Cybersecurity has become a critical concern for radiation oncology departments, in which digital systems are essential to the planning and delivery of treatment. Recent attacks on healthcare institutions have shown how quickly clinical activities can be disrupted, with direct consequences for patient safety. Yet, despite this growing vulnerability, many radiotherapy teams lack structured guidance that is tailored to the complexity of their workflows.
To help to address this gap, an international group of experts convened by ESTRO’s radiation oncology safety and quality committee has developed a dedicated cybersecurity framework for radiation oncology. The group brought together radiation oncologists, medical physicists, radiation therapists (RTTs), IT specialists and IT security experts, including professionals with expertise both within and beyond the radiation oncology field, Rooted in recognised standards and informed by a broad literature review, the framework offers a clear six-step structure for strengthening preparedness and resilience in the event of a cyber incident.
In the interview that follows, we speak with Samuel Peters, a co-author of the framework, to explore the motivations behind this initiative, the main principles of the six-step system, and how departments can begin to apply it in practice.
Interview with Samuel Peters, co-author of the framework.

Samuel Peters, Head of Radiation Oncology Informatics, HOCH Health Ostschweiz, Kantonsspital St. Gallen, Switzerland
What motivated your group to develop a cybersecurity framework specifically for radiation oncology?
We are seeing an increase in ransomware attacks in which criminals encrypt company’s data and demand millions of dollars to unlock the encryption. These attacks can shut down operations for weeks. Recent incidents in radiation oncology (RO) departments have proved that most clinics are completely unprepared for such events. Given that RO is highly dependent on digital data to treat patients while keeping them safe, we felt there was an urgent need to provide specific survival guidelines.
Can you explain the six-step model in simple terms?
The framework follows the timeline of a cyberattack and is divided into three phases:
First, the pre-incident phase: this comprises Step 1, “Preparation”, and Step 2, “Prevention”. This is the phase we are normally in. Step 1 focuses on creating a "business continuity plan", (BCP), which is an emergency playbook that outlines measures and processes to be followed during a cyber incident. Step 2 requires the imposition of preventive measures such as system updates, network restrictions and regular user awareness training.
Second, the incident phase: this consists of Step 3, “Detection”, Step 4, “Response”, and Step 5, “Recovery”. In Step 3, the aim is to identify the attack and stop its spread. Step 4 is the core of our framework: implementation of the playbook to ensure that we can continue to treat patients safely during the crisis. Step 5 focuses on the transition back to normal operations and the restoration of data.
Finally, the post-incident phase: Step 6, “Debriefing and continuous improvement”. Here, the affected department analyses what worked and what didn't so that it is better prepared for future incidents.
These six steps consist of 190 action measures. Which ones should departments prioritise first?
These 190 measures may sound overwhelming, but many clinics already have implemented some of them without being aware of it. The best starting point is Step 1 (preparation). The first move should be to define an "incident response team", which comprises the specific people who will be in charge when things go wrong. Next, departments should focus on “identification of systems, tools, processes and stakeholders and their weaknesses”, and ultimately define the BCP. Completion of these steps involves taking seven and 14 individual measures, respectively. Deciding which ones to tackle first depends heavily on the local situation. Nevertheless, all 190 measures should ultimately be considered to ensure comprehensive preparedness.
What does a robust BCP look like in practice?
As with many things, this depends on local circumstances. However, a robust plan is not just a document sitting on a shelf; it’s a living strategy that employees actually know and understand. It clearly defines roles and covers various emergency or incident scenarios. Most importantly, it must be tested regularly (ideally once a year) to ensure that the theory actually works in a high-stress, real-world situation.
How can small centres apply these recommendations with limited resources?
Small centres are unlikely to have their own IT security experts, so they should hire external providers who mainly cover the measures required under Steps 2 and 3. However, even small centres must develop their own BCPs, and each must be able to use it in an emergency. To save costs and time, don't reinvent the wheel: collaborate with other clinics of similar size to share templates, processes, and "best practices".
What is the minimum collaboration needed among IT staff, clinicians, and vendors of clinic software in order to be prepared?
There is often a "language gap". IT teams may not fully understand clinical workflows, while clinicians may not be familiar with IT security protocols and related processes. It is therefore essential to hold regular meetings between IT staff and clinical representatives to align expectations. For example, agree on "maximum tolerable downtime" – that is, how long can the clinic realistically remain offline before patient safety is compromised?
The situation is slightly different for clinic software providers. They are naturally familiar with hospital procedures, but may underestimate how complex system recovery can be, especially in large hospitals. Clinics should therefore have written agreements that specify exactly how much on-site technical support the software supplier will provide during a crisis and how quickly they will arrive.
What cyber threats should radiotherapy departments expect in the coming years?
Phishing remains the biggest threat. Phishing is a scam that involves the receipt of deceptive emails that are designed to steal passwords. With the rise of artificial intelligence (AI), these emails are becoming increasingly personalised and harder to spot. AI also helps hackers to create "stealth" malware that bypasses traditional security systems. Unfortunately, this means that the risk of falling victim to a cyberattack is likely to increase significantly in the coming years.
What is the one thing you want every department to start doing tomorrow?
Not tomorrow, but today! Ask yourself one question: "If our systems go down right now, who is being treated tomorrow and what is their radiation plan?" If you can’t answer that without access to your computer or hospital information system, you are at risk. Start creating offline copies of your most critical patient data immediately!
> Read the paper in the Green Journal: https://doi.org/10.1016/j.radonc.2025.111305