NHS Cybersecurity Governance — Freedom of Information Dataset Nov 2025 – Mar 2026
收藏资源简介:
Freedom of Information data on cybersecurity governance in the English NHS. Requests were sent to all 205 NHS trusts in England — 204 on 8 November 2025, one follow-up on 10 January 2026 — under the Freedom of Information Act 2000, asking how cyber risk is reviewed, by whom, through what reporting chain, and how many concurrent improvement programmes a trust runs. Responses run from 10 November 2025 to 20 March 2026, against a 31 March 2026 cut-off. Response outcomes: 171 substantive responses, 17 formal refusals, 13 no replies, 2 late replies, 2 replies not on their own request thread. The dataset carries one row per trust contacted, including refusals and non-replies, so that the response rate can be verified independently. Every reply coded as substantive or as a refusal is a public record, linked from its row through the wdtk_url column (WhatDoTheyKnow). The 13 trusts that did not reply, the 2 that replied after the cut-off, and the 2 whose replies are not on their own request thread (documented in CODING_MANUAL.md) carry no coded values. Version 1.2.0 corrects a systematic overstatement in the board-review-cadence variable found on independent re-reading (19 of 43 multi-cadence rows), releases the concurrent-improvement-programmes variable and the FOIA exemption record (which sections were invoked, and which of the nine questions had data withheld), and removes the 1.1.0 terminal-governance-layer fields, whose generator was found independently defective. The changes are listed in CHANGELOG.md; the coding decisions are in CODING_MANUAL.md. Files File Contents NHS_Q9_dataset.csv 205 rows, 17 columns check_dataset.py Deterministic checker: header, vocabularies, numeric/year shape, row uniqueness CODING_MANUAL.md Population, column reference, coding rules, distributions, exemptions, and the A2/A6/A5 notes below CHANGELOG.md What changed at every version, and why Columns ods_code · org_id · org_name · org_type (from the NHS Trust Classification Dataset v1.1) · response_date · wdtk_url · response_status · exemptions_sections (FOIA exemption grounds coded as applying) · partial_refusal_vars (which questions had data withheld) · A2_count (board or executive committee review frequency, reviews per year) · A3_most_recent_review_year · A4_reporting_line (the chain in the trust's words, ordered lowest node first) · A4_oversight_body_count · A6_concurrent_programmes_count · A6_concurrent_programmes_trend · A9_board_last_training_year · A9_in_window NULL marks data not provided, not held, or refused. NONE marks a practice the trust explicitly confirmed as absent. A note on the review-cadence correction All 43 rows naming more than one review cadence were re-read against the rule that only the board, a committee of the board, or an executive committee is in scope. Nineteen were wrong on the first reading — eighteen overstated how often boards look at cybersecurity, one (NHS_116) understated it. A2_count carries the corrected values throughout. A note on A6_concurrent_programmes_count The field is null on 78 of 171 substantive rows. Of those, 31 have this question marked as withheld (30 of them with a coded exemption ground; NHS_022 without one); the remaining 47 do not. Some of the 47 described an ongoing process instead of a count, which the author reads as an instrument defect rather than a response issue; the released columns do not separate them from other non-numeric answers. Distribution over the 171 substantive rows: 93 non-null, median 4, mean 6.18. A note on the removed terminal-governance-layer fields Version 1.1.0 carried three fields — A5_terminal_body, A5_terminal_class, A5_reaches_board — describing the node of a trust's reporting chain immediately before the trust board. They are removed in this version: their generator was independently defective (misparsing conjunctions and prose chains, misclassifying committees as individuals) and had also gone stale against hand-corrected chains. They are not being rebuilt from the stored values. Full detail in CODING_MANUAL.md. Associated publication Shabad, V. Beyond Explainability: Architectural Accountability in Public Sector Algorithms. SSRN working paper. https://doi.org/10.2139/ssrn.6131147 Licence and re-use The deposit is licensed CC BY 4.0. The licence covers the compilation, the coding, and the coding instrument, all of which are the author's own work. The underlying Freedom of Information responses remain the copyright of the individual NHS trusts that issued them. They were obtained under the Freedom of Information Act 2000, and each reply coded as substantive or as a refusal is published in full on WhatDoTheyKnow, linked from its row through wdtk_url. The two replies not on their own thread (NHS_083, filed on another trust's thread, and NHS_126, received by e-mail) are coded OFF_PLATFORM and carry no coded values. What is deposited here is the factual values extracted from those responses together with the author's coding of them: identifiers, dates, counts, years, and the reporting chain as the trust worded it. These are short factual strings, and no substantial part of any response is reproduced. NHS trusts are not Crown bodies (National Health Service Act 2006, Schedule 4), so their material is not Crown copyright, and no Open Government Licence attribution applies to it. Where a trust attached its own re-use terms to a response, those terms govern re-use of that response as a document. They do not attach to the factual values recorded here.



