Photo: Black Kira / iStock

NHS Scotland bolsters cyber defences with £3 Million AI-powered anti-ransomware investment

NHS Scotland has committed over £3 million to specialist artificial intelligence-driven anti-ransomware technology in response to escalating cyber threats to the country’s health infrastructure, according to official procurement documents. The investment, formalised through a contract awarded on 31st October 2025, will see IT services giant Computacenter supply software from California-based

Facebook
LinkedIn
X

Subscribe to our Daily Newsletter

Why? Free to subscribe, no paywall, daily business news digest.

NHS Scotland has committed over £3 million to specialist artificial intelligence-driven anti-ransomware technology in response to escalating cyber threats to the country’s health infrastructure, according to official procurement documents.

The investment, formalised through a contract awarded on 31st October 2025, will see IT services giant Computacenter supply software from California-based cybersecurity specialist Halcyon across all 14 NHS Scotland territorial health boards. The contract, valued at £3.1 million inclusive of VAT (£2.6 million excluding VAT), represents a significant expansion of the health service’s defensive capabilities following a devastating ransomware attack in 2024.

Learning from a Catastrophic Breach

The procurement comes in the wake of one of Scotland’s most significant healthcare cyberattacks. In March 2024, NHS Dumfries and Galloway fell victim to a ransomware assault by the Inc Ransom cybercriminal group, which infiltrated systems and exfiltrated approximately three terabytes of sensitive data. When ransom demands went unmet, the attackers published the stolen information, including patient medical records, X-rays, test results, and staff details, onto the dark web in May 2024.

The breach affected all 150,000 residents served by the Dumfries and Galloway health board, with officials advising citizens to assume their personal data had been compromised and to remain vigilant against potential extortion attempts. Julie White, chief executive of NHS Dumfries and Galloway, described the data release as “an utterly abhorrent criminal act by cyber criminals”.

According to a commercial notice published by NHS National Services Scotland, the Halcyon platform “would have significantly strengthened” defences against attacks like the Dumfries and Galloway incident, which highlighted critical vulnerabilities in existing cybersecurity infrastructure.​

Addressing a Critical Gap in Ransomware Defence

The procurement documentation reveals that whilst NHS Scotland has deployed multiple cybersecurity tools across its health boards through the Cyber Centre of Excellence, “the residual risk is still high due to the nature of ransomware attacks”. Existing security measures, the notice explains, “remediate reactively once they detect an attack to contain it,” leaving a dangerous window of opportunity for attackers.

Moreover, health officials acknowledge that “the risk of data being stolen prior to its encryption is now equal to—if not greater than—the encryption of the data itself”. This shift in ransomware tactics, known as double extortion, has become increasingly prevalent as criminal groups recognise that threatening to publish sensitive data can be as effective as encrypting systems.

The Halcyon Anti-Ransomware Platform represents a fundamentally different approach. Described as “a specialised, AI-driven cybersecurity tool that defends against advanced ransomware attacks and unauthorised access,” the technology is designed to complement rather than replace existing security infrastructure. Its lightweight architecture requires minimal resources to deploy and run on existing devices, making it suitable for rapid implementation across Scotland’s geographically dispersed health infrastructure.

According to Halcyon’s specifications, the platform is “purpose-built to focus exclusively on detecting and disrupting ransomware before damage occurs,” differentiating it from conventional security solutions that address a broader range of threats. The system employs multiple layers of protection across every stage of a ransomware attack—from pre-execution through data exfiltration to encryption—and includes the capability to capture encryption keys during active attacks, enabling rapid recovery without paying ransoms or relying on backups.

Significantly, every Halcyon deployment includes 24/7 ransomware detection and recovery services delivered by specialist experts at no additional cost—a feature that addresses the chronic shortage of cybersecurity professionals within public sector organisations.

A Sector Under Siege

The healthcare sector has emerged as a prime target for ransomware operators. Between January 2019 and June 2024, the UK healthcare sector reported 215 ransomware incidents. Globally, healthcare organisations experienced a surge in attacks during 2024, with 67% of healthcare providers hit by ransomware—the highest rate in four years and significantly above the 59% average across all sectors.

Scotland’s health service has not been immune to these trends. During the May 2017 WannaCry ransomware pandemic—which affected organisations across 150 countries—eleven of Scotland’s 14 territorial health boards were compromised, alongside NHS National Services Scotland and the Scottish Ambulance Service. That attack, which encrypted information on NHS computers and demanded payment for restoration, led to widespread disruption of GP surgeries, dental practices, and hospital systems.

The 2017 incident prompted significant investment in NHS cybersecurity infrastructure, with the UK government allocating £21 million immediately following WannaCry to address vulnerabilities in major trauma centres and ambulance trusts, followed by a further £25 million in capital funding. Despite these investments, the Dumfries and Galloway breach seven years later demonstrated that ransomware threats have evolved faster than defensive capabilities.

Building a National Cyber Defence Architecture

NHS Scotland’s ransomware investment forms part of a broader national cyber resilience strategy. The health service established its Cyber Centre of Excellence in December 2022, creating a 24/7 Security Operations Centre at Abertay University’s cyberQuarter facility in Dundee. The centre, which cost £100,000 per health board over six years through 2026, provides centralised threat monitoring, incident response, and security collaboration across all Scottish health boards.

Scott Barnett, Chief Information Security Officer at NHS National Services Scotland, has emphasised that “digital technology is a pivotal force driving every aspect of NHS Scotland today,” whilst acknowledging that this digital dependence “makes us a prime target for cyber threats”. The Scottish Government has further strengthened oversight through the Scottish Cyber Coordination Centre, with NHS National Services Scotland designated as a “core partner” in the 2024-2027 strategic plan.

As healthcare systems worldwide grapple with intensifying cyber threats, NHS Scotland’s substantial investment in specialised ransomware defence represents both a response to past breaches and a commitment to protecting future patient care from criminal disruption.

Facebook
LinkedIn
X

Related Stories from Silicon Scotland

Other Stories from Silicon Scotland