Ethical Hacking News
The use of Microsoft Azure by the UK police forces has long-standing security concerns, particularly with regards to the potential for foreign governments to access sensitive data. Despite the risks, every single UK police force has now put its data on Microsoft's cloud, raising concerns about the potential for sensitive data to be accessed by foreign governments, including the United States. Experts have pointed out that the risks identified in the 2017 assessment persist today, and the situation becomes even more complicated under international law. The current state of visibility is stark, and this is an important warning for anyone responsible for sensitive data in a large cloud environment.
UK police forces have been using Microsoft Azure to store and manage sensitive data, despite long-standing security concerns. A 2017 assessment warned of 15 risks tied to moving police data to Microsoft Azure, including foreign access risks. Microsoft has stated that data can leave the UK, but police officials claim it stays in the country and can't be shared without permission. Despite security concerns, all UK police forces have moved their data to Microsoft Azure. The US CLOUD Act allows US authorities to access data stored outside the US, creating a risk of foreign government access. The current state of visibility makes it difficult to detect data breaches, as logging and information in the cloud systems may not reveal issues.
The United Kingdom's police forces have been using Microsoft Azure, a cloud computing platform, to store and manage sensitive data for several years. However, a recent investigation by The Guardian has revealed that these forces have been aware of long-standing security concerns regarding the use of Microsoft Azure, particularly with regards to the potential for foreign governments, including the United States, to access sensitive data.
In 2017, a UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist today, according to five specialists who reviewed the findings. The assessment identified 15 risks tied to moving police data onto Microsoft Azure, including the potential for US government insiders to access the data.
The assessment was conducted by then City of London police commissioner Ian Dyson, who also held the title of senior information risk owner for the entire country. The document reviewed the risks associated with using Microsoft Azure, including the potential for Microsoft software vulnerabilities to be exploited by cybercriminals and other attackers.
Microsoft has since stated that data can leave the UK and that it cannot guarantee data sovereignty. However, police officials have told The Guardian that the data stays in the UK and that Microsoft cannot share it without permission. These statements are incompatible, and it appears that nobody is eager to reconcile them.
Despite the long-standing security concerns, every single UK police force has now put its data, wholly or partly, on Microsoft's cloud, despite all of this being on record since 2017. This has raised concerns about the potential for sensitive data to be accessed by foreign governments, including the United States.
Experts have pointed out that the risks identified in the 2017 assessment persist today. The proposed protections, including the use of Microsoft's built-in encryption and keeping servers updated, are not sufficient to prevent the US government from accessing the data.
The situation becomes even more complicated under international law. The US CLOUD Act allows American authorities to require US-based companies to provide data they control, even when that data is stored outside the United States. In some cases, companies can also be prevented from telling the customer about the request.
Microsoft, Amazon, and Google have said they would challenge such requests when possible. However, international law professor Douwe Korff has pointed out that the risk is obvious, even though the providers of the cloud and the government both have an interest in talking it down.
The current state of visibility is stark, according to a former senior policing source. The source stated that "all the security guys I worked with when this policy came in expected a big breach by now, and we know it will take that to change the police's position." The truth is, however, the level of logging and information in the cloud systems would not necessarily tell us if there was a problem. We really don't know if the data has been breached or not.
For anyone responsible for sensitive data in a large cloud environment, this is an important warning. In a security assessment, saying "we would probably know if something went wrong" is not enough without evidence that the monitoring can actually detect it.
Related Information:
https://www.ethicalhackingnews.com/articles/UK-Police-Data-on-Microsoft-Azure-A-Long-Standing-Security-Concern-ehn.shtml
https://securityaffairs.com/199442/uncategorized/uk-police-data-faces-long-standing-microsoft-cloud-security-concerns.html
Published: Mon Sep 21 04:11:17 2026 by llama3.2 3B Q4_K_M