Cyber Security Awareness Training for Healthcare Staff in Ireland
Why HSE Cyber Security Awareness training is mandatory, what it covers, and what the 2021 HSE ransomware attack changed.
Cyber Security Awareness training is one of five mandatory e-learning modules that HSE staff in Ireland must complete on HSeLanD, the health service's online learning platform. It teaches frontline and support staff how to spot phishing emails, handle passwords and credentials safely, and report suspicious activity before it turns into a full-blown incident. It sits alongside Children First training, Hand Hygiene training, Open Disclosure training and Dignity at Work training as one of the HSE's core mandatory modules — but unlike the others, it exists because of a specific, well-documented crisis: the ransomware attack that brought down the HSE's IT systems in May 2021. Understanding what happened then is the clearest way to understand why this training is compulsory now.
Why cyber security is a patient-safety issue, not just an IT problem
It's tempting to file "cyber security" under IT and move on. In a hospital or community health setting, that's a mistake. Patient records, appointment and diagnostic systems, radiology equipment, lab results and prescribing systems are all now digital and networked. When those systems go down, care doesn't pause neatly — it gets harder, slower and, in places, riskier.
Ireland has direct, painful proof of this. On 14 May 2021, the HSE was hit by a ransomware attack carried out using Conti ransomware, deployed by a Russia-based criminal group. The attackers had first gained access to an HSE workstation roughly two months earlier, in March 2021, through a malicious email opened by a staff member, and spent weeks moving through the network undetected before triggering the encryption attack. The HSE's response was to shut down its national IT systems entirely to contain the damage — a decision that took hospitals and community services back to pen and paper almost overnight.
The disruption was severe and prolonged. Hospitals nationwide lost access to patient records and radiology and diagnostic imaging systems; outpatient appointments and some cancer services were disrupted; and it took months, not days, to restore normal operations, with the HSE reporting the bulk of systems back online by around September 2021. The Irish Times has reported the eventual recovery cost at roughly €102 million, and a 2022 report from the Comptroller and Auditor General estimated further multi-year investment would be needed to bring HSE cyber security up to standard. The HSE commissioned an independent post-incident review, carried out by PwC, which found that attackers had gone undetected in HSE systems for around eight weeks and that the organisation's legacy IT estate was not resilient against this kind of attack.
None of that happened because a single member of staff was careless in some unusual or unforeseeable way. It happened because one email, opened once, was enough to give attackers a foothold — and because that kind of email lands in ordinary staff inboxes every day, across every part of the health service. That's the reason cyber security awareness is now treated as a patient-safety competency, not an optional IT add-on: the people best placed to stop an attack at the first click are frontline and administrative staff, not just IT security teams.
What the Cyber Security Awareness training covers
Based on the HSE's own published guidance for staff, the training and the wider cyber security expectations it supports focus on a small number of practical, everyday behaviours rather than deep technical content:
- Recognising phishing attempts — checking sender authenticity, spotting poor grammar or unusual requests, and being cautious about links and attachments in emails and text messages.
- Password and credential security — using strong passwords (a mix of upper and lower case, numbers and special characters), never sharing logins, and only using accounts assigned to you personally.
- Data protection basics — understanding that staff are personally accountable for activity carried out under their own login on HSE devices and systems.
- Reporting suspicious activity — knowing to contact the HSE's National Service Desk immediately if a suspicious link is clicked, an attachment is opened, or anything looks wrong, rather than staying quiet about it.
- Awareness of other threats, such as suspicious QR codes and restrictions on certain apps (the National Cyber Security Centre has, for example, prohibited TikTok on Irish public sector devices).
The emphasis throughout is on identification and reporting rather than technical troubleshooting — the training is designed for every member of staff, not just IT specialists, so it deliberately stays practical and jargon-free.
Why it's mandatory and who needs it
Cyber Security Awareness training is listed by the HSE as mandatory for all HSE staff, delivered through HSeLanD alongside the other four core mandatory modules. Given how the 2021 attack unfolded — a single opened email leading to a nationwide shutdown — it's treated as relevant to everyone with access to an HSE device or account, not just clinical staff or IT personnel. Administrative staff, healthcare assistants, nurses, doctors, allied health professionals and management are all expected to complete it, because a phishing email doesn't check job titles before it lands in an inbox.
Ireland's National Cyber Security Centre (NCSC) also treats organisations like the HSE as part of the country's critical national infrastructure, providing broader threat advisories and guidance to government bodies and essential service providers. The HSE's own mandatory training sits within that wider national push to raise baseline cyber security awareness across essential services.
How it's delivered and how long it takes
The training is delivered entirely online through HSeLanD, the HSE's e-learning platform, where staff can find it listed on their individual Mandatory Training page. According to HSeLanD's own support documentation, the Cyber Security Awareness module must be completed every 12 months to remain compliant — a previous completion of an older version of the course does not count towards current requirements, and staff need to complete the current version in full for their training record to show as compliant. Neither HSeLanD nor the HSE publish a specific estimated completion time for the module on their public-facing pages, so if you need an exact figure, check the module listing on your own HSeLanD account, which will show its expected duration before you start.
Frequently asked questions
Is Cyber Security Awareness training only for IT staff?
No. It's mandatory for all HSE staff, regardless of role. The 2021 ransomware attack began with a single email opened on an ordinary staff workstation, which is exactly why the HSE treats this as a whole-of-organisation responsibility rather than something only IT security teams need to worry about.
How often do I need to redo the training?
HSeLanD's support documentation states the module must be completed every 12 months to stay compliant. If you completed an earlier version of the course, check your HSeLanD training record, as older completions may not count towards the current requirement.
What happens if I click a suspicious link or open a suspicious attachment?
HSE guidance is clear: report it immediately to the National Service Desk rather than waiting to see what happens. Early reporting is what allows IT security teams to contain a potential problem before it spreads — exactly the kind of early warning that was missing in the lead-up to the 2021 attack.
Where do I complete the module?
Through HSeLanD (hseland.ie), on the Mandatory Training section of your personal training page. It's free and, per HSE policy, mandatory training generally counts as working time and takes place during working hours where possible.
Does completing this module mean an organisation is fully protected from cyber attacks?
No single training module can guarantee that. It's one layer of a much broader approach to cyber security — alongside technical safeguards, incident response planning and IT investment — that reduces the chances of a successful attack and helps it be caught earlier if one gets through.
Cyber Security Awareness training won't turn every HSE staff member into a security expert, and it isn't meant to. What it does is make sure that everyone with access to HSE systems can recognise the everyday warning signs — a suspicious email, an unexpected request for login details — and knows exactly what to do next. Given what happened in May 2021, that basic, practical awareness is now treated as core to keeping patients and their data safe, not a box-ticking exercise.
This guide is part of Learnsignal's ongoing coverage of professional qualifications and training routes.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


