A 2017 UK police risk assessment warned that sensitive data moved to Microsoft Azure could be vulnerable to cybercriminals, foreign actors and potential access by US government insiders. The material included criminal records, victim statements, internal emails and other information held by more than 40 police forces.
The assessment also warned that police data and related metadata could be processed or stored worldwide, with the extent unknown. Specialists who reviewed the findings said the risks identified in the document still apply, while police and Microsoft disputed the suggestion that cloud use automatically exposes data to foreign governments.
What the police assessment identified
The assessment followed a 2017 meeting chaired by Ian Dyson, then the City of London police commissioner and the senior information risk owner for British policing. It considered 15 risks linked to transferring police data to Microsoft’s global cloud, including vulnerabilities in Microsoft software that could eventually be exploited by cybercriminals and other threat actors.
The document said a significant volume of the information exceeded the “official” classification. That could place some files in the categories of “official sensitive”, “secret” or “top secret”, according to the classification described in the assessment.
Why data location and access remain disputed
The proposed mitigations included keeping police servers patched, using antivirus software and applying Microsoft’s standard encryption. Specialists said those measures would not prevent Microsoft employees from accessing data or necessarily stop US authorities from seeking files held by a US company.
The National Police Chiefs’ Council said access was restricted to people with a genuine need and subject to strict controls. It also said policing normally required UK-only datacentres, although Microsoft employees could sometimes access data for support. Microsoft said it does not give governments direct or unfettered access to customer data and had not provided UK data in response to a US government request. Related coverage: US Diplomats Walk Out as France Addresses UN Security Council on Ukraine War.
Microsoft also said its cloud services were not inherently insecure or automatically exposed to foreign governments. Its disclosure to Police Scotland in 2023 said data could go outside the UK and that it could not guarantee data sovereignty, while the company said it had strong controls around engineers’ access. Read the context: Amnesty says foreign nationals were deceived into fighting for Russia.
How widely the platform is used
Every UK police force now depends on Microsoft Azure either wholly or in part, although some forces, including Police Scotland, were still completing adoption. The data described includes intelligence, body-worn video, digital evidence, case files and ordinary organisational records.
The wider UK public sector also relies heavily on US cloud providers. The government spends at least £1.9bn a year on Microsoft software, and up to 60% of its IT infrastructure is hosted on cloud platforms, according to the reported figures.
No comments yet. Start the discussion.