Integrating Nurses into Cybersecurity Governance: Assessing Preparedness in European Healthcare Systems
Paul De Raeve · Iris Journal of Nursing & Care · 2025
Introduction: The digitalization of healthcare systems across the European Union brings significant benefits in care delivery but also increases the vulnerability of healthcare institutions to cyberattacks.Although national cybersecurity strategies exist, the role of nurses, key actors in care continuity, is often overlooked in these plans and related training programs.Aim: This study investigates the extent of nurses' involvement in national and regional cybersecurity plans within the EU, as well as the availability of cybersecurity education and training specifically for nurses.Methods: Data from a 2025 survey conducted by the European Federation of Nurses Associations (EFN), covering 20 countries, were analysed alongside a comparative bibliographic review of 31 National Cybersecurity Strategies (NCS) from EU and associated countries.The study combined quantitative survey analysis with thematic document review.Results: Most countries have adopted national cybersecurity plans, but implementation at regional and local levels remains inconsistent.Only 25% of countries involve nurses in cybersecurity planning, and just 20% provide structured training.Nursing staff are rarely mentioned in national strategies, and clear continuity plans ("Plan B") for healthcare delivery during cyber incidents are largely absent.Conclusion: Integrating nurses into cybersecurity governance is critical for strengthening healthcare resilience and patient safety.The study recommends formal inclusion of nurses in cybersecurity planning, development of targeted educational programs, and EU-funded initiatives to enhance preparedness for cyber crises.Such measures would improve coordination between digital security and clinical practice.