Home/Blog/Healthcare Security
Healthcare Security

DTAC, DSPT, and the Importance of Penetration Testing

In September 2024, the Data Security and Protection Toolkit (DSPT) will undergo a significant transformation by adopting the National Cyber Security Centre's Cyber Assessment Framework (CAF) as its basis for cyber security and information governance assurance.

What's changing?

  • A new interface for NHS Trusts, CSUs, ALBs and ICBs — aligned with the CAF's objectives, principles and outcomes.
  • Prescriptive controls for other organisations — the current interface remains, with controls mapped to the CAF in the background for consistency.
  • Expectation alignment — overall expectations stay broadly comparable to the current DSPT, with adjustments only where higher standards are needed.
  • Guidance and support — guidance materials and webinars will help organisations understand the CAF-aligned DSPT.

The rationale behind the change

  • Emphasising good decision-making — the CAF promotes informed decisions over mere compliance, fostering local ownership of information risk.
  • Supporting a culture of evaluation and improvement — organisations must assess how effective their practices are at meeting outcomes.
  • Creating opportunities for better practice — the framework prompts organisations to stay ahead of emerging threats.

How the CAF-aligned DSPT works

The new DSPT is structured around a series of contributing outcomes, each supported by indicators of good practice graded "Not Achieved", "Partially Achieved" or "Achieved". Organisations continue to self-assess, and national assurance still relies on independent audits and sampling. A custom "health and care CAF overlay" adds eight further outcomes covering data protection, confidentiality and clinical coding — 47 contributing outcomes in total.

CAF profiles

The CAF does not expect every outcome to be "Achieved". Instead, the DSPT defines minimum achievement levels for each outcome, forming a CAF profile that varies by organisation type and threat exposure. Achieving the relevant profile is a prerequisite for a "Standards Met" grading. Because minimum levels can be adjusted annually while the framework stays stable, organisations can forecast and plan more effectively.

The bigger picture

By adopting the CAF, the health and care sector gains a standardised framework consistent with other sectors — one that is scalable and adaptable as threats and capabilities change.

#dspt#caf#healthcare-security

Ready to strengthen your security?

Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.