Three NHS Trusts Chose the Same Cyber Security Vendor for the Same Reason. A Fourth Solved a Completely Different Problem
Birmingham Community Healthcare, Wrightington Wigan and Leigh, and Royal Orthopaedic Hospital didn’t choose the same cyber security vendor independently, their own case studies document a direct reference chain traced back to WannaCry. Oxford University Hospitals’ case study, filed under the same tag, solves an entirely different problem.
Key Takeaways
- Four NHS trusts’ published cyber security case studies look, from a distance, like four separate stories. Read closely, three of them, Birmingham Community Healthcare, Wrightington, Wigan and Leigh, and Royal Orthopaedic Hospital, converge on the same vendor, the same underlying model, and, in two cases, the exact same documented reason for choosing it.
- Birmingham Community Healthcare’s own account is explicit about the trigger: “Ever since WannaCry back in 2017, the Trust’s Board of Directors and I recognised we needed to up our game in regard to cyber security and give it the resource it demands,” said Gerard Kilgallon, the Trust’s Head of IT. Wavenet ran a proof of concept, then expanded into a full Security Information and Event Management deployment and CREST-approved penetration testing.
- Wrightington, Wigan and Leigh didn’t arrive at the same vendor independently. This publication’s own case study states the Trust “looked to Wavenet after seeing the benefits CyberGuard had delivered for Birmingham Community Healthcare NHS Foundation Trust,” a directly documented reference chain between two NHS trusts, not an assumption. WWL added a UK-based, 24/7/365 Security Operations Centre and cited the same national pressure Birmingham Community Healthcare named: “Cyber attacks are increasing yearly, and because of that, so is the demand for security coverage,” said Alan Moss, the Trust’s IT Programme Manager.
- Royal Orthopaedic Hospital’s case study describes a third, related layer of the same referral pattern: Wavenet’s existing relationship with Birmingham Women’s and Children’s NHS Foundation Trust, a fellow member of the same Integrated Care System, gave the hospital “further confidence in the relationship” before it signed on for 24/7/365 cloud-based cyber support.
- Oxford University Hospitals’ project, unlike the other three, has nothing to do with detecting or responding to attacks. Working with Telefónica Tech and Starlight Consulting rather than Wavenet, it built a Secure Data Environment governing how more than 30 billion health records can be safely accessed by researchers, a data governance and access-control problem, not a threat-detection one. For a UK C-suite, the useful distinction these four case studies draw isn’t “which vendor NHS trusts prefer.” It’s that “NHS cyber security” case studies actually describe two entirely different disciplines, defending infrastructure against attackers, and governing safe access to data, and only one of those two disciplines shows the peer-reference pattern visible across three of these four trusts.
Four NHS organisations’ published cyber security case studies sit in the same category on paper. Read together, they reveal something more specific than “the NHS is investing in cyber security”: three of the four trusts didn’t make their decision independently at all, they can be traced, in their own words, back to a single earlier deployment and a shared trigger, the 2017 WannaCry ransomware attack. The fourth solved a problem the other three never mention.
Birmingham Community Healthcare: the trust that started the chain
Birmingham Community Healthcare NHS Foundation Trust, which delivers more than 100 clinical services across 200 hospitals, health centres and clinics, traces its cyber security investment directly to a single event. “Ever since WannaCry back in 2017, the Trust’s Board of Directors and I recognised we needed to up our game in regard to cyber security and give it the resource it demands,” said Gerard Kilgallon, the Trust’s Head of IT. The Trust’s disparate workforce and IT landscape, combined with limited internal cyber security expertise, had made a coherent strategy difficult to build while the IT team’s priority remained keeping clinical services running. Wavenet ran a proof of concept for its CyberGuard solution over several weeks, alongside setting up a Critical Incident Response Service so a Security Operations Centre could investigate and remediate threats at source. “The proof of concept went as well as it possibly could have, the process of integrating new systems and protocols was managed seamlessly,” Kilgallon said. Wavenet’s role has since expanded to a full Security Information and Event Management deployment and CREST-approved internal and external penetration testing, giving the Trust what its own case study describes as constant threat detection through the Security Operations Centre.
Wrightington, Wigan and Leigh: a documented reference, not a coincidence
What makes Wrightington, Wigan and Leigh Teaching Hospitals NHS Foundation Trust’s case study worth reading directly against Birmingham Community Healthcare’s is that the connection between them isn’t inferred, it’s stated. WWL, a medium-sized Trust supporting 7,000 active IT users across the Wigan borough and Greater Manchester, “looked to Wavenet after seeing the benefits CyberGuard had delivered for Birmingham Community Healthcare NHS Foundation Trust,” according to this publication’s own account. Facing the same post-WannaCry threat landscape and a national NHS cyber security skills shortage, WWL combined a Managed Detect and Respond solution with Microsoft Azure Sentinel as its SIEM system, monitored 24/7/365 from a UK Security Operations Centre, and ran a three-month trial with weekly review meetings before committing to a full partnership. “Cyber security is an ever-evolving challenge and partnering with Wavenet put us in the best position to protect ourselves,” said Malcolm Gandy, WWL’s Chief Information Officer. Alan Moss, the Trust’s IT Programme Manager, named the same pressure Birmingham Community Healthcare’s own case study describes: “Cyber attacks are increasing yearly, and because of that, so is the demand for security coverage.”
Royal Orthopaedic Hospital: the third link in the same chain
The Royal Orthopaedic Hospital NHS Foundation Trust, one of the largest specialist orthopaedic units in Europe, extends the same pattern a step further. As part of the NHS Integrated Care System covering Birmingham and Solihull, whose shared processes aren’t always suited to fast implementation, ROH needed to replace an on-premise security setup and traditional service desk cover that didn’t extend to out-of-hours cyber alerts. It, too, chose Wavenet, moving to a cloud-based cyber security service with 24/7/365 support, standardised alert handling and a formal internal IT service management system built around weekly checkpoints. The Trust’s own case study is specific about why the choice felt lower-risk than it might otherwise have: Wavenet’s existing work with Birmingham Women’s and Children’s NHS Foundation Trust, a fellow member of the same Integrated Care System, gave ROH “further confidence in the relationship.” “Wavenet consistently outperformed, outpriced, and out serviced other providers,” said Chris Page, ROH’s Cyber Security Consultant. “We were looking for the best service and value for money, that offered the best protection to the widest number of threats that we both knew and didn’t know about.”
Oxford University Hospitals: a fourth NHS trust, and a completely different problem
Oxford University Hospitals NHS Foundation Trust’s case study sits in the same “NHS cyber security” category as the other three on this publication’s own tagging, and describes something with almost no overlap in substance. Working with Telefónica Tech and Starlight Consulting rather than Wavenet, OUH built the Thames Valley and Surrey Secure Data Environment, unifying more than 30 billion health records covering a population of 4.3 million people into a single, secure research platform. The problem it solved wasn’t detecting or responding to attackers; it was governance, giving researchers safe, ethical, de-identified access to data that traditional processes had made slow and fragmented to obtain, sometimes taking years to establish, across dozens of NHS organisations each running bespoke research approval processes. The team stood up the initial environment and began onboarding data sources within six weeks, building in joint controllership agreements with NHS partners, an airlock process controlling what data can leave the environment, and a patient and public access review committee. More than 35 research projects are now live, with over 100 approved researchers accessing the platform. “Every day, vast amounts of health data are collected, but much of its potential remains untapped, not just because of time constraints, but because traditional systems made it difficult for anyone to access and use this information effectively,” said Professor Jim Davies, the environment’s Chief Technical Officer. Nothing in Oxford University Hospitals’ case study references WannaCry, a Security Operations Centre, or any of the threat-detection language that runs through the other three trusts’ accounts, because it was never solving that problem.
What a UK C-suite should actually take from reading these four together
The instructive finding here isn’t that NHS trusts are investing in cyber security, every large UK institution is. It’s that three of these four trusts’ decisions can be traced through a documented chain rather than treated as four independent choices: Birmingham Community Healthcare built the original CyberGuard deployment in response to WannaCry, Wrightington, Wigan and Leigh explicitly chose the same vendor after seeing what it delivered there, and Royal Orthopaedic Hospital drew confidence from Wavenet’s separate work with a fellow Integrated Care System member. That’s a real, citable pattern of peer reference inside a single sector, not a coincidence of three trusts reaching for the same category of tool. Oxford University Hospitals’ case study is the useful control: tagged the same way, published in the same category, but solving a governance and access problem with an entirely different vendor and no trace of the same reference chain. For a UK C-suite evaluating its own cyber security investment, the practical lesson from all four together is that a vendor’s track record inside your own sector, not just its general reputation, is doing real, documented work in how similar organisations actually choose, and that “cyber security” as a category still needs breaking apart into what specific problem, attack detection or data governance, is actually being solved before any of these four trusts’ results can be read as a template.

