Skip to content
USE CASE: NHS ORGANISATIONS

DSPT and Cyber Risk Assurance for NHS Organisations

STREAM® Cloud connects cyber risk, controls, actions and evidence in one workspace, so your Data Security and Protection Toolkit submission and board-level assurance rest on a coherent view, not scattered spreadsheets.

Request a Demo

NHS organisations must complete the Data Security and Protection Toolkit (DSPT) every year, measuring their performance against the National Data Guardian's ten data security standards, and the NHS Standard Contract requires suppliers who touch NHS data to meet the same standard. STREAM Cloud is Acuity Risk Management’s configurable workspace for the cyber risk, control, action and evidence work behind that submission: a connected view instead of spreadsheets, static reports and disconnected action logs, so assurance is easier to build, defend and act on from ward to board.

What sits behind the Toolkit submission

Every NHS organisation submits the Data Security and Protection Toolkit annually, a self-assessment against the National Data Guardian's ten data security standards, now aligned to the NCSC's Cyber Assessment Framework. Every supplier, data processor and joint controller that touches personal or confidential data is expected to have completed one too, and the NHS Standard Contract requires providers to comply with the Toolkit's mandatory requirements. NHS England's own voluntary Cyber Security Charter for suppliers sets the bar at 'Standards Met' or better, alongside multi-factor authentication, continuous monitoring and board-level incident exercises.

The pressure on NHS oversight is not getting lighter. Many teams are still working across spreadsheets, static reports, disconnected action logs and separate evidence stores, which makes assurance harder to build, harder to defend and harder to act on. When risks sit in one place, controls in another, actions somewhere else, and reporting depends on manual collation, leadership sees updates but not always context, and teams produce evidence but not always a connected view.

For the audit committee or board, the question isn't whether the Toolkit gets submitted. It's whether the submission is backed by a defensible, connected record if a National Data Guardian review, a commissioner's due diligence check, or a contract renewal asks to see it. That's a governance question as much as a technical one, and it's answered by how the evidence is held between submissions, not only on the day it's filed.

What STREAM Cloud gives you

  • Cyber risk, controls, assets, actions, incidents and compliance activity linked in one platform, instead of stitched-together updates from separate systems.
  • A DSPT-ready evidence trail: the record a National Data Guardian review or commissioner’s due diligence check would ask to see, held as structured evidence rather than assembled after the request lands.
  • Cyber risk quantification and continuous controls monitoring, for organisations that want more than checkbox compliance.
  • Ward-to-board reporting: dashboards, search and audit history built for governance meetings and audit readiness, not just the Toolkit submission itself.
  • Supplier oversight through Vendor Management Hub, for the suppliers and data processors your own DSPT submission depends on.
  • ISO 27001-aligned ISMS lifecycle support, for organisations building assurance beyond the Toolkit’s ten standards.

STREAM Cloud is not a SIEM, security operations platform, or incident response tool, and it does not replace your clinical or incident-reporting systems. It is a configurable workspace for the cyber risk, control and evidence work that sits alongside them. It does not submit your Data Security and Protection Toolkit assessment on your behalf: it holds the evidence and control record your team uses to complete it. And it is not a certification in itself: it is where you keep the record that a reviewer would ask to see.

Built for NHS trusts, integrated care boards and other NHS organisations managing cyber risk and Toolkit evidence across multiple teams and services. If you’re a small practice with a single, simple DSPT submission and no board-level reporting need, a full workspace like this is likely more than you need today; the STREAM Editions Quiz is a two-minute way to check.

Who this is for

The compelled buyer and the person who signs off the budget usually aren’t the same person here, and they’re looking for different things on this page.

Chief Information Security Officer / Head of Cyber Security

The compelled buyer: owns the Toolkit submission and the evidence behind it.

Head of Information Governance / Data Protection Officer

Needs the ten standards and supplier assurance held in one place, not siloed.

Digital / IT Director

Needs cyber risk and controls connected to the systems they actually run.

Audit Committee / Non-Executive Director

The board-level buyer: needs a defensible, connected view, not a status update with no context behind it.

Third-Party / Supplier Risk Lead

Needs oversight of the suppliers and data processors the organisation’s own submission depends on.

How a connected workspace works

There is no named NHS case study to share here yet; this is how the work typically runs.

1

Baseline. Hold your current position against the ten data security standards as a structured record, not a static document.

2

Connect. Link risks, controls, actions, incidents and supplier assurance so they reference each other, not sit in separate files.

3

Evidence. Capture the evidence behind each control as you go, not reconstructed in the weeks before submission.

4

Report. Produce ward-to-board and audit-committee views from the same underlying record, not a separate slide deck.

5

Resubmit. Carry the record into next year’s Toolkit cycle instead of starting again from spreadsheets.

When STREAM Classic may be needed

STREAM Cloud is built to fit most NHS organisations connecting cyber risk and Toolkit evidence. STREAM Classic may be the better starting point if you need:

  • Configurable automations
  • APIs
  • Quantitative analysis
  • Enterprise-scale cyber GRC
  • Messaging and alerting
  • Advanced modelling
  • Complex data sets
  • You’re a large multi-site trust or an Integrated Care Board coordinating cyber risk across many constituent organisations and need Classic-grade depth across that scale
Compare STREAM Cloud and Classic →

STREAM Cloud for NHS: FAQs

Common questions about STREAM Cloud, the Data Security and Protection Toolkit, and how this fits alongside Acuity's patient safety workspace.

See it against your own Toolkit position