Cybersecurity Awareness

Version: 2.0
Review date: 01 January 2027
Clinical approval: Nominated Individual
Approved by: Dr James Glass, Nominated Individual
Operational lead: Caroline Lawrence, Registered Manager
Minimum pass mark: 12 out of 15
Refresher frequency: At induction and annually or sooner following a significant incident or material change

1. Purpose of this module

Cybersecurity is the protection of devices, accounts, systems and information from unauthorised access, alteration, loss, disruption or misuse.

It is not simply an IT issue. It is part of information governance, patient safety and the safe operation of WMI Psychiatry.

A compromised email account could expose confidential health information. Ransomware could prevent staff from accessing appointments, prescriptions and urgent clinical messages. A fraudulent payment request could cause financial loss. Altered or unavailable records could affect decisions about care.

Administration staff are often the first people to receive unexpected emails, file-sharing invitations, password-reset messages, payment requests and calls asking for information. This makes the administration team an important part of WMI Psychiatry’s cybersecurity controls.

The central rule is:

Pause when something is unexpected. Verify it through a trusted route. Report concerns promptly.

Staff will be supported when they promptly report an honest mistake or near miss.

This module will

  • explain common cyber threats within an outpatient psychiatry service

  • provide practical guidance about email, accounts, devices, files, payments and remote working

  • explain what to do after a suspicious click, lost device or possible breach

  • clarify the limits of the administration role

  • support prompt reporting and organisational learning

This module does not

  • authorise administration staff to investigate a cyberattack themselves

  • authorise staff to access another person’s account or records

  • replace technical security controls, access management or backups

  • require staff to decide whether a breach must be reported to the Information Commissioner’s Office

  • authorise staff to wipe, reconfigure or destroy a device

  • permit the use of personal email or personal cloud storage for clinic information

  • permit staff to use unauthorised messaging services for confidential information

  • replace WMI Psychiatry’s incident, data breach or business continuity procedures

2. Learning outcomes

By the end of this module staff should be able to:

  1. Explain why cybersecurity matters to confidentiality, patient safety and service continuity.

  2. Recognise phishing, social engineering, impersonation and fraudulent payment requests.

  3. Use passkeys, passwords and two-step verification safely.

  4. Protect accounts and respond to unexpected sign-in requests.

  5. Use work email, approved systems and authorised sharing methods.

  6. Check recipients, permissions and attachments before sending information.

  7. Protect laptops, phones and workspaces during office and remote working.

  8. Respond safely to suspicious links, malware warnings and ransomware.

  9. Recognise a possible personal data breach or cyber incident.

  10. Take immediate containment steps within the limits of their role.

  11. Preserve relevant evidence.

  12. Report incidents and near misses promptly without concealing mistakes.

  13. Recognise when a request must be verified through a separate trusted channel.

  14. Understand that administration staff must not conduct technical investigations or make regulatory reporting decisions.

  15. Apply WMI Psychiatry’s procedures to realistic situations.

3. WMI Psychiatry local contacts and procedures

The following information must be completed before this module is issued.

Internal escalation

Registered Manager: Caroline Lawrence

Nominated Individual: Dr James Glass

Data Protection Lead: James Glass

Google Workspace administrator: James Glass

IT support provider: Zanda Health Support and Google Workspace Support

Out-of-hours cybersecurity escalation: Registered Manager or Nominated Individual using their designated work contact details

Incident reporting system: WMI Psychiatry Incident Reporting System

Data breach log: WMI Psychiatry Data Breach Log

Location of current policies: WMI Google Drive > Policies and Procedures

Location of business continuity information: WMI Google Drive > WMI Business Continuity Policy

Approved systems

WMI Psychiatry’s core systems currently include:

  • Google Workspace for work email, approved files and authorised collaboration

  • Zanda Health for appointments, patient administration and authorised clinical records

  • AppSheet for approved clinic jobs and governance workflows

  • Stripe for authorised payment processing

A system being approved does not mean that every member of staff is authorised to use every function. Access must be appropriate to the person’s role.

Staff must not share accounts, passwords or verification codes.

Immediate local response

If a cyber incident may have occurred:

  1. Stop the risky activity.

  2. Do not continue opening files, entering details or approving requests.

  3. If a device may be infected disconnect it from Wi-Fi and any network cable where this can be done safely.

  4. Do not wipe the device or continue investigating.

  5. Contact the Registered Manager and urgent IT support immediately using a trusted contact method.

  6. If an account may be compromised contact support from a separate trusted device.

  7. Preserve the email, message, screen details and relevant times.

  8. Do not delete evidence unless instructed.

  9. Record the incident or near miss through the approved system as soon as possible.

4. Confidentiality, integrity and availability

Cybersecurity incidents can affect three main areas.

Confidentiality

Confidentiality is affected when information is accessed or shared with someone who is not authorised to receive it.

Examples include:

  • emailing a report to the wrong parent

  • sharing a file using a public link

  • allowing another person to use your account

  • discussing patient information where others can hear

  • leaving a record visible on an unlocked screen

Integrity

Integrity is affected when information is altered without proper authority or can no longer be trusted.

Examples include:

  • bank details on an invoice being changed

  • information in a patient record being altered

  • an attacker sending messages from a staff member’s account

  • important information being deleted

  • an unauthorised person changing appointment details

Availability

Availability is affected when information or systems cannot be accessed when needed.

Examples include:

  • ransomware preventing access to appointment records

  • an account being locked following compromise

  • files being deleted

  • a system being taken offline because of an attack

  • an urgent clinical message being inaccessible

In healthcare all three can affect people. A privacy breach may cause distress, embarrassment, discrimination or loss of trust. Altered records could lead to incorrect decisions. Unavailable systems could delay care and urgent communication.

5. Common cyber threats

Phishing

Phishing is a message or website designed to make someone reveal information, approve access, send money or install harmful software.

Phishing may arrive through:

  • email

  • text message

  • a messaging application

  • a QR code

  • social media

  • a telephone call

  • a file-sharing invitation

  • an online advertisement

  • a false website

The message may appear to come from a patient, clinician, manager, bank, supplier, payment provider or software company.

Social engineering

Social engineering uses trust, urgency, fear, authority or helpfulness to influence someone.

An attacker may:

  • claim that immediate action is needed

  • ask staff to keep the request secret

  • pretend to be a senior manager

  • threaten that an account will be closed

  • claim that a patient will be harmed if staff do not act

  • ask staff to bypass the usual process

  • offer to help resolve a supposed technical problem

  • use information found online to make the approach convincing

The attacker may know staff names, roles, suppliers or recent clinic events. Accurate information does not prove that the person is genuine.

Account takeover

An attacker may use a stolen password, session token or approved sign-in request to access an account.

Once inside an account they may:

  • read confidential messages

  • impersonate a member of staff

  • create automatic email-forwarding rules

  • hide or delete messages

  • reset other accounts

  • access shared files

  • change payment information

  • send phishing emails to colleagues or patients

Malware

Malware is harmful software designed to damage, disrupt or obtain unauthorised access to devices and information.

It may be installed through:

  • a malicious attachment

  • an infected website

  • unauthorised software

  • a browser extension

  • a false update

  • a remote-access tool

  • an unknown USB device

Ransomware

Ransomware may encrypt information, steal it or prevent systems from working. The attacker may demand payment to restore access or prevent publication.

Paying does not guarantee that information will be recovered or deleted.

Administration staff must not communicate with an attacker, negotiate or pay a ransom.

Payment and invoice fraud

An attacker may impersonate a manager, supplier, patient or payment provider.

They may request:

  • a payment to a new bank account

  • an urgent refund

  • a payroll change

  • gift cards

  • cryptocurrency

  • payment of an altered invoice

  • disclosure of payment information

A familiar email address may itself have been compromised. Staff must still follow the usual financial controls.

Insider risk and accidental error

Not every cybersecurity incident is a deliberate attack.

Incidents may also result from:

  • sending information to the wrong recipient

  • using excessive sharing permissions

  • leaving a device unlocked

  • losing a laptop or telephone

  • uploading a file to an unauthorised location

  • using a personal email account

  • giving another person access to an account

  • failing to remove access when someone leaves the organisation

Prompt reporting allows the organisation to contain the problem and reduce harm.

6. Recognising suspicious messages

No single feature proves that a message is malicious. Staff should consider the complete situation and whether the request was expected.

Possible warning signs include:

  • the sender’s address or domain is slightly different from the expected address

  • the display name is familiar but the underlying address is not

  • the message creates pressure to act immediately

  • the sender asks for secrecy

  • the request bypasses the usual process

  • the message asks for a password or verification code

  • the message asks you to approve a sign-in

  • a file or link was not expected

  • the link destination does not match the visible text

  • a QR code directs you to sign in or make a payment

  • the sender asks for new bank details to be used

  • the sender asks for gift cards or cryptocurrency

  • the message asks you to move to a personal account

  • the document asks you to enable macros

  • the sender asks you to install software

  • the sender asks you to grant remote access

  • the tone or timing is unusual for the person

  • an unexpected invoice or refund request is received

Good spelling, a correct logo, a familiar writing style or knowledge of clinic information does not prove that a message is genuine.

AI tools can help attackers create convincing text, audio, images and video.

7. Pause, check and report

Use the following approach when a message or request is unexpected.

Pause

Do not:

  • click the link

  • open the attachment

  • scan the QR code

  • enter your password

  • approve the sign-in

  • provide a verification code

  • make a payment

  • disclose information

  • install software

Check

Verify the request through a route obtained independently.

You may:

  • call a previously known telephone number

  • start a new email using the saved address

  • open the service through the usual bookmark

  • contact the manager through the established work route

  • check the request directly within the approved system

Do not verify a suspicious request by replying to the same message or calling a number provided within it. The attacker may control both.

Report

Use the approved phishing or incident-reporting route.

Urgent risks must also be reported directly to the Registered Manager and IT support.

Reporting a suspicious message does not mean that you have done anything wrong.

8. Passwords, passkeys and two-step verification

Passwords

Staff should:

  • use a unique password for every work account

  • use the organisation-approved password manager where provided

  • keep passwords private

  • avoid reusing a work password for a personal account

  • change a password promptly when instructed following suspected compromise

Staff must not:

  • share a password with a colleague

  • share a password with a manager

  • send a password by email

  • store passwords in an unprotected document

  • keep passwords on visible paper notes

  • use another person’s account

  • ask another person for their password

No legitimate support process requires staff to disclose their password.

Passkeys

Passkeys can reduce phishing risk because they are connected to the genuine service.

Use passkeys where WMI Psychiatry has approved and configured them.

A passkey must still be protected by:

  • the device’s screen lock

  • secure account recovery arrangements

  • appropriate control of the device

  • prompt reporting if the device is lost

Two-step verification

Two-step verification adds another check when signing into an account.

Never approve an unexpected sign-in request.

Repeated requests may be an attempt to wear you down. This is sometimes called multi-factor authentication fatigue.

If an unexpected request appears:

  1. Deny the request.

  2. Do not approve it to make the prompts stop.

  3. Report it immediately.

  4. Contact support through a trusted route.

  5. Follow instructions about securing the account.

Never read a verification code to someone who telephones or messages you.

IT support may ask you to confirm your identity. They should not ask you to disclose your password or send them a one-time verification code.

9. Email safety

Staff must use the WMI Psychiatry work email account for patient and professional correspondence.

Before sending an email:

  • check the full recipient address

  • confirm that the recipient is authorised to receive the information

  • check all attachments

  • review the previous email history included in the message

  • ensure that only the minimum necessary information is included

  • check whether Bcc is required

  • check that autofill has selected the intended person

Staff must not:

  • forward clinic email to a personal account

  • use a personal email address for clinic work

  • create an automatic forwarding rule without authorisation

  • send information simply because a family member requests it

  • assume that a parent, partner or relative is authorised

  • send confidential information using an unapproved method

Report:

  • sent messages you do not recognise

  • missing emails

  • unexpected forwarding rules

  • unexplained password-reset messages

  • changes to account recovery information

  • unexpected sign-in alerts

Sending sensitive information

Before sending sensitive information confirm:

  • the person’s identity

  • their authority to receive it

  • the purpose of the disclosure

  • the minimum information required

  • the approved secure method

Cybersecurity does not replace consent, confidentiality or identity-verification procedures.

10. Files, links and cloud sharing

Staff should:

  • open work systems through trusted bookmarks or approved applications

  • check that a file-sharing invitation is expected

  • share files with named authorised people

  • use the least level of access required

  • use viewer access rather than editor access where appropriate

  • remove access when it is no longer required

  • check whether links have been made public

  • store files only within approved work systems

Staff must not:

  • upload clinic documents to personal Google Drive

  • upload clinic documents to personal Dropbox or another consumer service

  • create public links for patient information

  • download confidential information to a personal device without explicit authorisation

  • enable macros because a document asks them to

  • bypass a security warning

  • install a browser extension to open a file

  • move files to an unauthorised platform because the approved system is unavailable

If a document is accidentally uploaded or shared incorrectly remove access where this can be done safely and report the incident immediately.

Do not assume that deleting the visible file means that there was no breach. Another person may have opened, downloaded or copied it.

11. Devices and physical security

Staff should:

  • use only authorised devices for work

  • use a strong device passcode

  • use biometric protection where approved

  • lock the screen whenever they step away

  • install approved security updates promptly

  • allow the device to restart when required

  • keep antivirus and firewall controls active

  • keep devices physically secure

  • report loss, theft or unexpected behaviour immediately

Staff must not:

  • disable antivirus or firewall controls

  • disable device encryption

  • install unauthorised software

  • install unauthorised browser extensions

  • install remote-access tools without approval

  • connect unknown USB devices

  • allow family members or friends to use a work device

  • leave a work device unattended in a vehicle

  • lend a work device to another person

Printing and paper records

Cybersecurity also includes physical information.

Staff should:

  • collect printing immediately

  • avoid leaving patient lists or letters visible

  • store paper records securely

  • use the approved confidential-waste route

  • check printers and scanners after use

Staff must not photograph a screen or document using a personal telephone unless a current authorised procedure specifically permits this.

12. Remote and mobile working

When working remotely staff should:

  • work where conversations cannot be overheard

  • position screens where they cannot be viewed by unauthorised people

  • use an approved device

  • use the approved browser profile

  • follow the approved network arrangements

  • lock the device when stepping away

  • close systems at the end of the session

  • store work in approved systems rather than on the local desktop or Downloads folder where possible

  • use a privacy screen where required

Staff should avoid:

  • public or shared computers

  • discussing patients in public places

  • displaying confidential information during travel

  • allowing other household members to view work

  • leaving papers visible at home

  • using an unapproved personal service when the approved system is unavailable

Public Wi-Fi may be imitated by an attacker. Staff must follow WMI Psychiatry’s approved connection arrangements.

If the approved method is unavailable contact the manager for a safe alternative.

13. Telephone calls, identity and impersonation

A caller may claim to be:

  • a patient

  • a parent

  • a clinician

  • a bank

  • a software provider

  • an IT engineer

  • a police officer

  • a senior manager

  • a supplier

Caller identification can be falsified. A confident manner or knowledge of staff names does not prove identity.

Staff should:

  • follow the approved identity-verification process

  • verify unusual requests through a separate trusted route

  • end an unsolicited technical-support call

  • contact the organisation using a published or saved number

  • report attempts to obtain information

Staff must not disclose:

  • passwords

  • verification codes

  • confidential patient information

  • staff home addresses

  • personal telephone numbers

  • details of security arrangements

  • whether someone is a patient without appropriate authority

Staff must not install software or grant screen access during an unsolicited call.

14. Payment, refund and bank-detail fraud

Financial requests require additional verification because urgency and authority are commonly used to manipulate staff.

Staff should:

  • follow the approved payment and refund workflow

  • independently verify new or changed bank details

  • use an already-known telephone number for verification

  • retain evidence that verification was completed

  • check unexpected Stripe messages by opening Stripe through the usual route

  • report suspected fraud immediately

Staff must not:

  • allow an urgent email to replace required approval

  • process gift-card purchases for a manager

  • make cryptocurrency payments

  • send unusual transfers without the normal checks

  • use bank details supplied only within an unexpected email

  • make a payment because a sender claims that it is confidential

  • bypass controls because the request appears to come from a senior person

A message that appears to come from Dr Glass, Caroline Lawrence, a clinician or a supplier must still follow the normal approval and verification process.

Authority does not remove the need for verification.

15. Software updates, technical support and remote access

Security updates close known weaknesses.

Staff should allow approved updates to install and restart devices when required.

Unsupported devices or software must be reported.

Remote-access tools can give another person control of a device.

Staff must not install or activate remote-access software following:

  • an unsolicited telephone call

  • an unexpected email

  • a pop-up message

  • a website warning

  • an unexpected text message

Use only WMI Psychiatry’s established support route.

Verify the support person through the agreed process before granting access.

16. Malware and ransomware warning signs

Possible warning signs include:

  • files not opening

  • files having unfamiliar names

  • a message demanding payment

  • the device becoming unusually slow

  • repeated pop-ups

  • antivirus being disabled unexpectedly

  • the mouse moving without your action

  • windows opening without your action

  • unexpected software appearing

  • many files being changed or deleted

  • colleagues receiving messages you did not send

  • being locked out of an account

  • verification details changing unexpectedly

Immediate response

If malware or ransomware is suspected:

  1. Stop using the affected device.

  2. Disconnect it from Wi-Fi and any network cable where this can be done safely.

  3. Do not connect backup drives or USB devices.

  4. Do not connect another work device.

  5. Contact the Registered Manager and urgent IT support from a separate trusted device.

  6. Do not pay a ransom.

  7. Do not negotiate.

  8. Do not delete files.

  9. Do not run cleaning software.

  10. Do not wipe or reset the device.

  11. Record what you observed and the time.

  12. Preserve relevant messages through an authorised method.

17. What to do after clicking or entering information

People sometimes click convincing messages. Rapid and honest reporting is more valuable than trying to conceal the mistake.

You opened the message but did not interact with it

  • stop

  • do not click links

  • do not open attachments

  • report the message through the approved phishing route

You clicked a link

  • close the page

  • do not enter any information

  • contact the manager and IT support immediately

  • preserve the original message

You entered a password

  • stop using the page

  • report it immediately

  • follow support instructions

  • change the password from a trusted device when instructed

  • ensure that active sessions are reviewed or revoked

You approved a sign-in request or shared a code

Treat this as an urgent possible account compromise.

Do not wait to see whether anything happens.

You opened an attachment or installed something

  • stop using the device

  • disconnect it from the network

  • contact urgent support

  • do not attempt to remove the software yourself

You made a payment or disclosed bank information

  • report it immediately to management

  • follow the fraud-response procedure

  • preserve the message and payment details

  • act promptly because recovery may be time-sensitive

18. Personal data breaches and cyber incidents

A personal data breach is a security incident that affects the confidentiality, integrity or availability of personal data.

It can be accidental or deliberate.

Examples include:

  • an email sent to the wrong person

  • an attachment sent to the wrong person

  • a patient file shared with excessive permissions

  • a lost or stolen device

  • an unauthorised person viewing a record

  • a compromised account

  • altered or deleted records

  • ransomware making records unavailable

  • patient information uploaded to an unauthorised platform

  • paper records being lost

  • confidential information being placed in ordinary waste

WMI Psychiatry must record personal data breaches and assess whether notification is required.

Some breaches must be reported to the Information Commissioner’s Office without undue delay and where feasible within 72 hours of awareness.

Administration staff must report a possible breach immediately.

They must not delay while deciding whether the legal reporting threshold has been met.

Administration staff must not contact the Information Commissioner’s Office independently unless this is part of their authorised role.

19. Reporting and preserving evidence

Report the incident as soon as possible.

Include:

  • the date and time of discovery

  • the device, account or system involved

  • the communication method

  • what you saw

  • what you did

  • whether a link was clicked

  • whether an attachment was opened

  • whether a QR code was scanned

  • whether credentials were entered

  • whether a sign-in was approved

  • whether information or money was disclosed

  • the type of personal data involved where known

  • the approximate number of people affected where known

  • containment steps already taken

  • who was notified

  • the time they were notified

Preserve:

  • the original email

  • messages

  • relevant screen information

  • call records

  • payment information

  • system alerts

  • relevant times

  • authorised screenshots or logs

Do not:

  • alter records

  • delete evidence

  • fabricate information

  • forward sensitive evidence to a personal account

  • post screenshots in an informal staff group

  • attempt to make the incident appear less serious

  • attempt to investigate another person’s account

20. Near misses and a just culture

A near miss is an event that could have caused harm but did not.

Examples include:

  • noticing an incorrect email recipient before sending

  • receiving a convincing fraudulent invoice without paying it

  • denying an unexpected sign-in request

  • identifying excessive file permissions before confidential information is accessed

  • recovering a work device before it is lost

Near misses should be reported because they can reveal weaknesses in systems and processes.

WMI Psychiatry expects prompt and honest reporting.

An inadvertent error reported immediately should be used to support containment, learning and improvement.

Deliberate misuse, concealment or repeated disregard of policy may require a separate management process.

21. Access control and role boundaries

Staff should:

  • use only their own account

  • access only the information needed for their work

  • use only the permissions provided for their role

  • report when access is excessive

  • report when necessary access is missing

  • report access that is no longer required

  • challenge unexpected requests for bulk exports

  • challenge unexpected requests for administrator access

Staff must not:

  • browse records out of curiosity

  • use another staff member’s unlocked session

  • share an account

  • approve their own additional access

  • retain access after their role changes

  • retain access after their work ends

  • use a colleague’s credentials to complete urgent work

Least privilege means giving each person only the access needed for their role.

This limits the harm which can occur if an account is compromised.

22. Business continuity during a cyber incident

A cyber incident may make email, Zanda Health, Google Workspace, AppSheet, payment systems or telephone services unavailable.

Staff must follow the current Business Continuity Plan rather than creating unapproved workarounds.

Staff should:

  • follow management instructions about which systems must not be used

  • use only approved contingency records

  • use only approved communication routes

  • record urgent clinical messages through the authorised process

  • maintain a clear record of actions taken during the outage

  • escalate risks to care or urgent communication to the responsible clinician

Staff must not:

  • move patient information to a personal account

  • use an unauthorised consumer service

  • reconnect an isolated device without IT authorisation

  • use another person’s account

  • create an unapproved local database

  • assume that a system is safe because it appears to be working again

23. Practical scenarios

Scenario 1: Unexpected shared document

An administrator receives an email stating that a clinician has shared a patient report. The sign-in page looks like Google but the invitation was not expected.

Appropriate response:

  1. Do not use the link.

  2. Contact the clinician through a trusted route.

  3. Open Google Workspace through the usual bookmark to check whether a genuine share exists.

  4. Report the message through the approved phishing route.

Scenario 2: Unexpected verification prompt

A sign-in approval appears on the administrator’s telephone while they are not signing in.

Appropriate response:

  1. Deny the request.

  2. Do not approve it to make the prompts stop.

  3. Report it immediately as a possible account compromise.

  4. Follow support instructions through a trusted route.

Scenario 3: Urgent refund request

A message appearing to be from Caroline asks an administrator to send an urgent refund to new bank details. The message states that she cannot take a telephone call.

Appropriate response:

  1. Do not process the payment.

  2. Verify the request using a previously known contact method.

  3. Follow the normal approval process.

  4. Report the suspicious message.

Scenario 4: Wrong recipient

An administrator sends an appointment letter to the wrong email address because autofill selected a similar name.

Appropriate response:

  1. Notify the Registered Manager immediately.

  2. Attempt recall if this is available but do not assume it worked.

  3. Follow instructions about contacting the recipient and containing the breach.

  4. Complete the incident or data breach record promptly.

Scenario 5: Lost laptop

A work laptop is missing after a journey.

Appropriate response:

  1. Report the loss immediately.

  2. Provide the last known time and place.

  3. Confirm whether the device was locked.

  4. Follow instructions about remote locking, account sessions and police reporting.

  5. Do not delay because you hope the device will be found.

Scenario 6: Ransom message

A device displays a payment demand and files will not open.

Appropriate response:

  1. Stop using the device.

  2. Disconnect it from networks where this can be done safely.

  3. Contact management and urgent IT support from another device.

  4. Do not pay, wipe or attempt to repair the device.

Scenario 7: IT support telephone call

A caller states that they are from Google and need the administrator’s verification code to stop an attack.

Appropriate response:

  1. Do not provide the code.

  2. End the call.

  3. Contact the approved support route using known contact details.

  4. Report the attempt.

Scenario 8: Personal cloud upload

A patient document is accidentally uploaded to a personal cloud account.

Appropriate response:

  1. Remove access where this can be done safely.

  2. Report the incident immediately even if the file has been deleted.

  3. Provide details of the account, file and possible access.

  4. Do not assume that deletion means there was no breach.

Scenario 9: New supplier bank details

A genuine-looking invoice states that the supplier has changed bank accounts.

Appropriate response:

  1. Do not rely on the invoice email.

  2. Verify the change using the saved supplier telephone number.

  3. Follow the approved financial process.

  4. Record how the change was verified.

  5. Report inconsistencies as suspected fraud.

Scenario 10: Unauthorised browser extension

A website states that a browser extension is needed to view a referral.

Appropriate response:

  1. Do not install the extension.

  2. Close the page.

  3. Check the referral through the approved system.

  4. Report the website or message.

Scenario 11: Video meeting link

An unexpected person asks to join an online clinical meeting and states that the clinician invited them.

Appropriate response:

  1. Do not admit the person based only on the claim.

  2. Verify their identity and authority through the approved process.

  3. Protect meeting details and patient confidentiality.

  4. Report suspicious access attempts.

Scenario 12: Colleague requests a login

A colleague cannot access Zanda Health and asks to use another administrator’s account for one appointment.

Appropriate response:

  1. Do not share the account or password.

  2. Ask the colleague to use the authorised access-support route.

  3. Escalate urgent work through the manager.

  4. Report repeated or pressured requests for shared access.

24. Key learning points

  • Cybersecurity protects confidentiality, information accuracy and service availability.

  • Unexpected urgency, secrecy or a bypass of normal processes should make staff pause.

  • A familiar display name, logo, voice or writing style does not prove identity.

  • Sensitive requests should be verified through an independently trusted route.

  • Staff must use unique credentials and approved passkeys or two-step verification.

  • Passwords and one-time codes must never be shared.

  • Unexpected sign-in requests must not be approved.

  • Only approved work systems, devices and accounts should be used.

  • Recipients, attachments and sharing permissions must be checked before sending.

  • Devices should be updated, locked and physically secure.

  • Staff must not install software or grant remote access following an unsolicited request.

  • A device which may be infected should no longer be used and should be isolated where safe.

  • Suspicious clicks, lost devices, wrong recipients and near misses must be reported immediately.

  • Staff must not conceal mistakes or attempt to investigate alone.

  • Evidence should be preserved through approved routes.

  • Administration staff report incidents but do not make regulatory notification decisions alone.

  • The Business Continuity Plan should be followed when systems are unavailable.

Knowledge assessment

Learner instructions

Choose the single best answer.

You must achieve at least 12 out of 15 to pass.

Any incorrectly answered safety-critical question must be reviewed even if the overall pass mark is achieved.

Question 1

Which statement best explains why cybersecurity matters in an outpatient psychiatry service?

A. It is only an issue for the IT provider
B. It protects confidentiality, reliable information and access to services
C. It applies only when money is stolen
D. It applies only to clinical staff

Question 2

Which feature proves that an email is genuine?

A. It uses the clinic logo
B. It contains correct staff names
C. It has no spelling mistakes
D. None of these features proves that it is genuine

Question 3

You receive an unexpected link to a shared patient document. What should you do?

A. Sign in so that you can see whether it is genuine
B. Forward it to a personal email account
C. Verify the share through a trusted route and report the suspicious message
D. Reply to ask the sender whether it is safe

Question 4

You entered your work password on a page reached from a suspicious email. What should you do?

A. Wait to see whether anything happens
B. Report it immediately and follow support instructions from a trusted device
C. Delete the email and say nothing
D. Change one letter in the password next week

Question 5

Which statement about two-step verification is correct?

A. Approve requests until they stop
B. Share a code with anyone who knows your job title
C. Deny and report an unexpected request
D. Two-step verification makes password sharing acceptable

Question 6

A message from a senior manager requests an urgent payment outside the normal process. What is the best response?

A. Pay because the sender is senior
B. Verify the request through an independent trusted route and follow the normal approval process
C. Reply to the message and accept the answer
D. Use a personal account to make the payment faster

Question 7

A caller claiming to be IT support asks for your one-time verification code. What should you do?

A. Provide it if the caller sounds professional
B. Provide half of it
C. Refuse, end the call and contact approved support through a trusted route
D. Ask the caller to email you and then provide it

Question 8

Which action is appropriate when sharing a clinic file?

A. Create a public link because it is faster
B. Share it with named authorised people using the least access required
C. Upload it to personal cloud storage
D. Give editor access to everyone in the organisation

Question 9

You accidentally email a patient letter to the wrong person. What should you do first?

A. Hope that they do not open it
B. Delete the sent message only
C. Report it immediately and follow the breach-containment procedure
D. Contact the Information Commissioner’s Office before telling your manager

Question 10

Which statement about personal data breach reporting is correct?

A. Staff should investigate fully before telling anyone
B. Only deliberate attacks count as breaches
C. Staff should report promptly so that the organisation can assess and contain the event
D. A deleted file can never be a breach

Question 11

What should you do with an unexpected multi-factor sign-in request?

A. Approve it once
B. Deny it and report possible account compromise
C. Ignore repeated requests for several days
D. Ask a colleague to approve it

Question 12

A computer displays a ransom demand and files will not open. What is the best immediate response?

A. Pay the demand
B. Continue working to identify every affected file
C. Stop using the device, disconnect it from the network where safe and obtain urgent help
D. Wipe the device immediately

Question 13

Why should near misses be reported?

A. To punish staff for every mistake
B. To identify weaknesses and prevent future harm
C. Because every near miss must be reported to the police
D. Near misses should not be reported

Question 14

A colleague asks to use your Zanda Health account because their access is not working. What should you do?

A. Share it for five minutes
B. Sign in and leave the session open for them
C. Refuse and use the authorised access-support and escalation route
D. Send them your password and change it later

Question 15

Which best summarises the administration team’s role during a cyber incident?

A. Investigate the attacker and decide whether to notify the Information Commissioner’s Office
B. Stop risky activity, contain the incident within the limits of the role, report promptly and preserve evidence
C. Delete all suspicious information
D. Keep the incident private until the next governance meeting

Learner declaration

I confirm that:

  • I have completed the full module.

  • I know how to contact the Registered Manager and urgent IT support.

  • I understand how to recognise and report suspicious messages.

  • I will not share passwords or verification codes.

  • I will not approve unexpected sign-in requests.

  • I understand how to verify payment and bank-detail requests.

  • I know what to do after clicking a suspicious link or entering credentials.

  • I know how to respond if a device may be infected or affected by ransomware.

  • I know where cyber incidents, personal data breaches and near misses must be recorded.

  • I understand that I must report promptly and must not conceal an error.

  • I understand that I must use approved work accounts, devices and systems.

  • I understand my role boundaries during technical and regulatory investigations.

  • I know how to access WMI Psychiatry’s current policies and Business Continuity Plan.

Learner’s name: ______________________________

Role: ______________________________

Date completed: ______________________________

Attempt number: ______________________________

Signature: ______________________________

Score: ______ / 15

Result: Pass / Further learning required

Safety-critical errors reviewed: Yes / No / Not applicable

Manager or assessor: ______________________________

Renewal date: ______________________________

Manager’s marking guide

Question 1

Correct answer: B

Cybersecurity protects confidentiality, the reliability of information and the availability of systems needed for care and administration.

Question 2

Correct answer: D

Logos, names and fluent writing can be copied or generated. The sender and request must be checked using trusted controls.

Question 3

Correct answer: C

The learner should avoid the link, check through the known system or sender and report the suspicious invitation.

Question 4

Correct answer: B

Entered credentials may be used immediately. Rapid reporting allows password reset, session revocation and investigation.

Question 5

Correct answer: C

An unexpected request may mean that someone has obtained the password. It must be denied and reported.

Question 6

Correct answer: B

Seniority and urgency do not replace financial controls. Independent verification reduces the risk of impersonation and compromised-email fraud.

Question 7

Correct answer: C

Verification codes are authentication secrets. The call should be ended and approved support should be contacted independently.

Question 8

Correct answer: B

Named access and least privilege reduce accidental disclosure and limit harm if an account is compromised.

Question 9

Correct answer: C

A wrong-recipient email may be a personal data breach. Immediate reporting enables recall attempts, recipient contact and risk assessment.

Question 10

Correct answer: C

Staff should report the facts promptly. The authorised lead assesses the event and decides whether the Information Commissioner’s Office or affected people must be notified.

Question 11

Correct answer: B

An unexpected sign-in request must not be approved. It may indicate an attempted account takeover.

Question 12

Correct answer: C

Stopping use and isolating the device can reduce the spread of malware. Staff should obtain urgent help and must not pay or wipe the device.

Question 13

Correct answer: B

Near misses reveal weaknesses in messages, workflows and controls before harm occurs.

Question 14

Correct answer: C

Accounts are individual. Urgent work must be escalated without sharing credentials.

Question 15

Correct answer: B

Administration staff should stop risky activity, take approved containment steps, report promptly and preserve evidence. Technical investigation and regulatory decisions require authorised leads.

Questions 4, 5, 7, 9, 10, 11, 12 and 14 are safety-critical.

For every incorrect answer the manager should:

  1. Discuss the correct response with the learner.

  2. Record that the answer was reviewed.

  3. Ask the learner to explain the correct local procedure in their own words.

  4. Confirm that the learner knows the urgent reporting route.

  5. Require reassessment if understanding remains uncertain.

A learner must not be recorded as competent if they remain uncertain about:

  • unexpected sign-in requests

  • credential disclosure

  • wrong-recipient information

  • suspected malware

  • ransomware

  • urgent incident reporting

  • account sharing

  • preserving evidence

  • payment verification

CQC and governance implementation requirements

Before issuing this module WMI Psychiatry should:

  • complete and test every local contact and reporting route

  • confirm the current list of approved systems

  • remove obsolete systems from the module

  • ensure the module matches the current Information Governance Policy

  • ensure the module matches the current incident and data breach procedures

  • provide every user with an individual account

  • ensure access is appropriate to each person’s role

  • enable passkeys or two-step verification where supported and authorised

  • maintain joiner, mover and leaver access controls

  • maintain supported devices

  • install security updates promptly

  • maintain malware protection and encryption

  • maintain tested backups

  • maintain a current Business Continuity Plan

  • provide an approved phishing-reporting route

  • provide an urgent IT-support route

  • maintain a personal data breach and cyber incident log

  • encourage prompt reporting of honest errors and near misses

  • review cyber incidents through governance meetings

  • review account activity and sharing permissions proportionately

  • protect staff personal details from impersonation and social engineering

  • maintain financial verification controls

  • prohibit shared credentials

  • prohibit unauthorised remote-access tools

  • provide practical induction on WMI Psychiatry’s actual systems

  • retain the learner’s answers, score, declaration and attempt number

  • record completion in the staff training matrix

  • document review of safety-critical errors

  • provide refresher training annually

  • provide additional training after relevant incidents or significant system changes

  • consider supportive phishing simulations or practical exercises

  • review whether controls are effective

  • ensure security arrangements do not encourage unsafe workarounds

CQC Regulation 17 requires records to be secure and accessed, amended or destroyed only by authorised people.

CQC expects organisations to provide regular data-security training, restrict access according to role and maintain plans for responding to threats.

CQC Regulation 18 requires staff to receive appropriate support and training.

The UK GDPR security principle requires appropriate technical and organisational measures to protect personal data.

These duties cannot be met through e-learning alone. The training must be supported by effective policies, technical controls, access management, incident reporting, backups, supervision and business continuity arrangements.

Further reading and authoritative guidance

Cybersecurity guidance and legal requirements change. The Registered Manager should confirm that this module remains aligned with current NCSC, ICO, CQC and NHS guidance at each review and following any significant incident or system change.

Previous
Previous

Duty of Candour

Next
Next

Conflict Resolution and De-escalation