Comment former le personnel à la cybersécurité sans les ennuyer
Reassuring your patients in an age of data anxiety, digital health and cyber threats
Rédigé par Thomas Andrew Porteus, MBCSPublié à l'origine 9 juil. 2025
Respecte les directives éditoriales
- TéléchargerTélécharger
- Partager
- Language
- Discussion
- Version audio
- Ajouter aux sources préférées sur Google
Professionnels de la santé
Les articles de référence professionnelle sont conçus pour être utilisés par les professionnels de la santé. Ils sont rédigés par des médecins britanniques et basés sur des preuves de recherche, des directives britanniques et européennes. Vous pouvez trouver l'un de nos articles de santé plus utile.
Cyber security might sound like something for IT departments and software companies, but it’s just as important in general practice. In fact, with increasing digital access, cloud-based systems and phishing threats, your staff are often the first line of defence - or the first point of failure. Yet one of the most common complaints from NHS staff is that cyber training is either too technical, too boring, or too detached from day-to-day roles. If your annual IG module feels like a tick-box chore, it’s time to rethink how you’re delivering the message. This guide offers practical ways to engage your team in meaningful, relevant cyber security training - without putting them to sleep.
Why cyber security matters in primary care
A single click on a malicious email link can expose thousands of patient records. A weak password or a misused device can shut down your clinical systems for days. In recent years, practices have faced:
Ransomware attacks targeting GP clinical systems.
Phishing emails impersonating NHS suppliers.
Staff using personal email accounts for work-related tasks.
Lost laptops or phones without encryption.
Fraudulent requests for patient data.
None of these are rare, and all are preventable - if staff are aware of the risks and know what to do. Cyber security is not just an IT issue, it’s a patient safety issue.
Why traditional training often fails
Most IG or cyber training fails for one of three reasons:
It’s too abstract – The training talks about concepts like “data assets” or “threat actors” without showing real-world relevance.
It’s not role-specific – A receptionist, practice nurse, and GP all face different risks, but training is often one-size-fits-all.
It’s passive – Watching a 30-minute video or clicking through a slideshow doesn’t drive behaviour change.
Staff need training that speaks their language, relates to their daily work and sparks enough interest to make the message stick.
Five ways to make cyber training more effective (and less boring)
1. Start with real stories from healthcare
Nothing grabs attention like something that actually happened. Start your next cyber update by sharing a real-world incident:
A receptionist at another practice who clicked on a fake invoice.
A local CCG that had to shut down systems after a cyber attack.
A GP laptop stolen from a car, later traced to the dark web.
Make it specific, make it human, and make it relevant to your team.
2. Use short, sharp team briefings
Not every training moment needs to be a formal session. Use your weekly huddles or monthly team meetings to drip-feed key lessons:
“This week’s tip: how to spot a phishing email.”
“Quick refresher: what to do if you lose your work phone.”
“Did you know? NHSmail has a built-in spam filter – here’s how to report something suspicious.”
Bite-sized training delivered regularly is more effective than a single long session.
3. Tailor examples to each role
Receptionists might be targeted with fake appointment requests. Clinicians might be at risk when accessing records remotely. Admin staff might be asked to process unusual data requests. Make sure your training reflects the real cyber decisions each role has to make. Consider short, role-specific handouts or scenarios.
4. Run tabletop simulations or ‘what if’ drills
People remember what they experience. Try running a short simulation:
“What would you do if you received this suspicious email?”
“Let’s pretend your computer won’t start - what’s the first thing you do?"
“You get a call asking for patient details - what questions should you ask?”
Keep it light but meaningful. Encourage discussion and questions.
5. Celebrate good practice and give feedback
If a team member spots and reports a suspicious email, make a point of praising it. If someone asks a good question about security, share the answer with the wider team. Reinforcing positive behaviour builds a culture where cyber awareness is valued, not feared.
Resources that help
Consider using:
NHS Digital’s ‘Keep IT Confidential’ campaign - Free posters, screensavers and messages designed for primary care staff.
NHS England's cyber security awareness toolkit - Includes customisable templates and real-life case studies.
Local ICB or CSU training teams - They may offer short on-site or virtual training tailored to general practice.
Final word: It’s not about perfection, it’s about awareness
You don’t need every staff member to become a cyber security expert. But you do need them to care, to be alert and to know what to do when something seems wrong. By bringing cyber security training into everyday conversations, grounding it in real-world examples and making it feel relevant to people’s jobs, you’ll create a practice that’s more resilient, more aware and better protected - without ever needing to sit through another dull slide deck.
Mises à jour exclusives pour les professionnels de la santé
Restez informé des dernières mises à jour cliniques, des perspectives professionnelles et des conseils fondés sur des preuves. La newsletter Patient Pro sélectionne des contenus essentiels pour les professionnels de santé—livrés directement dans votre boîte de réception.
En vous abonnant, vous acceptez notre Politique de confidentialité. Vous pouvez vous désabonner à tout moment. Nous ne vendons jamais vos données.
À propos de l'auteurVoir la biographie complète

Thomas Andrew Porteus, MBCS
Technologie de la santé
MBCS
Thomas écrit pour informer, inspirer et équiper les leaders de pratique et les professionnels de la santé naviguant dans le changement, en s'appuyant sur deux décennies de travail pratique à travers le système de santé britannique.
Historique de l'article
Les informations sur cette page sont rédigées et examinées par des cliniciens qualifiés.
Article également disponible en Anglais, Allemand, Espagnol, Français, Italien, Portugais, Hindi, Hébreu, Arabe, and Suédois.
Prochaine révision prévue : 9 juillet 2028
9 juil. 2025 | Publié à l'origine
Écrit par :
Thomas Andrew Porteus, MBCS

Demandez, partagez, connectez-vous.
Parcourez les discussions, posez des questions et partagez vos expériences sur des centaines de sujets de santé.

Vous ne vous sentez pas bien ?
Évaluez vos symptômes en ligne gratuitement
Plus sur la gouvernance de l'information et la sécurité
- Loi sur l'utilisation et l'accès aux données 2025 - ce que cela signifie pour la pratique générale
- Comment éviter les maux de tête liés à IG en travaillant avec le personnel de PCN
- Comment réaliser une évaluation des risques IG à l'échelle de la pratique
- Comment créer une culture de sensibilisation à l'IG dans votre pratique
- Comment créer un calendrier de pratique IG qui fonctionne réellement
- Comment gérer une violation de données des patients
- Comment gérer une demande d'accès aux données personnelles (SAR)
- Comment gérer les questions courantes des patients sur la sécurité de l'information
- Comment gérer la cybersécurité dans une pratique de travail hybride
- Comment se préparer à une soumission DSPT sans panique
- Comment prévenir le partage de cartes à puce et pourquoi c'est important
- Comment répondre à un e-mail suspect en moins de 60 secondes
- Comment organiser une session de rafraîchissement IG de 15 minutes lors de votre prochaine réunion d'équipe
- Comment repérer et arrêter les risques internes liés à la gouvernance de l'information
- Comment rédiger un avis de confidentialité à l'intention des patients qui inspire confiance