Cyber Risk at Board Level: Aligning NHS Leadership, Supplier Risk and Organisational Resilience

2 6a59eca73d26c

NHS Executive Tabletop Exercise: Third-Party Dependency, Decision-Making and Organisational Resilience

  • Date: 10th November 2026
  • Time: 10:30am - 1:30pm
  • Venue: etc.venues, Prospero House, 241 Borough High St, London, SE1 1GA
  • Attendance: Complimentary for approved NHS and public sector delegates
  • Places: Maximum 15 participants

VISIT BLUEFORT HERE

 

About the Session

Cyber incidents affecting NHS organisations are no longer solely an IT issue.

A significant cyber event can quickly affect clinical services, operational capacity, communications, workforce deployment, patient safety and critical third-party suppliers.

This private, scenario-led tabletop exercise will bring together a small group of senior NHS leaders to explore how an organisation responds when a major cyber incident begins to disrupt essential services.

Rather than focusing on technical cyber defence, the session will examine the decisions senior leaders may need to make during an incident, how responsibilities are shared across the organisation and how boards and executive teams maintain safe and resilient services under pressure.

A Practical Board-Level Exercise

The centrepiece of the session will be an interactive tabletop scenario designed around a realistic cyber incident affecting an NHS organisation and one or more of its critical third-party dependencies.

Participants will work through the evolving scenario as a leadership group, considering:

  • What information is needed before decisions can be made.
  • Who should take ownership of different elements of the response.
  • How clinical and operational services should be prioritised.
  • When and how an incident should be escalated.
  • How third-party suppliers should be managed during disruption.
  • What the board and executive team need to know.
  • How regulatory, governance and assurance responsibilities should be handled.
  • How the organisation moves from immediate response into recovery.

The exercise is intended to encourage discussion, challenge assumptions and examine how different senior functions work together during a significant incident.

Key Areas of Focus

Key Areas of Focus

Executive Cyber Decision-Making

Exploring the decisions senior leaders may need to make when normal digital services are disrupted and information remains incomplete.

Clinical and Operational Resilience

Considering how organisations maintain safe patient care, prioritise critical services and manage operational pressures during prolonged digital disruption.

Third-Party and Supplier Risk

Examining what happens when a critical supplier, platform or infrastructure provider becomes part of the incident. This will look beyond data loss alone and consider the wider operational impact created by dependencies across the hospital or healthcare system.

Governance and Accountability

Understanding how responsibilities are shared across boards, executives, clinical leadership, digital teams, operational teams and assurance functions.

Organisational Response and Recovery

Considering escalation, communication, business continuity, recovery priorities and the decisions required as an organisation begins restoring services.

Who Should Attend?

This session is designed for senior NHS and public sector leaders who would have a role in organisational decision-making, governance, clinical continuity or operational response during a significant cyber incident.

Relevant roles may include:

  • Board members and Non-Executive Directors.
  • Chief Executives and Executive Directors.
  • Medical Directors and Deputy Medical Directors.
  • Chief Clinical Information Officers.
  • Chief Information Officers and Chief Digital Information Officers.
  • Directors of Digital and Transformation.
  • Directors of Operations.
  • Directors of Risk, Governance, Audit or Assurance.
  • Senior clinical leaders with digital resilience responsibilities.
  • Senior leaders involved in Emergency Preparedness, Resilience and Response.
  • Integrated Care System and wider NHS executive leaders.

Delegate Suitability

Places are deliberately limited to ensure a senior, relevant and highly interactive discussion.

Delegates do not need to be cybersecurity specialists.

However, attendees should have some level of responsibility or involvement in the organisational response if a major cyber incident occurs.

This could include responsibility for:

  • Executive or senior clinical decision-making.
  • Incident escalation or command.
  • Business continuity.
  • Maintaining safe clinical services.
  • Organisational resilience.
  • Board-level cyber governance.
  • Risk, assurance or regulatory accountability.
  • Digital recovery.
  • Third-party or supplier dependency.
  • Operational response.

All registrations will be reviewed before attendance is confirmed.

Session Format

10:30am - Arrival, Registration and Networking

Tea and coffee on arrival with an opportunity to meet the other participants.

10:45am - Opening Insight: Cyber Risk as an Executive Responsibility

Led by Jessica Figueras.

An opening discussion examining cyber risk through a board and executive leadership lens, including organisational accountability, resilience and the importance of coordinated leadership during an incident.

11:10am - Interactive NHS Cyber Tabletop Exercise

A facilitated, evolving cyber scenario designed to test executive decision-making, clinical and operational priorities, governance, escalation and third-party dependency.

The scenario will develop in stages, requiring participants to consider new information and agree how the organisation should respond.

12:10pm - BlueFort Insight Session

A focused session exploring lessons around cyber resilience, supplier dependency and the practical challenges organisations face when critical technology or infrastructure is disrupted.

12:30pm - Facilitated Board-Level Discussion

A structured discussion reflecting on the exercise and examining:

  • What worked
  • Where decision-making became difficult
  • Potential governance gaps
  • Third-party dependencies
  • Communication and escalation
  • Lessons organisations can take back to their own boards and executive teams

1:15pm - Closing Reflections and Key Takeaways

Final observations and practical actions for participants to consider within their own organisations.

1:30pm - Lunch and Networking

Post-session lunch and informal networking.

Facilitator

Jessica Figueras

Jessica Figueras is a specialist in cyber governance, board-level cyber risk and organisational resilience.

The session will focus on the leadership and governance questions that arise during major cyber incidents rather than technical cybersecurity operations.

Jessica will chair the discussion, introduce the scenario and facilitate the executive tabletop exercise.

Supporting Partner

BlueFort

BlueFort is supporting the development of this private NHS leadership session.

BlueFort will contribute insight around organisational cyber resilience, critical supplier dependencies and the challenges organisations face when technology disruption begins to affect wider service delivery.

VISIT BLUEFORT HERE

Shaping the Scenario

Approved participants will be asked to complete a short registration questionnaire ahead of the session.

Responses will help the facilitators understand:

  • Participants' roles during cyber incidents.
  • Current organisational priorities.
  • Areas of concern.
  • Third-party dependencies.
  • Governance responsibilities.
  • The issues delegates would most value exploring.

This information will be used to help shape the final scenario and discussion so that the exercise reflects the priorities of those attending.

Registration

Attendance is complimentary for approved NHS and public sector delegates.

Due to the interactive format, attendance is strictly limited to 15 participants.

All applications will be reviewed to ensure attendees have an appropriate level of responsibility or involvement in organisational cyber incident response, resilience, governance or continuity.

Request a place to attend.

Our accreditations

abpco
Manchester Bee
Living Wage Employer
Good Employment
Good Employment Member
Armed Forces Covenant
Tech UK
IHSCM
FSB
Ban The Box
Stockport County
cpdgroup
Q-Park
Play It Green