Skip to main content

Part of Networks and connectivity standards

Network management standards

Standards you should meet on network management tools, monitoring and performance.


4.1 NHS organisations should proactively manage filtering and monitoring systems

Importance of meeting the standard

Filtering and monitoring systems help protect NHS networks, staff and patients from inappropriate, harmful or illegal online content. They also reduce exposure to cyber threats and support compliance with safeguarding, DSPT requirements.

When to meet the standard

You should meet this standard when:
  • reviewing, maintaining or updating existing filtering and monitoring systems
  • commissioning new internet services
  • upgrading internet or wireless services
  • completing a DSPT assessment
  • issues are identified through audits or incidents

How to meet the standard

You should ensure your organisation has
  • a suitable filtering solution that blocks harmful and high‑risk content
  • monitoring tools that provide visibility and alerting of inappropriate or suspicious activity
  • clear processes for reviewing alerts, reports and incidents
  • filtering rules that reflect safeguarding, security and clinical needs
  • roles and responsibilities agreed across IT, cyber security and safeguarding teams

Your approach should align with DSPT, Cyber Assurance Framework (CAF) and Internet Watch Foundation (IWF) requirements.

Technical requirements to meet the standard

Filtering and monitoring solutions should
  • block illegal and harmful content (including IWF‑listed material)
  • support different policies for staff, guests and public Wi‑Fi
  • protect against high‑risk categories such as malware, phishing and proxies
  • provide reporting and alerting capabilities
  • receive regular updates to filtering lists and threat intelligence

Systems should be maintained and reviewed regularly to ensure they remain effective as risks evolve.

Aligns to the following DSPT principles:

Principle How it supports
Policies, processes and procedures Clean, documented data paths make secure design and monitoring more effective.
Security monitoring Improves monitoring coverage, secure log handling, alerting and the ability to identify security incidents.

4.2 NHS organisations should have solutions in place to centrally manage all network infrastructure

Importance of meeting the standard

NHS networks, wired and wireless, support a wide range of clinical and operational services. As the number of connected devices grows, and as digital dependency increases, it becomes essential to have a centralised way to configure, monitor and secure the network.

A centrally managed solution helps to:

  • ensure consistent configuration across switches and wireless access points
  • improve visibility of performance and faults across the whole network
  • enable faster diagnosis and resolution of service issues
  • support secure, standardised deployment of updates, firmware and patches
  • reduce operational burden through automation and policy‑based management

Centralised management provides a stable and predictable network environment that supports safe, efficient patient care.

When to meet the standard

You should meet this standard when
  • upgrading an underperforming or unsupported wired or wireless network
  • introducing new network infrastructure
  • carrying out digital refresh programmes, building works or major wireless modernisation
  • consolidating multiple network solutions or legacy platforms

How to meet the standard

You should work with your supplier or IT support to implement a centralised management solution that
  • provides unified configuration and monitoring for both wired network switches and wireless access points
  • enables proactive management through dashboards, alerts and reporting
  • supports consistent application of policies such as segmentation, QoS, authentication and access management
  • provides automated or guided updates for security patches, firmware and software
  • enables remote troubleshooting and reduces the need for on site interventions
  • aligns with your wider network management, resilience and cyber security practices
Management solutions may be
  • cloud based, where appropriate for the site and organisation
  • on premises, where required for resilience, integration or security
  • hybrid, where capabilities are distributed across both 

The solution should be scalable, from small sites with a compact network footprint, to large hospital campuses with extensive wired and wireless infrastructures.

Technical requirements to meet the standard

To meet this standard, your central management solution should
  • provide configuration, monitoring and alerting capabilities for the entire network (wired and wireless)
  • use open standards where possible to increase interoperability and reduce risk of vendor lock-in
  • support visibility of device health, performance and capacity
  • enable application of consistent security, segmentation and access policies
  • include vendor supported warranties, licences, firmware updates and security enhancements
  • allow automated or scheduled software and security updates
  • include administrator training appropriate to the scale of your network and security requirements
  • be scalable and capable of supporting future increases in bandwidth, device density and complexity
Where available, management tools should also support
  • inventory and lifecycle visibility for network equipment including integration with a Configuration Management Database (CMDB)
  • change control and configuration management features
  • audit logging of all configuration and administrative access changes
  • integration with other relevant monitoring or cyber security systems

Aligns to the following DSPT principles:

Principle How it supports
System security Enables central administration and controlled, consistent configuration changes.
Security monitoring Provides consolidated telemetry and alerting across network infrastructure.

4.3 NHS organisations should proactively monitor network performance, capacity and health across fixed and wireless networks

Importance of meeting the standard

Reliable network performance is essential for delivering safe and efficient digital healthcare. Proactive monitoring across both fixed and wireless infrastructure helps NHS sites:

  • identify issues early and minimise disruption to clinical and operational services
  • maintain sufficient capacity and performance for current and future demands
  • support rapid diagnosis and resolution through timely, meaningful alerts
  • detect anomalies, degradation or unusual behaviour that could indicate security or service risks
  • make informed decisions about upgrades, resilience measures and investment

Modern monitoring, especially when enhanced by AI and cloud‑based analytics, enables NHS organisations to move from reactive fault‑fixing to predictive, intelligence‑led network management.

This supports real‑time clinical applications like Ambient Voice Technology (AVT), where performance issues may not be visible via traditional network metrics alone and identification requires monitoring of end‑user experience and application behaviour.

When to meet the standard

You should meet this standard when
  • deploying or upgrading network infrastructure
  • implementing centralised management solutions for wired and wireless networks
  • carrying out resilience, cyber‑security or digital transformation activity

How to meet the standard

You should work with your supplier, IT support team or network partner to ensure
  • continuous monitoring is in place for wired switching and wireless access networks
  • alerts are generated for critical events (outages, degradation, abnormal activity, capacity thresholds)
  • performance and capacity measures such as latency, throughput, jitter, signal quality and utilisation are regularly reviewed
  • proactive workflows are in place to triage and respond to alerts quickly
  • monitoring data informs network planning, resilience reviews and business continuity processes
AI‑assisted or cloud‑based monitoring capabilities are used where appropriate to
  •  detect anomalies or patterns that humans may not spot
  • anticipate likely failure points
  • provide predictive insights on capacity, performance or configuration issues
  • reduce time to identify and resolve problems

Monitoring should be integrated into your central network management platform wherever possible.

Monitoring approaches should reflect the scale, complexity and clinical dependency of each site.

Technical requirements to meet the standard

To meet this standard, your monitoring capabilities should
  • provide visibility across core, distribution and access network layers
  • support fixed connectivity, switching, routing and wireless access networks
  • track key performance metrics and generate alerts based on thresholds or detected anomalies
  • provide historical trend analysis to support forecasting, planning and diagnostics
  • use open standards where possible to support integration with third‑party monitoring, logging and Security Information and Event Management (SIEM) systems
  • integrate, where possible, with cyber‑security monitoring and logging tools
  • include AI or cloud‑based features that support predictive maintenance, anomaly detection and automated insights
  • use vendor‑supported tools with regular updates, enhancements and security patches
  • use end-user experience monitoring tools to ensure clinical applications are performing as expected

Monitoring configurations should be regularly reviewed to ensure they remain aligned with clinical, operational and security needs.

Aligns to the following DSPT principles:

Principle How it supports
Security monitoring Proactive AI or cloud analytics enhance monitoring coverage, alerting workflows and the capability of monitoring tools and staff.

4.4 NHS organisations should adopt Software-Defined Networking to improve performance, flexibility and security

Importance of meeting the standard

NHS networks are becoming increasingly complex, supporting clinical systems, cloud‑based services, IoT, medical devices and modern wireless networks.

Traditional static network architectures can limit performance, resilience and flexibility.

Software‑Defined Networking (SD‑Networking) allows organisations to:

  • simplify and centralise control of both LAN and WAN
  • apply consistent security, segmentation and access policies
  • optimise traffic paths for cloud and Internet‑First services
  • improve resilience through automated failover, path selection and continuous monitoring
  • reduce reliance on rigid private networks by moving towards modern, flexible connectivity models
  • support Zero Trust principles and future digital service delivery
  • support Secure Access Service Edge (SASE) architectures to provide consistent connectivity and security for remote sites and users

SD‑Networking provides a scalable foundation suitable for small GP practices through to large acute hospitals. The more complex and diverse your network, the more appropriate and beneficial implementing SD-Networking becomes.

When to meet the standard

You should meet this standard when
  • refreshing network infrastructure (wired or wireless)
  • upgrading WAN connectivity or moving towards an Internet‑First model
  • modernising segmentation, security or network management approaches
  • carrying out major digital transformation or cloud adoption programmes

How to meet the standard

You should work with your network provider or IT support to ensure your SD‑Networking approach:

  • supports both LAN and WAN connectivity, including switching, routing and wireless infrastructure
  • aligns with Internet‑First principles, making efficient and secure use of the public internet for appropriate services
  • extends security and access controls to remote sites and users through Secure Access Service Edge (SASE) aligned services
  • supports consistent policy enforcement regardless of user location or access method
  • maintains the ability to use private networks where clinically or operationally necessary
  • provides centralised management for policies, devices and connectivity
  • enables secure segmentation across sites, user groups, devices and clinical systems
  • includes performance monitoring and automated optimisation
  • supports integration with cyber‑security controls such as identity‑based access, Zero Trust and continuous verification

SD‑Networking solutions may be cloud‑managed, on‑premises or hybrid, depending on organisational requirements and resilience needs.

You should work with your network provider or IT support to ensure your SD‑Networking approach
  • supports both LAN and WAN connectivity, including switching, routing and wireless infrastructure
  • aligns with Internet‑First principles, making efficient and secure use of the public internet for appropriate services
  • extends security and access controls to remote sites and users through Secure Access Service Edge (SASE) aligned services
  • supports consistent policy enforcement regardless of user location or access method
  • maintains the ability to use private networks where clinically or operationally necessary
  • provides centralised management for policies, devices and connectivity
  • enables secure segmentation across sites, user groups, devices and clinical systems
  • includes performance monitoring and automated optimisation
  • supports integration with cyber‑security controls such as identity‑based access, Zero Trust and continuous verification

SD‑Networking solutions may be cloud‑managed, on‑premises or hybrid, depending on organisational requirements and resilience needs.

Technical requirements to meet the standard

To meet this standard, your SD‑Networking solution should
  • provide a centralised platform for managing both LAN and WAN components
  • support dynamic routing and traffic optimisation for cloud and internet services
  • implement consistent segmentation and access control policies across all sites
  • enable encrypted connectivity between sites and to cloud services
  • support automatic failover across available links (including internet, full‑fibre, mobile or private network connections)
  • integrate with existing firewalls, identity providers and monitoring tools
  • provide vendor‑supported updates, security patches and lifecycle management
  • support Secure Access Service Edge (SASE) components for remote site and user connectivity, including integrated security and access controls
  • provide API‑driven automation to enable policy‑based configuration, orchestration and integration with other management systems
  • include high‑availability and disaster recovery for SD‑Networking management and control planes

SD‑Networking solutions should be scalable and adaptable to different NHS environments, from small single‑site practices to large multi‑building hospital estates.

Aligns to the following DSPT principles:

Principle How it supports
System security Enables policy‑driven security controls and centralised management across LAN and WAN.
Resilient networks and systems Supports link and path diversity and automated failover.
Security monitoring

Provides integrated telemetry to enhance monitoring and troubleshooting.


4.5 NHS organisations should ensure all network and connectivity equipment is supported, maintained and resilient against cyber threats

Importance of meeting the standard

Network and connectivity infrastructure underpins the safe delivery of digital healthcare services. Equipment that is out of support, unable to receive updates, or operating beyond its intended life introduces significant cyber, operational and clinical risk. Maintaining a secure, supported and up‑to‑date network estate ensures:

  • access to critical security patches and manufacturer‑issued fixes
  • protection against emerging cyber threats and vulnerabilities
  • predictable performance and resilience across core network services
  • reduced likelihood of outages, instability or security breaches

Keeping network infrastructure within supported life is essential for maintaining both cyber and operational resilience.

When to meet the standard

You should meet this standard when
  • procuring, designing or refreshing network or connectivity services
  • existing equipment approaches end‑of‑life (EoL) or end‑of‑support (EoS)
  • subscriptions or licences that support updates are due for renewal
  • carrying out cyber‑security reviews, DSPT assessments or major upgrades

How to meet the standard

You should ensure the organisation
  • only deploys equipment that is actively supported by the manufacturer
  • maintains valid licences and subscriptions so devices receive firmware, patches and security updates
  • reviews vendor lifecycle announcements and plans timely replacement of End of Life (EoL) and End of Support (EoS) devices
  • routinely applies firmware and software updates following safe change processes
  • uses accelerated patching cadence for externally facing infrastructure
  • maintains visibility of supported‑life status across all network devices, including those hosted or managed by third-parties
  • designs network infrastructure so unsupported equipment cannot become a single point of failure
  • aligns replacement cycles with resilience, security and capacity‑planning activities

Technical requirements to meet the standard

To meet this standard, NHS organisations should ensure
  • all core network components (switching, wireless infrastructure, firewalls, routers, security appliances, Software Defined‑Networking (SDN) platforms) are within supported life
  • SDN solutions support open APIs and interoperable orchestration to reduce risk of vendor lock-in
  • devices have current support contracts enabling access to patches, technical support and firmware updates
  • security updates are applied promptly and safely, with automated or centrally orchestrated updates used where appropriate
  • End of Life (EoL) and End of Support (EoS) dates are tracked centrally as part of asset and configuration management
  • unsupported or unpatched equipment is not used in production network paths where it would introduce significant security or resilience risk
  • configurations, backups and update records are maintained to support recovery and assurance activities

Aligns to the following DSPT principles:

Principle How it supports
System security

Supported builds and ongoing patching maintain secure configuration baselines. 

Identifying and replacing EoL and EoS equipment supports effective vulnerability mitigation.

Asset management Lifecycle tracking ensures equipment is managed, supported and secure.

Last edited: 6 August 2026 1:30 pm