NHS Cybersecurity Governance — Freedom of Information Dataset Nov 2025 – Jan 2026
收藏资源简介:
Freedom of Information data on cybersecurity governance in the English NHS. Requests were sent to all 205 NHS trusts in England between November 2025 and January 2026 under the Freedom of Information Act 2000, asking how cyber risk is reviewed, by whom, and through what reporting chain. Response outcomes: 170 substantive responses, 20 formal refusals, 15 no replies. The dataset carries one row per trust contacted, including refusals and non-replies, so that the response rate can be verified independently. Every underlying response is a public record and is linked from its row through the wdtk_url column (WhatDoTheyKnow). Version 1.1.0 adds the terminal governance layer: which body receives cyber risk immediately before the trust board, and whether the chain the trust described reaches the board at all. The coding instrument that produces those variables is deposited alongside the data, and reproduces them exactly when run on the deposited file. Files File Contents DAP_FOI_dataset.csv 205 rows, 15 columns code_oversight.py Rule-based, deterministic coding of the terminal governance layer CODING_MANUAL.md Population, column reference, coding rules, distribution, and the caveat on A5_reaches_board CHANGELOG.md What changed from 1.0.0 and what did not Columns ods_code · org_id · org_name · org_type · response_date · wdtk_url · response_status · A2_count (board or executive committee review frequency, reviews per year) · A3_most_recent_review_year · A4_reporting_line (the chain, verbatim) · A4_oversight_body_count · A9_board_last_training_year · A5_terminal_body · A5_terminal_class · A5_reaches_board NULL marks data not provided, not held, or refused. NONE marks a practice the trust explicitly confirmed as absent. A note on A5_reaches_board In 31 of 163 classifiable chains, the chain as described does not reach the trust board. This is a property of how trusts answered an open question, not evidence that their boards do not receive cyber risk. Thirty of the 31 report board-level cyber review elsewhere in the same response, most with a 2025 board paper; the 31st withheld the item under a statutory exemption. The variable is published for provenance and should be reported, if at all, as a property of the instrument. CODING_MANUAL.md sets out the test. Associated publication Shabad, V. Beyond Explainability: Architectural Accountability in Public Sector Algorithms. SSRN working paper. https://doi.org/10.2139/ssrn.6131147 Licence and re-use The deposit is licensed CC BY 4.0. The licence covers the compilation, the coding, and the coding instrument, all of which are the author's own work. The underlying Freedom of Information responses remain the copyright of the individual NHS trusts that issued them. They were obtained under the Freedom of Information Act 2000, and each is published in full on WhatDoTheyKnow, linked from its row through wdtk_url. What is deposited here is the factual values extracted from those responses together with the author's coding of them: identifiers, dates, counts, years, and the reporting chain as the trust worded it. These are short factual strings, and no substantial part of any response is reproduced. NHS trusts are not Crown bodies (National Health Service Act 2006, Schedule 4), so their material is not Crown copyright, and no Open Government Licence attribution applies to it. Where a trust attached its own re-use terms to a response, those terms govern re-use of that response as a document. They do not attach to the factual values recorded here.



