Portsmouth Hospitals University NHS Trust operates on a scale that makes it a high-value target. Serving roughly 675,000 residents across Portsmouth and south east Hampshire, with specialist services reaching over 2 million people, the trust runs 1,200 beds, 28 operating theatres, and treats over half a million patients annually. It's a sprawling attack surface - medical devices, EHR systems, imaging networks, and the operational infrastructure of acute care all need defending.
The threat model is acute healthcare: ransomware that can halt surgeries, breaches exposing sensitive patient data, and attacks on connected medical equipment like the trust's four linear accelerators used in cancer treatment. Portsmouth also hosts a Ministry of Defence Hospital Unit, adding another layer of classification and coordination complexity. With over 8,700 staff across multiple sites including Gosport and Petersfield, identity management and access control alone is a significant operational domain.
The trust covers general and specialized medical care including regional cancer services and the Wessex Kidney Service, meaning any cybersecurity incident has direct clinical consequences. The security team here isn't protecting abstract assets - they're supporting live clinical workflows where downtime translates to delayed treatment. It's a role where technical decisions carry weight measured in patient outcomes.






