As others have noted, Micro$oft stopped supporting Windows XP three years ago, and gave the NHS plenty of warning. The NHS bought one year's further support of patches to update and protect from hacking, then left it up to NHS local organisations to upgrade, without giving them the funding to do this. If you have to meet A and E targets or get fined, you are not going to spend the money on IT.
The NHS has not bought sufficient bandwidth to run all systems at speed, so updates are switched off from automatically working so that an overload does not occur.
This attack has revealed how vulnerable every business is unless it keeps its servers up to date and patched. The fact that this particular bit of ransomware was built by the CIA to hack into computers and leave them open to further hacking, and then leaked and sold, show the sort of world we now have to cope with.