FOI/2026/27/03

Read more about this page below

Reference FOI/2026/27/03
Description Cyber breaches
Date requested 07/05/2026
Attachments N/A

Your request:

 

Under the Freedom of Information Act, I would like to request the following information for each calendar year from 2020 to 2026 inclusive:

1.     The number of cyber security breaches that have being identified that were found to be a result of a malicious threat actor (i.e. not accidental data breach)

2.     The breakdown in high-level causes of these breaches as identified by cyber security incident response teams (CSIRTs), for example (but not limited to) unpatched software/hardware, lack of multi-factor authentication (MFA), leaked user credentials, lack of in-transit encryption, etc

3.     The number of breaches that occurred that were attributed to a previously known vulnerability to the organisations hardware, software, policies, or processes, for example where system was known to be at risk due to being unpatched or out of support, or security controls were recommended but not enforced, and was defined within the resulting incident response report.

4.     The estimated combined costs incurred as a result of cyber security breaches defined in request number one in each year.

 

Our response:

 

Having completed enquiries within CLCH, in respect of Sec1(1)(a) CLCH does hold information relating to your request, however, this information is published online. Therefore, for the purpose of section 17 of the Freedom of Information Act 2000 (FOIA), this part of our response serves as a formal notification of refusal of your request on the basis that exemption Section 21 of the FOIA applies.

Section 21 - Information Reasonably Accessible by Other Means

(1)Information which is reasonably accessible to the applicant otherwise than under section 1 is exempt information.

(2)For the purposes of subsection (1)—

              (a)information may be reasonably accessible to the applicant even though it is accessible only on payment, and

              (b)information is to be taken to be reasonably accessible to the applicant if it is information which the public authority or any other person is obliged by or under any enactment    to communicate (otherwise than by making the information available for inspection) to members of the public on request, whether free of charge or on payment.

Section 21 is an absolute exemption and where information falls within the scope of an absolute exemption, a public authority is not obliged to communicate it to an applicant and is also not obliged to comply with the duty to confirm or deny the existence of the information requested.

Having said that and in an effort to assist, please see the below in relation to your FOI request.

 

https://clch.nhs.uk/about-us/foi/foi-requests?search=1&keywords=cybers+security&category=&ccm_paging_p=1&ccm_order_by=&ccm_order_by_direction=

 

Accessibility tools