The Stryker cyber attack is a useful reminder that an NHS supplier can suffer a serious service problem without its product being compromised. For established suppliers, resilience includes the technology, people, stock, logistics and third parties underneath the promise made to the NHS organisation.

IN SHORT

In short: NHS supply-chain cyber security is about more than protecting your own network. Suppliers need to understand the physical and digital dependencies behind the NHS-facing service, reduce single points of failure, test how long the business can operate without a critical dependency and know how NHS communication will work during disruption.

This is part of the wider NHS supplier resilience and readiness picture. The Cyber Security Charter and ongoing assurance provide useful companion perspectives.

The Stryker incident is a useful warning

In March 2026, a cyber attack on medical-device manufacturer Stryker created a problem for the NHS without the attacker needing to breach an NHS system.

The Stryker attack disrupted the company’s global IT systems, affecting business operations, shipping and distribution and halting production. The affected servers were internal rather than product-facing, connected and life-saving devices remained safe to use, and at the time it was not clear whether data had been stolen (NHS England, 2026a).

The NHS impact was still immediate. Stock already in the UK supply chain was estimated to cover only around two weeks at normal ordering volumes, so NHS Supply Chain introduced demand controls and an interim ordering route to protect continuity of supply (NHS England, 2026a).

That is the part worth paying attention to. An incident does not have to compromise your product or expose patient data to threaten the service you provide. A cloud platform, identity provider, component, manufacturer, distributor, logistics partner, connectivity supplier or outsourced support team can all become part of the NHS service you are responsible for.

Supplier scrutiny extends beyond the direct contract

A4 takes the view that supply-chain risk does not stop at the direct supplier. NHS organisations are expected to consider material subcontractors, the impact of disruption or compromise further down the chain, concentration risk and any gaps in visibility or assurance (NHS England, 2026b).

For suppliers, it is a useful indication of the scrutiny a mature NHS buyer may apply. If a dependency is critical to the service you sell, expect a mature NHS buyer to want to understand it.

Start with the service the NHS organisation actually depends on

A long supplier register is not the same thing as understanding your dependencies. Start at the other end.

Start with the promise you make to the NHS organisation. The application is available. Patient information can be accessed. Reports arrive on time. Calls are answered. Devices ship. Data stays protected. The integration keeps running.

Then work backwards. What has to be true for that promise to hold? That quickly shows where somebody else's failure becomes yours, and it often exposes dependencies that looked ordinary until you imagine losing them.

NHS service dependency

What enables it?

Critical third party

If it disappears

Fallback

NHS user can access service

Hosting, identity, connectivity

Cloud/identity provider

Service partially or fully unavailable

Defined failover/manual process

Patient / NHS data remains available

SaaS platform, backup

Backup/data processor

Loss of access or recovery delay

Alternate recovery path

Support remains available

Telephony, ticketing, staff access

Telecoms/SaaS provider

NHS user cannot reach support

Secondary contact route

Product continues shipping

Production/logistics

Manufacturer/distributor

Supply interruption

Secondary supplier/buffer

Routine operational process keeps running

Support triage, document processing, scheduling or coding assistance

AI / automation platform

Process slows, stops or reverts to manual

Documented manual route and owner

The newest entry on that map is often an AI or automation service. If support triage, document processing, customer communication, coding, scheduling or another operational process now depends on an external AI service, that service may have become part of your operational supply chain. Not every AI tool is critical, but the resilience question is the same as for any other dependency: what happens if it becomes unavailable, changes materially or can no longer be used with the information involved? The NCSC makes a similar point, treating visibility of AI supply chains as part of managing AI risk (NCSC, 2024).

In resilience conversations, the dependencies that worry us most are often not the obvious ones. It is the shared identity platform, the single admin route, the one distributor, or the fallback that quietly depends on the same provider as the primary service.

Concentration risk is easy to miss when everything is working

A business can have twenty suppliers and still have one enormous single point of failure.

Perhaps all identity runs through one platform. All backups depend on the same administrative accounts as production. Two ‘different’ services sit in the same cloud region. Your support number, internet connectivity and failover all ultimately depend on the same carrier.

On paper, there are multiple vendors. Operationally, there may still be one point at which the NHS service stops.

Concentration risk and over-reliance on individual providers are now explicit parts of the A4 supply-chain view, while the NCSC treats mapping and understanding the supply chain as a core part of third-party cyber-risk management (NHS England, 2026b; NCSC, 2023).

Run a two-week supplier failure test

Stryker gives suppliers a useful resilience test. At the time of the incident, NHS England estimated that normal stock could cover only around two weeks before further disruption was likely (NHS England, 2026a). So test the plan properly: assume your most important dependency is unavailable for fourteen days.

Time horizon

Question to answer

Day 1

What stops immediately? Which NHS services, products, systems or teams are affected first?

Day 3

Which SLAs, stock levels or NHS service commitments are now at risk? What workaround is operating?

Day 7

Which temporary workarounds are becoming fragile? Which alternative suppliers or routes can actually scale?

Day 14

Can you still deliver the service promised to the NHS, and what would you need to tell the NHS organisation if normal service is still unavailable?

For a software supplier, that exercise may expose hosting, identity, data-processing or support dependencies, including any AI or automation service a routine process now relies on. For a medtech or device supplier, it may expose manufacturing lead times, stock buffers, warehousing, logistics and the availability of clinically acceptable alternatives. The underlying question is the same: how long can the NHS service promise survive when one dependency disappears?

Just-in-time efficiency can create resilience debt

Lean supply chains are efficient when everything works. They become fragile when a critical supplier has no easy substitute, stock is thin or replacement capacity cannot ramp quickly. The Stryker response relied on mutual aid, clinical prioritisation, controlled demand and alternative suppliers. Resilience can therefore mean sensible stock or capacity buffers, pre-agreed alternatives and low-tech fallback routes as well as cyber controls (NHS England, 2026a).

The aim is not to duplicate every supplier or hold unlimited inventory. It is to know where a single dependency could stop delivery, understand how long you can tolerate its loss, and decide in advance which risks need a fallback.

A backup is not the same as the ability to recover

This distinction matters particularly for technology suppliers.

The NHS Cyber Security Charter is explicit on this point: suppliers should maintain immutable backups of critical business data and products, test business-continuity and rapid-recovery plans, and exercise cyber response at board level (NHS England, 2026c).

The important word there is tested. We see plenty of organisations that can show a green backup dashboard. That is useful, but it is not the same as proving the service can be recovered under pressure.

A dashboard showing successful backups answers one question: did the backup job run? It does not tell you how long a real recovery would take, whether identities and dependencies can be restored in the correct order, whether people know what to do, whether NHS communication works, or whether an external provider will actually be available during a widespread incident.

For an NHS supplier, recovery is part of the service you sell. It is not just a technical feature sitting in the background.

Know what you will tell the NHS organisation

There is another part of resilience that gets much less attention until something goes wrong: what you are going to tell the NHS organisation you supply.

Incident communication can also be a contractual requirement. Relevant supplier obligations can cover notifying the NHS organisation of ongoing incidents and impacts, working collaboratively on remediation, and meeting security SLAs for out-of-hours support, reporting and incident handling (NHS England, 2026b).

So imagine the incident has already happened. At 08:00 tomorrow, a critical provider tells you they are offline and cannot give a recovery time.

By 09:00, could you tell the NHS organisation what is affected, what is not affected, whether data is at risk, what contingency is operating, who owns the response and when the next update will arrive?

If you cannot answer those questions, the continuity plan is not finished yet.

Resilience is becoming part of supplier quality

This is also moving into supplier management. NHS Supply Chain's 2026-27 business plan includes a new Supplier Assurance Framework focused on resilience, transparency and sustainability, alongside stronger business-continuity and disaster-recovery capability (NHS Supply Chain, 2026).

The commercial point is straightforward. The NHS does not only need a good product. It needs confidence that the supplier behind it can keep delivering when normal conditions disappear.

That makes dependency mapping, recovery testing, incident readiness and supplier risk part of the NHS supplier proposition, not an internal cyber side project.

This is not about designing for every imaginable disaster. It is about knowing which failures could genuinely stop you serving the NHS organisation, and dealing with those before an incident makes the decision for you.

Frequently asked questions

What is NHS supply-chain cyber risk?

It is the risk that a supplier, subcontractor or dependency disrupts or compromises a service the NHS relies on. That can be digital or physical. A4 specifically brings critical suppliers, material subcontractors, concentration risk, assurance gaps and operational impact into scope.

How should an NHS supplier identify critical third parties?

Work backwards from the service promised to the NHS organisation. Identify the systems, people, platforms, manufacturers, logistics routes and third parties required to deliver it, then test the impact if each critical dependency becomes unavailable for days or weeks.

Are backups enough for resilience?

No. Backups matter, but the NHS Cyber Security Charter also expects tested plans for business continuity and rapid recovery. Recovery time, dependencies, responsibilities and NHS communications need to work in practice.

References

NHS England (2026a) Stryker Medical – cyber-attack and associated disruption to supply of medical equipment and consumables. 20 March. Available at: https://www.england.nhs.uk/long-read/stryker-medical-cyber-attack-and-associated-disruption-to-supply-of-medical-equipment-and-consumables/ (Accessed: 5 October 2026).

NHS England (2026b) Principle: A4 Supply chain. Available at: https://www.england.nhs.uk/long-read/principle-a4-supply-chain/ (Accessed: 5 October 2026).

NHS England (2026c) Cyber security charter for suppliers to the NHS. Available at: https://www.england.nhs.uk/long-read/cyber-security-charter-for-suppliers-to-the-nhs/ (Accessed: 5 October 2026).

National Cyber Security Centre (2023) Supply chain security guidance. Available at: https://www.ncsc.gov.uk/collection/supply-chain-security (Accessed: 5 October 2026).

NHS Supply Chain (2026) Business Plan 2026–2027. Available at: https://www.supplychain.nhs.uk/about-us/business-plan/ (Accessed: 5 October 2026).

National Cyber Security Centre (2024) AI and cyber security: what you need to know. Available at: https://www.ncsc.gov.uk/guidance/ai-and-cyber-security-what-you-need-to-know (Accessed: 6 October 2026).