UK Police Data on Microsoft Azure Faces Ongoing Foreign‑Access Risks
What Happened – A 2017 risk assessment signed by the City of London Police commissioner warned that moving police records, victim statements and classified material to Microsoft Azure could expose the data to “US government insiders” and to worldwide transmission. A 2026 Guardian investigation confirms the same 15 risks are still considered relevant, even though almost every UK police force now relies on Azure and the UK government spends >£1.9 bn annually on Microsoft software.
Why It Matters for Trust & Control Assurance
- Continuous third‑party risk monitoring is required to prove that cloud‑provider access controls remain aligned with the organization’s data‑protection obligations.
- Evidence of data‑location, encryption‑in‑use and provider‑access logs is essential for a defensible audit trail under a control‑assurance program.
- The scenario directly tests the control objective of vendor/third‑party oversight – a single control that maps to many frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2).
Who Is Affected – UK law‑enforcement agencies, other public‑sector bodies that store sensitive citizen data in Microsoft Azure, and any organization that relies on the same multi‑jurisdictional cloud infrastructure.
Recommended Actions
- Conduct a formal third‑party risk assessment of Azure, focusing on data‑residency, encryption‑in‑use, and Microsoft employee access policies.
- Require continuous monitoring of Azure access logs and obtain independent attestations of provider controls.
- Update data‑classification policies to mandate end‑to‑end encryption for “secret” or higher data before it leaves the organization’s perimeter.
- Document all oversight activities in a Trust Center‑style repository to support audit readiness.
Source: Security Affairs
Technical Notes – The risk stems from Microsoft’s globally distributed data‑center architecture (files can be fragmented across >100 countries) and the fact that Microsoft‑employee or government‑insider access is not blocked by at‑rest encryption alone. No specific CVE or exploit is cited; the concern is systemic to the cloud service model.
Source: same as above