minimum viable care cannot mean reducing care to the lowest possible service level.
It means identifying the functions that must continue without interruption because people could otherwise face unacceptable harm.
That begins with the resident rather than the technology.
A service should be able to identify the information and capabilities without which it cannot reliably maintain safe care.
That includes medicines, personal risks, communication, nutrition, mobility, safeguarding, emergency contacts, staffing and escalation.
The relevant question is not:
Which applications are business critical?
It is:
Which care activities are safety critical, and what technology do they currently depend upon?
Once leaders answer that question, the digital dependencies become much clearer.
Medicines Could Become the First Critical Test
Electronic medication systems have brought significant benefits to adult social care.
They can improve visibility, create audit trails, support alerts and reduce some forms of transcription risk.
That usefulness makes their unavailability more consequential.
Imagine an eMAR platform becomes inaccessible immediately before a medication round.
Staff need to know not simply what medicines somebody takes, but potentially:
- which doses were administered previously;
- recent changes;
- allergies;
- refusals;
- PRN instructions;
- variable doses;
- time-critical medicines;
- covert administration arrangements;
- and monitoring requirements.
The home may possess an offline or printed record.
The crucial question is when that record was created.
An offline medication summary produced yesterday can already be wrong if a prescription changed this morning.
The problem is therefore not solved simply by saying:
We keep paper copies.
A safe continuity arrangement needs to establish currency, ownership and reconciliation.
Who updates the offline information?
How often?
Where is it stored securely?
What happens if both the eMAR and internet are unavailable?
Who contacts the pharmacy or prescriber if information conflicts?
How does the service prevent duplicate administration when the live platform returns?
The final point is often overlooked.
The system coming back online is not the end of the incident.
It begins another high-risk stage.
Recovery Creates a Second Patient-Safety Risk: Reconciliation
During an outage, the care home begins generating a second stream of information.
Medicines may be recorded manually.
Care notes may be written on temporary sheets.
Incidents may be logged separately.
Changes in health may be recorded outside the normal care record.
Staff may create local handover notes.
Then the system returns.
The provider now potentially has two versions of the care history:
the digital record before the outage
and
the temporary operating record created during it.
Those records have to be reconciled carefully.
A rushed recovery can create:
- duplicate medication records;
- missing incidents;
- incorrectly backdated notes;
- contradictory care plans;
- lost escalation decisions;
- and an audit trail that no longer accurately reflects what happened.
This is one reason cyber recovery must be owned jointly by operational and care leadership rather than treated purely as an IT restoration.
The technical team can tell the provider that the platform is accessible.
The registered manager needs to establish whether the information within it is now safe to rely upon.
The Agency Worker Test Exposes Whether the Continuity Plan Really Works
A useful way of testing cyber resilience is to imagine the service being run by someone who does not carry its knowledge in their head.
Permanent staff often compensate for system weakness through familiarity.
They know:
- which resident needs reassurance before personal care;
- whose swallowing difficulties have recently increased;
- where equipment is stored;
- which relative should be contacted;
- and which behaviours may indicate pain.
That organisational memory can hide poor continuity planning.
Now replace one experienced employee with an agency worker who has never worked at the home before.
The digital system is unavailable.
Can the provider still give that person enough accurate information to work safely?
If the answer depends on another member of staff verbally remembering everything, the organisation does not have a reliable cyber-continuity solution.
It has knowledgeable employees compensating for one.
That distinction becomes particularly important overnight, at weekends and during periods of high absence when the most experienced people may not be present.
Supply-Chain Cyber Risk May Be the Biggest Blind Spot
One of the most important conclusions from DHSC’s adult social care research is that providers do not control their complete cyber exposure.
Almost half of reported attacks among affected providers originated from third parties.
That should fundamentally influence technology procurement.
A care home may use excellent passwords, multi-factor authentication and staff training and still lose a critical service because the software supplier itself is compromised.
The wider UK regulatory direction reflects exactly this concern.
The government’s Cyber Security and Resilience Bill proposes bringing qualifying medium and large managed service providers within the UK’s Network and Information Systems regime because their privileged access across numerous customers can create severe one-to-many consequences when one supplier is compromised. Relevant regulated providers under the proposed regime would also face strengthened incident-reporting requirements, including an initial notification within 24 hours and fuller reporting within 72 hours for significant incidents.
That does not mean an ordinary care home automatically falls within those specific proposed reporting duties.
The important message for social care is the policy logic behind the change:
government increasingly recognises technology suppliers themselves as part of national cyber-resilience infrastructure.
Care providers should begin asking suppliers more difficult questions.
Not merely:
Is your platform secure?
But:
How will my care home operate when your platform is unavailable?
Procurement Needs a Failure Conversation
Digital procurement tends to concentrate on normal operation.
Providers want to know:
- what the software does;
- how easy it is to use;
- how much it costs;
- how data is migrated;
- what dashboards it provides;
- and how quickly staff can be trained.
Those questions are necessary.
Cyber resilience requires another conversation before the contract is signed.
What happens if the supplier is offline for 24 hours?
What happens for seven days?
Does the provider receive current offline information?
Who owns backups?
How often are recovery processes tested?
What happens if the supplier itself suffers ransomware?
How will it communicate when its normal support systems are unavailable?
What is the escalation route outside normal office hours?
How easily can the provider export its complete records if the supplier experiences sustained failure or ceases trading?
These are not technical procurement details.
They are care-continuity questions.
The strongest digital suppliers will increasingly be differentiated not only by how well their products operate but by how effectively they help customers survive their failure.
DSPT Completion Is an Important Milestone—Not the Finish Line
The sector has made significant progress on data security.
By the 30 June 2026 deadline, 22,429 CQC-registered adult social care services had a current DSPT, including 12,887 care homes. That represents almost 76.5% of registered services and a dramatic increase from only 15% in 2021.
This deserves recognition.
But the next phase matters even more.
Digital Care Hub is now rolling out free Digital Health Checks after an early-2026 pilot specifically to help providers establish whether their documented data-protection and cyber arrangements are working in practice. The programme describes adult social care as becoming “digital by default” and focuses on finding gaps between policies, systems and everyday practice before those weaknesses become incidents.
That captures the distinction perfectly.
A cyber policy states what should happen.
A real or simulated outage establishes whether it can happen.
A backup policy says information is protected.
A restoration exercise establishes whether it is usable.
A continuity document says staff will revert to alternative processes.
A tabletop exercise establishes whether night staff know what those processes actually are.
The DSPT should therefore be the foundation of cyber resilience.
It should not become a certificate that allows the organisation to stop asking difficult questions.
CQC Has Already Connected Digital Continuity With Safe Care
This is no longer an issue sitting outside regulation.
From February 2026, CQC’s registration requirements for care homes explicitly require a business continuity plan.
CQC says the purpose is to show how the service will keep operating during and after disruption. Its current guidance specifically requires care homes to consider IT system failures and cyber attacks, demonstrate backup and data-recovery arrangements, set out how normal service will be restored, and explain how plans will be tested and reviewed.
That is a significant regulatory signal.
CQC also lists business-continuity plans among the process evidence it may consider when assessing Safe environments, alongside risk assessments and evidence that equipment, facilities and technology support safe care.
The regulatory logic is clear.
Cyber resilience is not merely about protecting confidential data.
It is part of keeping the environment and systems supporting care safe.
That makes cyber a resident-safety and governance issue, not simply an IT responsibility.
Care Homes Need a Cyber Continuity Plan, Not Just a Generic Business Continuity Plan
A generic continuity plan may contain sections covering:
- fire;
- flood;
- pandemic;
- loss of utilities;
- and staffing shortages.
Cyber disruption behaves differently.
A fire may remove access to a building while leaving cloud information available elsewhere.
A cyberattack may leave the building perfectly intact while removing access to the information required to operate it.
That difference changes the response.
During cyber disruption, leaders must consider whether information can be trusted.
A compromised account may still appear operational.
A recovered file may be incomplete.
A network may need to remain disconnected while investigation continues.
Employees may be instructed not to connect particular devices.
The provider may need to operate simultaneously across:
- functioning technology;
- unavailable technology;
- temporary paper;
- and reconstructed information.
That is far more complex than simply “going back to paper.”
“We Can Go Back to Paper” Is Not a Continuity Strategy
This phrase sounds reassuring because paper feels familiar.
But many modern care homes no longer maintain a complete parallel paper record.
Nor should they necessarily do so.
The digital record may contain thousands of changing pieces of information that would be impossible to duplicate continuously.
The issue is therefore not whether the provider can reproduce its entire system offline.
It is whether it has identified the minimum critical information required to continue safe care.
That should be deliberate.
For example, if the digital record disappeared at midnight, which information would staff need immediately before 8am?
Which information can wait?
Which information must be confirmed externally?
Which residents have the greatest risk if guidance is unavailable?
Which actions must continue regardless of the technology?
The best continuity pack is not necessarily the thickest one.
It is the one that gives staff the right information at the right moment without creating a second uncontrolled record system.
Backups Matter—but Restoration Matters More
DHSC’s adult social care research found that a large majority of participating providers reported backing up data, and most were confident those backups were complete and usable.
Confidence is encouraging.
Testing creates assurance.
The provider should understand the difference between:
a backup completed successfully
and
a care service restored successfully.
Restoration may require more than recovering data.
The organisation may need:
- application infrastructure;
- user accounts;
- authentication;
- device configuration;
- integrations;
- internet connectivity;
- supplier access;
- and validation that the recovered information is current.
A recovered database that staff cannot access is not operational recovery.
A restored application containing records from three days earlier is not complete recovery.
And an application that technically works but has not reconciled the temporary care delivered during the outage is not yet safe business as usual.
Staff Behaviour Is Often a Design Issue, Not a Training Failure
Cybersecurity commentary can place too much responsibility on employees.
Staff do sometimes make mistakes.
Phishing remains a major attack route.
Training matters.
But insecure behaviour can also emerge because systems are poorly designed around the reality of care.
DHSC’s research identified concerns around shared accounts, use of personal devices and resource limitations across parts of the sector.
Consider a care team sharing too few devices.
Employees need information quickly.
Several staff require access during medication, handover and care delivery.
The official process may require repeated logins, authentication and device handover.
If that operating model creates constant delay, workers may begin developing shortcuts.
Passwords get shared.
Sessions remain open.
Information gets photographed or written down.
The provider may describe this as non-compliance.
But the vulnerability may partly originate in the resources and workflow the organisation created.
Strong cyber governance therefore asks:
Have we made secure behaviour practical during real care?
Security that works only when employees have unlimited time is not robust security.
Cyber Recovery Has a Workforce Cost
Even when nobody is physically harmed, a major cyber incident can place enormous pressure on employees.
DHSC’s sector research found that additional staff time was one of the most frequently reported impacts among affected providers.
That makes intuitive sense.
During an outage, employees may have to:
- locate information manually;
- repeat documentation;
- phone colleagues;
- verify medicines;
- reassure families;
- support temporary processes;
- and later reconcile everything when systems return.
Managers carry an even greater burden.
They may simultaneously be handling:
- resident safety;
- staff allocation;
- technical suppliers;
- commissioners;
- CQC;
- data-protection decisions;
- families;
- and senior leadership.
A cyber-recovery plan that calculates only technology cost misses this operational load.
The provider should consider who will support the workforce during a prolonged incident.
Who takes over routine management duties?
Who coordinates the response?
Can managers work in shifts rather than remain continuously on call?
How will temporary recording workload be controlled?
A care home that restores its technology but exhausts the team required to use it has not completed its recovery.
The Resident and Family Communication Problem
Cyber incidents are also trust events.
Residents and families may reasonably want to know:
- Is my relative safe?
- Has their personal information been accessed?
- Are medicines being given correctly?
- Will care continue?
- When will normal systems return?
- Should I do anything?
The provider may not have complete answers immediately.
That does not mean silence is the safest response.
Good crisis communication distinguishes between:
- what is known;
- what remains under investigation;
- what the organisation is doing;
- and when the next update will be provided.
The care home also needs alternatives if its usual communication tools are unavailable.
An emergency contact plan stored only in the compromised email system is not an emergency contact plan.
Cyber Insurance Does Not Solve Minimum Viable Care
Insurance can be an important part of the provider’s wider risk strategy.
Depending on the policy, it may contribute to specialist response, technical investigation, legal support, restoration costs, interruption or liability.
But this article deliberately starts somewhere else.
A policy cannot decide which resident must be prioritised when systems fail.
It cannot produce a safe offline medication process.
It cannot brief the agency worker.
It cannot reconcile temporary care records.
And it cannot maintain trust with residents during an extended outage.
Insurance can help fund consequences.
Operational resilience determines how severe those consequences become.
That is why cyber insurance and cyber preparedness should complement each other rather than be confused.
The 24-Hour Care Home Cyber Test
Every care-home board, owner, nominated individual and registered manager should be able to work through one simple scenario:
At 6am tomorrow, digital care records, eMAR, email and the rota become unavailable for 24 hours. The supplier cannot confirm when they will return.
Then ask:
- How will we confirm morning medicines safely?
- How will every staff member access essential current care information?
- How will we identify who is expected to work?
- What happens when new agency staff arrive?
- How will we record care, incidents and changes during the outage?
- How will we contact families, GPs, pharmacies and commissioners?
- Who leads the operational response, and who leads the technical response?
- Which supplier escalation routes work outside normal office hours?
- How will we know recovered information is accurate?
- Who owns reconciliation when the systems come back?
That is the one list I would put into the published article prominently.
Because if a provider cannot answer those questions today, the vulnerability already exists—even if an attack has never occurred.
The More Important Test Is 72 Hours
Twenty-four hours will reveal obvious weaknesses.
Seventy-two hours reveals the operating model.
By day three:
- medicines will have changed;
- care-plan information may have changed;
- staff shifts will have changed;
- new incidents will have occurred;
- appointments may need managing;
- payroll or timesheets may be affected;
- and temporary paperwork will have grown substantially.
The home may also be operating with employees who were not present when the outage started.
This is where continuity becomes a governance challenge.
The organisation needs one reliable process for communicating what has changed while its normal source of truth remains unavailable.
That is far harder than keeping a handful of emergency printouts.
And the Real Scenario May Last Much Longer
The NCSC’s latest guidance is important precisely because it encourages leaders to abandon the assumption that everything returns quickly.
A highly disruptive attack may require a programme of containment, investigation and rebuilding lasting weeks or months. Temporary ways of operating may remain necessary while the organisation progressively restores minimum viable functions and eventually returns to normal.
For a care home, that means the business continuity plan needs a second horizon.
Not only:
What do we do tomorrow?
But:
What happens if our core supplier tells us the platform will not be safely restored this week?
At that point the provider may need to establish a temporary operating model capable of functioning reliably for longer.
That may require:
- controlled interim record systems;
- additional staff;
- alternative technology;
- secure communications;
- external technical support;
- and potentially significant management resource.
The transition from emergency workaround to sustainable temporary operation should be planned rather than improvised.
Senior Leaders Need to Own Cyber as a Care Risk
The 2025/26 Cyber Security Breaches Survey found that 38% of sampled health and social care businesses had a board member or trustee with explicit responsibility for cyber security.
That suggests considerable room for stronger senior ownership.
Cyber cannot sit entirely with:
- the outsourced IT company;
- the office administrator;
- or the employee who happens to understand computers.
The provider’s leadership must understand enough to challenge assurance.
Not technical detail for its own sake.
Practical care consequences.
A board should know which technology failure would affect residents most quickly.
It should know when backups were last restored rather than merely backed up.
It should know which suppliers could take several services offline simultaneously.
It should know whether an outage has been rehearsed.
And it should understand what remains dependent on one person’s knowledge.
That is what mature cyber governance looks like in social care.
The Opportunity Is Not to Become Less Digital
There is a danger that cyber discussions become so risk-focused that the obvious conclusion appears to be:
Technology has made care unsafe.
That would be wrong.
Digital care records, eMAR, connected systems, sensors and better data have the potential to make care:
- safer;
- more visible;
- more consistent;
- and more responsive.
The answer is not retreat.
It is maturity.
Care homes have moved through the first digital question:
Do we have the technology?
They are now entering the second:
Does it improve care?
Cyber resilience introduces the third:
Can we depend on it safely?
That is a much more sophisticated standard.
When the Care Home Goes Offline
The strongest cyber-resilient care home is not necessarily the one claiming that an attack cannot happen.
No organisation can make that promise credibly.
It is the service that understands exactly what happens when protection fails.
It knows:
- what information people cannot safely be cared for without;
- where that information exists;
- how employees access it;
- how medicines continue;
- how temporary records are controlled;
- how suppliers are escalated;
- how staff are supported;
- and how information is reconciled when technology returns.
It has tested those assumptions.
It has learned from the test.
And it has changed the service before a real attacker is given the opportunity to expose the weakness.
CQC’s increasing focus on business continuity and cyber resilience reflects an important reality.
Digital systems have become part of the care environment.
Their resilience therefore forms part of safe care.
The next cyber conversation in adult social care should not be dominated by hackers, ransomware graphics and technical terminology.
It should begin with the resident.
Because the most important cyber question facing a care home is not:
Can we stop somebody getting into our systems?
It is:
Can we keep people safe when somebody does?
Cyber resilience is no longer measured only by whether the care home can protect its technology.
It is measured by whether the care home can protect its residents when that technology is no longer there.
Frequently Asked Questions
Is cyber security a serious current issue for care homes?
Yes. Cyber exposure is increasingly relevant because adult social care is becoming digitally dependent. Current government survey data indicates cyber incidents remain common across UK businesses, while dedicated DHSC research has identified specific vulnerabilities in adult social care including sensitive data, supplier dependency and uneven digital maturity.
How widely are digital care records now used?
As of March 2026, an estimated 83.7% of CQC-registered adult social care provider locations in England had a digital social care record, covering an estimated 92% of people receiving regulated adult social care.
Does having a current DSPT mean a care home is cyber resilient?
Not necessarily. DSPT provides an important framework for data security and protection, but practical resilience also requires tested backups, staff capability, incident response, supplier assurance and functioning continuity arrangements. Digital Care Hub is now offering Digital Health Checks specifically to test whether arrangements work in practice.
Does CQC expect care homes to plan for cyber attacks?
Yes. CQC’s current registration guidance requires care-home business continuity plans to address risks including IT-system failure and cyber attacks, with backup, recovery and testing arrangements.
How long could recovery from a major cyber attack take?
The NCSC warns that recovery from a highly disruptive cyber attack may take weeks or months. Organisations may need temporary workarounds while rebuilding towards minimum viable operations.
Why are technology suppliers an important cyber risk?
DHSC’s adult social care study found that 44% of attacks reported by affected providers originated from third-party organisations. Care providers increasingly depend on external software, cloud and managed-service suppliers, making supply-chain resilience an important part of continuity planning.
Should a care home simply revert to paper if systems fail?
A temporary paper process may form part of continuity, but it needs to contain current critical information, remain secure, support safe care and include a method for reconciling records when systems return. Simply saying “we’ll use paper” is not enough.
Editorial sources
This feature has been developed using information available on 6 August 2026.
National Cyber Security Centre, What to Do When Cyber Attacks Disrupt Your Organisation, published 28 July 2026.
National Cyber Security Centre, Recovering From a Highly Disruptive Cyber Attack, published 28 July 2026.
Department of Health and Social Care, The State of Cyber Security in Adult Social Care.
Department for Science, Innovation and Technology and Home Office, Cyber Security Breaches Survey 2025/26, published 30 April 2026.
Department of Health and Social Care, Adult Social Care Provider Statistics: Quarterly Update to May 2026, published 4 June 2026.
Digital Care Hub, Record Numbers of Care Services Have DSPT, published 1 July 2026.
Digital Care Hub, Digital Health Checks.
Care Quality Commission, Business Continuity Plan, updated February 2026.
Care Quality Commission, Care Homes and Supported Living Services: Safe.
Care Quality Commission, Digital Record Systems: Achieving Good Outcomes for People Using Adult Social Care Services.
Department for Science, Innovation and Technology, Cyber Security and Resilience Bill: Relevant Managed Service Providers and Incident Reporting, updated 30 June 2026.
