We received responses from executives (23%), administrative staff (22%), IT staff (18%), clinicians (12%) and the remainder a mix of researchers, consultants, vendor specialists and board members.
Respondents felt a strong sense of organisational responsibility for the security of information assets and information systems with the following measures in place: formal plans (73%), staffing (75%) and dedicated security budget (42%).
Compared to 2017, there has been a notable improvement in security awareness training (59%, from 36%) documented procedures (68%, from 45%) and evaluation of systems at procurement (51%, from 36%)