Sunday, 20 September 2026NewsWorldBusinessTech
Latest

UK Police Data on Microsoft Azure Vulnerable to Foreign Access Risks

More than 40 police forces across the United Kingdom store sensitive criminal records, victim statements, and intelligence on Microsoft Azure cloud services. A 2017 security assessment warned that the data could be vulnerable to foreign actors and U.S. government insiders, raising ongoing concerns over data sovereignty.

Sensitive information belonging to more than 40 police forces throughout the United Kingdom is currently stored on Microsoft Azure cloud services, according to a security assessment examined by the media. The material housed on the platform includes criminal records, case files, victim statements, internal police communications, and digital evidence such as body-worn video.

A police document reviewed by the Guardian revealed that some of this information surpasses the standard UK classification of “official,” falling potentially under categories designated as secret or highly secret. This reliance stems from an administrative decision made in 2017.

The 2017 Assessment and Foreign Access Risks

The foundation for the current arrangement was laid during a 2017 meeting where senior police officials examined the risks of migrating law enforcement data to Microsoft cloud services. Minutes from that meeting acknowledged that U.S. government insiders might gain access to the data, and that information could be processed or stored globally without clear geographic boundaries.

At the time, officials proposed several safeguards, including regular software updates, security tooling, and built-in Microsoft encryption. However, security experts reviewing the documents later argued that these technical measures fail to eliminate foreign access risks entirely. Because Microsoft operates an extensive international network, technical support and data processing often involve personnel operating outside the UK.

Cloud Scale Versus National Data Sovereignty

The core tension in the UK policing setup involves the physical location of data storage versus the jurisdictional reach of foreign legislation. While Microsoft maintains that customer information is not automatically exposed to foreign governments and notes that its Azure data centres have been assessed against Police-Assured Secure Facilities requirements, legal experts warn that contractual promises face complications under foreign laws.

This dynamic fuels a broader debate surrounding data sovereignty, particularly as the UK government spends substantial sums annually on Microsoft software products. Five experts who reviewed the findings of the journalistic investigation confirmed that the risks identified in 2017 remain present today.

Official Responses and Security Industry Counterweights

In response to these concerns, the National Police Chiefs’ Council (NPCC) stated that access to police information stored in the cloud is restricted to people who have a genuine need to see it and is subject to security controls. Microsoft also says its Azure services can meet specific UK police security requirements.

Yet, independent specialists argue that systemic vulnerabilities remain difficult to monitor. Mark Butcher, a cloud computing expert and strategic consultant for government sectors, pointed out that security agencies and government bodies understand these risks well, but senior officials have continued to rely on assurances from Microsoft that such breaches will not occur. Another informed source noted that security specialists who supported the adoption of this policy expected a major breach later, pointing out the current difficulty in verifying whether data has actually been compromised due to the limited capability of cloud systems to detect such incidents.

Broader Industry Shifts Toward Confidential Computing

As organizations wrestle with data control in shared environments, the technology sector is pushing hardware-level protections to address these exact exposure vectors. On August 25, 2026, Palo Alto, California-based Anjuna Security—a leader in confidential computing and autonomous software runtime governance—announced the availability of the Anjuna Seaglass platform running on AMD Secure Virtualization (SEV), providing a confidential computing solution on AMD EPYC datacenter CPUs.

خرق أمني يحرج بريطانيا.. العثور على وثائق عسكرية سرية ملقاة في مكب نفايات

Enterprises and organizations in regulated industries that operate with sensitive data and applications can now help protect them with confidential computing running on bare metal without code changes or a new operational model to learn. As Ayal Yogev, CEO of Anjuna Security, stated: Ayal Yogev, CEO of Anjuna Security, stated that enterprises are reporting a need for confidential computing to operate identically on-premises and in the cloud, utilizing the same platform, policies, and operational experience while eliminating deployment overhead. Yogev added: Ayal Yogev added that with Anjuna Seaglass on AMD SEV, they have delivered the precise solution to address that challenge, offering one-click confidential computing for on-premises environments to help secure sensitive workloads such as autonomous software, mission-critical cryptographic services, privacy-sensitive financial processes, and blockchain transaction systems.

UK Police Data on Microsoft Azure Vulnerable to Foreign Access Risks
Photo: finance.yahoo.com

Madhu Rangarajan, corporate vice president, Compute and Enterprise AI Products, AMD, stated: Madhu Rangarajan stated that enterprises require a consistent approach to safeguarding sensitive data during processing, regardless of where their workloads execute. Rangarajan added: Madhu Rangarajan added that AMD SEV, integrated into EPYC CPUs, establishes a hardware-enforced foundation for confidential computing incorporating memory encryption, integrity protection, and attestation, while Anjuna Seaglass builds upon that foundation to streamline the deployment of confidential computing for containerized workloads. For public safety agencies and regulated enterprises alike, balancing the economic convenience of global cloud providers against the rigid demands of local security compliance remains an escalating operational hurdle.

خرق أمني يحرج بريطانيا.. العثور على وثائق عسكرية سرية ملقاة في مكب نفايات