UK Police Data Vulnerable to Compromise on Microsoft Azure
The UK police's sensitive data is vulnerable to 'compromise' by foreign actors and the US government, according to a report from Microsoft. The data, which includes criminal records, victim statements, internal emails, and sensitive information held by over 40 police forces across the UK, is stored on Microsoft Azure.
In 2017, the UK police decided to put their most sensitive data on the Microsoft platform despite knowing that 'US government insiders' could see it. The risks were identified in a document signed off by Ian Dyson, a senior police officer and senior information risk owner for all of Britain.
The assessment concluded that the data would be vulnerable to hackers and that it was 'unknown' where the data would be processed or stored. It also identified the potential risk from 'US government insiders', saying there was a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers.
The National Police Chief's Council (NPCC) claims that access to data stored on the cloud is limited to those with a genuine need to access it and is subject to strict controls. However, experts say these mitigations are inadequate and that the information 'could be viewed by hundreds of people around the world, some of them not vetted, many of them not directly employed by Microsoft.'