Lightfoot help NHS teams turn routine data into real-time insight, safely and responsibly. Our signalsfromnoise® platform and Health Insights service are already supporting over 100 NHS organisations to improve patient flow, reduce waits and forecast future demand – all underpinned by resilient data protection and robust assurance.
Lightfoot’s tools hold over a billion pseudonymised records, used by clinicians, analysts, executives and transformation teams across 87 acute trusts and 28 ICBs. In this environment, security isn’t a bolt-on — it’s the foundation.
Security You Can Trust, Proven Where It Matters
When your tools deliver SPC analysis, live pathway modelling and predictive analytics across whole systems, the need for watertight assurance is clear. That’s why we’ve built our security around recognised, independently validated standards, trusted across the NHS and UK government.
We’re proud to hold all three of the following core certifications:
✅ Cyber Essentials Plus
Cyber Essentials Plus provides assurance that our defences are effective against commodity cyber threats from phishing and malware to unauthorised access. It’s not just a tick-box form – it involves external penetration testing and hands-on validation of our controls by IASME certified auditors
Our certification covers the entire Lightfoot Solutions Group, including our UK, New Zealand and Australia operations. That means all clients regardless of where we support them benefit from consistent, verified cyber defence across our full estate.
✅ ISO/IEC 27001:2022
Certified to the latest international standard for information security
Lightfoot’s ISO 27001 certification applies to our software development, consultancy and hosting services. It verifies that we operate an organisation-wide information security management system (ISMS), including risk management, access control, incident handling and supplier governance.
Our certificate uses the 2022 version – reflecting the most up-to-date global standards and covers the systems and teams behind both signalsfromnoise® and our private cloud environments used in NHS deployments.
✅ NHS Data Security and Protection Toolkit – Standards Exceeded
DSP Toolkit Version 7
The DSP Toolkit is the NHS’s own measure of whether a supplier can be trusted to process NHS data. Lightfoot’s latest submission – reviewed for 2024–25 – was rated “Standards Exceeded”, meaning we not only meet but go beyond the core 10 national data security standards.
Our DSPT covers everything from secure hosting and data minimisation to training, incident response, and encryption — fully aligned with UK GDPR and NHS national policy.
Insight with Integrity: What We Offer
At the heart of our services is the belief that NHS data should be used for patient benefit, not just stored. But it must be used safely. That’s why every part of our offer balances powerful analytics with data stewardship:
🔹 signalsfromnoise® (sfn) – A live analytics platform delivering whole-pathway views, Statistical Process Control (SPC) monitoring and hypothesis testing on real operational data. Unlike traditional BI tools, sfn works directly on raw data, with no lag, no pre-aggregation, and no black box.
🔹 Health Insights – A regional platform commissioned by NHS England South East, built by Lightfoot, offering secure access to data-driven planning tools. Users can explore pathway dependencies, simulate discharge levels, profile diagnostic bottlenecks, and calculate elective recovery capacity in real time.
🔹 Secure Private-Cloud Hosting – Our data warehouses are hosted in dedicated environments designed for NHS pseudonymised and de-identified data — resilient, UK-based, and access-controlled at every level.
🔹 Elective, Diagnostics and Flow Modelling – Our forecasting models help local systems plan the workforce, resources and flow strategies needed to meet national targets, from 65-week waits to winter pressures.
🔹 Consultancy and Left-Shift Redesign – Beyond the platform, our team of statisticians, analysts and NHS experts work side-by-side with systems to redesign services, move care upstream and eliminate waste.
🔹 Training and Communities of Practice – We help NHS staff build internal capability through modular e-learning, coaching and hands-on workshops.
Data Governance Is Not a Paper Exercise
Every feature we release – from a new bed viewer to a waitlist scenario planner – is designed with data protection by design and by default. We apply role-based access, data minimisation, audit trails, encryption at rest and in transit, and align with both UK GDPR and NHS national policy.
We are also transparent with our partners. Controllers can audit, review and evidence how their data is used at any time. Lightfoot support Data Protection Impact Assessments (DPIAs), data sharing agreements and IG documentation from day one.
Security Builds Confidence. Confidence Enables Action.
The NHS is under pressure to deliver more, faster, and with fewer resources. Insight alone isn’t enough. It has to be trusted, scalable and secure.
That’s why Lightfoot continues to invest in both the analytics that drive transformation, and the infrastructure that keeps data protected.
We don’t believe in compromise. We believe in solutions that are insightful, compliant and robust – because the NHS deserves nothing less.
If you’re working to improve flow, capacity, or waiting times, and want a platform – and partner – that treats your data with the same care you do, get in touch.
Contact: info@lightfootsolutions.com
Andy Garside CEng CITP MBCS – Director of IT and Information Security – Lightfoot Solutions