Software supplier Advanced confirmed on 4 August that a ransomware attack had disrupted systems behind NHS 111, forcing call handlers back onto pen and paper for emergency referrals, ambulance dispatch support and out-of-hours bookings. Advanced says the incident was contained to a small slice of its infrastructure — but that slice happens to power 111 services for the vast majority of NHS trusts in England. Recovery is expected to run into weeks for some services, with specialist cybersecurity firms, Microsoft and the National Cyber Security Centre all called in to help contain and clean up the breach.
If that sounds familiar, it’s because it is: Advanced was hit by LockBit ransomware once before, and the fallout from that earlier incident is still working its way through regulatory fines years later. What makes this newsworthy again isn’t just that it happened twice — it’s the reminder that a single supplier failure can take down services for organisations who never chose that supplier directly and have no way to fix the problem themselves.
Why this matters even if you’ve never heard of Advanced
Most UK SMEs don’t run their own servers any more — payroll, bookings, CRM, accounting and comms all sit with third-party software vendors, and increasingly those vendors sit on top of other vendors again. That’s efficient right up until one link in the chain gets ransomed, at which point everyone downstream is offline regardless of how good their own security is. The NHS 111 outage is a large, visible version of a risk every business carries in miniature: if your booking system, your finance software or your helpdesk provider goes down, so do you, and there’s very little you can do about it in the moment except wait and have a fallback plan.
What to actually check this week
Start with a simple inventory: which of your critical business functions depend on a single external software vendor with no manual fallback? For NHS 111 staff, the fallback was literally paper and phone lines — unglamorous, but it kept the most urgent cases moving while systems were down. Your equivalent might be a printed customer contact list, an offline invoice template, or simply knowing who to call at each supplier and what their promised response time is. None of this prevents the outage; it just stops it becoming a full stop for your business.
It’s also worth asking your key suppliers a direct question you might not have asked before: have they had a security incident in the past three years, and what changed afterwards? A vendor that’s been through a breach and visibly hardened its defences can be a safer bet than one that’s never been tested at all. If you’re not sure how to frame that conversation or assess the answer, KeepSafe monitors for exactly this kind of exposure across the suppliers and systems your business depends on, so a partner’s bad week doesn’t blindside you without warning.
Don’t forget the contract, not just the technology
Alongside the fallback plan, it’s worth checking what your supplier contracts actually promise when something goes wrong — most SMEs have never read the service-level agreement attached to the tools they rely on daily, and many say nothing at all about ransomware, breach notification timelines, or compensation for downtime. That’s not a reason to panic; it’s a reason to know where you stand before you need to. A short review of your two or three most business-critical software contracts, ideally with someone who can translate the legal language into plain terms, tells you whether you’d have any recourse at all if your provider went dark for a week the way Advanced’s customers did. Smallprint has ready-made templates and reviews that make this the kind of check you can actually finish in an afternoon, rather than a project that never quite gets prioritised.
The takeaway
You can’t stop your suppliers getting hit by ransomware. You can make sure it isn’t a surprise when they do — know which of your critical functions have no fallback, and fix that gap before an outage forces the question.