University Hospitals of Liverpool Group has noted “significant progress on cyber security” and the data security and protection toolkit (DSPT). The board of directors this month highlighted strong assurance in cyber security management, information risk oversight, information incident management, data quality improvement, clinical coding assurance, and the ongoing digitisation of records. 38 of 41 outcomes were recorded as “standards met” at LUHFT in the DSPT cyber assessment framework submitted last year, it states. An internal audit for DSPT provided an improvement plan for supply chain, identification verification authentication and authorisation, and vulnerability management, with seven of 11 recommendations now implemented. LUHFT established a risk management forum, including information risk, the group notes, said to help to identify and manage risk to personal data. A digital risk assurance group now meets every month to incorporate all trust site management, discussing and grading risks, and assigning risk scores and mitigations. An information governance group is responsible for overseeing all information governance and cyber security activities, meeting monthly and chaired by the trust’s CDIO/SIRO. A digital oversight committee is responsible for overview and scrutiny of all cyber and information governance risks, and meets on a monthly basis. From 1 April 2025 to 31 March 2026, digital services identified a total of 37 new risks, according to the group, representing a 31.5 percent decrease on the previous year. 29 of these were labelled “moderate”; seven were “serious”; and one was “significant”. 16 cyber security related incidents were recorded during the 2025/26 reporting period, decreasing from 19 in the previous year, with none requiring external reporting to the information commissioners office. “Following incidents, the Cyber Security Team discuss the impact of these events and possible gaps in controls that could allow a reoccurrence,” the group states. “Opportunities for improvement are discussed at appropriate forums and