The Register Home Page

back to article Microsoft wares may be UK public sector's only viable option

Not for the first time, Microsoft is in the spotlight for the UK government's money it voraciously consumes – apparently £1.9 billion a year in software licensing, and roughly £9 billion over five years. Microsoft in the public sector This debate series is prompted by our reporting on the recent UK government commitments to …

  1. Doctor Syntax Silver badge

    "Open source also comes with a range of less measurable costs – training, over-engineering, reliability, security maintenance, data interchange and interface complexity."

    As opposed to assuming staff will just "know" Office etc* and be able to stumble along with Microsoft's next changes, under-engineering, MS <365, patch Tuesdays, proprietary "standards" and complexity**.

    I think you make a convincing case for preferring FOSS to Microsoft.

    If this Microsoft is the only viable option for public sector it is an excoriating condemnation of the public sector.

    * Training costs saved here will become evident in CCed confidential data, Excel misused as a database with row limits overlooked and numerous other public sector ballsups traced back to lack of training.

    ** See stumbling along with Microsoft's next changes.

    1. graemep Bronze badge
      Flame

      Even the "people already know MS Office" only applies to training costs.

      Any software has reliability and security maintenance costs. The difference with open source is that you are not linked to any one vendor. Proprietary software is more likely to be over engineered. You can reduce data interchange costs by sticking to one vendor, but that gives them an awful lot of leverage over you. I do not even understand what the issue is with interface complexity - except insofar as software that does complex things tends to have complex interfaces.

  2. elsergiovolador Silver badge

    Wine and dine

    So the takeaway here is: “Yes, we’re spending £9 billion with Microsoft, but open source is scary and only technologists like it - so let’s just keep feeding the beast.” The whole piece reads like a press release for Redmond, with the usual “hidden costs” bogeyman rolled out to justify locking the public sector into one supplier until the end of time.

    What it completely dodges is the real reason we’re in this position: UK government procurement has been systematically engineered to favour multinational, tax-shy mega-corps over domestic suppliers for decades. We’ve hollowed out our own IT sector by design - killing off in-house skills, burying SMEs under procurement bureaucracy, and making sure the only companies who can survive the tender process are the same global giants who can afford to wine and dine ministers.

    And while we’re handing over billions, we’re also handing over sovereignty. Thanks to the US CLOUD Act, any public data sitting on Microsoft’s infrastructure is legally accessible to US authorities the moment they ask for it - no matter what “assurances” are on the contract. So not only are we exporting the money, we’re exporting the data too, and pretending it’s “value for money.”

    Standardisation could mean interoperable, open systems that empower UK-based development - but in practice it means monoculture contracts that funnel billions offshore, place public data under foreign jurisdiction, and lock us into a dependency we’ll never escape. It’s not risk management, it’s market capture - and it’s been policy, not accident.

    1. Anonymous Coward
      Anonymous Coward

      Re: Wine and dine

      ... systematically engineered to favour multinational, tax-shy mega-corps over domestic suppliers for decades.

      And you know exactly who to thank for that debacle.

      Because, you know, private sector always does it better.

      .

      1. elsergiovolador Silver badge

        Re: Wine and dine

        The private sector isn’t a free market in this context - it’s rigged. In public procurement you can’t simply judge suppliers on past performance. Even if a company had a track record of serious misconduct, you can’t reject them outright without jumping through narrow legal hoops, because “past poor performance” is hard to prove under procurement rules. Imagine a CV stating someone was fired for skimming from the till, and you still have to consider them for the job.

        Layer on top of that regulations like IR35, which actively block smaller, agile competitors from even entering the market, and you end up with a procurement ecosystem where the same large players keep winning by default. The public sector is a dense web of conflicts of interest - and the bodies supposedly set up to police those conflicts have never meaningfully cleaned house.

  3. VoiceOfTruth Silver badge

    I read this as propaganda

    So many holes in this 'argument', but it's what I expect from those in charge in the public sector.

    >> It is not that open source is not viable, but rather that the true costs often only come to light over time.

    What a howler. I know it's Oracle, not MS, but... Birmingham City Council. Expected costs: £19 million. Not it looks like £130 million++.

    The essence of the problem is that people like Jos Creese think they have achieved 'good value'.

    1. LBJsPNS Silver badge

      Re: I read this as propaganda

      Do ya really think they're going to admit "Oh shit, I fucked up big time" in public and risk their cushy jobs?

    2. Doctor Syntax Silver badge

      Re: I read this as propaganda

      Stockholm syndrome at its finest.

    3. doublelayer Silver badge

      Re: I read this as propaganda

      The problem being that deployment costs with something open source can follow the same pattern that the Oracle thing did. The reason for that cost wasn't Oracle coming to Birmingham and telling them they had to pay ten times as much. It was systems not functioning properly, processes being delayed for months or years, having to build the custom parts over and over again. Probably Oracle's business or software can be blamed for some of that, but not all of it. A bad plan can absolutely obtain the same level of breaking things around an open source database, and while that would be less expensive because you're not paying for licensing the database, it doesn't help with the rest.

      In some ways, this is an argument against the one from the article, because having a commercial software provider doesn't prevent that kind of implementation cost. You can still have a disaster when changing something, even when Microsoft or Oracle is involved, because neither of them is making sure processes aren't interrupted. However, given the frequent responses implying, or sometimes outright stating, that open source would fix this kind of thing which it has nothing to do with, it's a point which seems to go against both attitudes to what kind of software should be used.

      1. VoiceOfTruth Silver badge

        Re: I read this as propaganda

        >> The problem being that deployment costs with something open source can follow the same pattern that the Oracle thing did. ...

        I agree. But, Jos Creese makes out the costs with proprietary software are known up front and those with open source are not. He can't have it both ways.

        1. Scotech

          Re: I read this as propaganda

          To be fair to Jos, the opinion does draw a distinction in the final section between proprietary software that is available and usable off the shelf, versus bespoke or FOSS solutions. With Microsoft 365, for instance, the delivered products and feature sets are fairly well-known and easy to compare against business requirements, and a price can be relatively easily quoted and weighed against those criteria to assess cost-efficiency. When it comes to FOSS or bespoke, the landscape is different. Do you use an implementation partner or a supporting vendor, which can introduce just as great a risk of lock-in but with less predictability around transition pathways to alternative technologies? Or do you go in-house, using homebrew code or borrowing code from FOSS community projects, which means accepting potentially significant additional risks and overheads?

          Like it or not, most Microsoft products set the standards by which their competitors are assessed, simply by virtue of their ubiquity. The same goes for a select group of other big tech vendors. Technical professionals have to answer to actual users of the solutions they provide, and they must accept the reality of the situation is that most of those users will be reaching for OTS equivalents from Microsoft et. al. as their yardstick by which to assess any proposed solution. Trying to sell these people on a solution that can't achieve full feature-parity for their potential use-cases will always be an uphill battle, even more so when you tell them that in addition to that, the organisation will be spending more upfront and shouldering a bigger portion of the risks and ongoing maintenance activities than would be the case with a third-party cloud vendor. The biggest advantages OTS solutions bring here are that they're very easy to fit to user expectations, they tend to be quicker and easier to implement and deploy, and they tend to act as BAU force multipliers when compared to bespoke equivalents, requiring fewer internal staff to administer large estates than would often be be possible with a cobbled together solution of FOSS and bespoke equivalents.

          I should point out at this stage that I actually disagree with the position taken in this article - I'm a big believer that the public sector should have it's own flagship software engineering unit building bespoke solutions that are designed specifically to be rolled-out at scale across all areas of the public sector, alongside the more niche projects that are inevitably required by any large organisation with unique business requirements. I explicitly believe that such a team should by necessity be permanent and have zero downtime between projects. I see this as being no different than the need for in-house expertise in other areas of infrastructure engineering - e.g. countries with great train networks and associated services tend to have dedicated public-sector engineering teams who are kept in constant work on building or improving some area of the network in order to ensure that the necessary staff and skills are kept sharp and current. The same goes for public sector IT, in my opinion.

          That said, here in the UK we've been running in the opposite direction to that logic for the last few generations now, and our public sector is thoroughly infested with private sector providers and consultants throughout every level of national infrastructure provision. These posts tend to be ephemeral in principle, but in practice, there's a revolving door of consultants from the same old firms coming and going, ultimately costing more than retaining them in-house would. Rectifying the situation would require reallocating those resources to building up the public sector's internal capacity to independently deliver once again, and that wouldn't be a quick or simple process. It's a chicken-egg conundrum - building up internal capacity would take time and requires resources that are already allocated to the external consultants and vendors who need to get paid to keep the lights on. And committing to an internalised delivery model would also send a surefire signal to those external suppliers that government is potentially susceptible to significant price gouging as the gravy train approaches its final stop.

          1. VoiceOfTruth Silver badge

            Re: I read this as propaganda

            Thank you for your copious reply.

            >> With Microsoft 365, for instance, the delivered products and feature sets are fairly well-known

            I agree 100%. The FOSS world has problems which are seemingly insurmountable in some areas - endless arguments about which desktop environment is 'right' or 'better', which Linux distro is 'better'. Meanwhile MS makes Windows and people use it eventually.

            >> the public sector should have it's own flagship software engineering unit

            I like that. I don't believe that Cornwall's software requirements are so different to Norfolk's. So making a standard offering should not be too hard.

            >> our public sector is thoroughly infested with private sector providers and consultants

            John Effing Harvey-Jones: Don't build it, buy it in. As the knowledge went out the door.

            1. wpeckham

              Re: I read this as propaganda

              >> With Microsoft 365, for instance, the delivered products and feature sets are fairly well-known

              I agree 100%. The FOSS world has problems which are seemingly insurmountable in some areas - endless arguments about which desktop environment is 'right' or 'better', which Linux distro is 'better'. Meanwhile MS makes Windows and people use it eventually.

              [[[ Except that I have been using MS-OFFICE since it was NEW, and often a new version, release, or even patch breaks compatibility with all earlier versions. The feature set is "well known" only as long as MS never messes with it, which they ALWAYS DO! ]]]

              >> the public sector should have it's own flagship software engineering unit

              I like that. I don't believe that Cornwall's software requirements are so different to Norfolk's. So making a standard offering should not be too hard.

              [[[ Absolutely. While a private user can depend upon the developers and maintainers of FOSS, companies, industries, and systems (Education, healthcare, etc.) need to set their own platform and application independent requirements and have a trusted central authority do the final engineering, deployment, and support for that solution. That might be a division of a corporation, a government body, of a contracted team. What it should NEVER be is a company, body, or organization that has a financial incentive to increase risk or shave the standards! And such a body cannot maintain the product if they have no access to, or control of, the source. FOSS lends itself to that. No proprietary solution does! ]]]

              >> our public sector is thoroughly infested with private sector providers and consultants

              John Effing Harvey-Jones: Don't build it, buy it in. As the knowledge went out the door.

              [[[ This reminds me of the discussion of "industry standard. Business guys like to talk about the advantage of using "industry standard" without really understanding the words. When innovators hear them they translate it to "Let us give up our competitive advantage and do it just like everyone else until the bankruptcy courts bar the doors!" Education institutions of higher learning have the best IT people in the world. Why do we never leverage them for designing solutions we can trust? Oh, wait: that is where we got FOSS! ]]]

          2. Roland6 Silver badge

            Re: I read this as propaganda

            >"With Microsoft 365, for instance, the delivered products and feature sets are fairly well-known and easy to compare against business requirements"

            Now maybe, but those years back when Microsoft was courting the UK public sector and getting its disciples from various "independent" system integrators (Microsoft Practices) advising the Cabinet Office, Microsoft's cloud and 365 offering was still largely vapourware.

            So the only reason why Jos can answer his question "Are the alternatives truly viable and comparable?" with a no, is because for the last decade the UK public sector has been throwing money at Microsoft. Why were they doing this? because they had been throwing money at Microsoft since the early 1990s after Thatcher pulled the teeth from the CCTA and then directed Local Authorities to purchase COTS products for their bespoke/sector specific needs - previously satisfied by vendors who had and cultivated in-house experience of building and maintaining such systems - hence why we now see failures such as at Birmingham with Oracle.

            So to answer Jos's question "Are the alternatives truly viable and comparable?" The answer is actually yes; instead of investing in blind faith, knowing that MS will ignore your actual needs, you invest with your eyes open with UK businesses most probably operating in your local and/or neighbouring economy. It will take time to rebuild skills that existed prior to 1990, but within a decade such alternative solutions will most probably have a better fit with the UK public sector and thus be better than Microsoft's offering. Will it be cheaper? probably not, but most of the money will have been spent in the UK and potentially local economy, so the district will be better off.

            Trump might be mad, but there is an element of hard economic logic behind his desire to repatriate jobs to the USA, hence we should be cherry picking and adapting elements of what he is doing.

            1. Anonymous Coward
              Anonymous Coward

              Re: I read this as propaganda

              With all due respect, you can blame Thatcher for much but she had nothing to do with the invasion of Microsoft. In my opinion you can contribute all of that to Tony Blair who was so blatantly supporting Microsoft that he was even present at a launch product launch for which he justly attracted a lot of criticism.

              But the seeds of destruction had thus been introduced to government IT and boy, oh boy, have I seen some doozies after that. That's also why CCTA had to go - they had *way* too many people who were actually competent (yes, they did exist).

              Education fell soon after it because the allegedly "smart" academics were falling over themselves that Microsoft graciously sponsored education by giving them vast discounts. They were extensively warned by people who had seen it all before that they were given the first heroin shot for free, but of course nobody listened. And then, when they were all properly locked in the discounts disappeared to nobody's surprise but the academia.

            2. Anonymous Coward
              Anonymous Coward

              Re: I read this as propaganda

              Trump might be mad, but there is an element of hard economic logic behind his desire to repatriate jobs to the USA, hence we should be cherry picking and adapting elements of what he is doing.

              There isn't a single honest economist who would agree with you there, sorry. What everyone does agree on, however, is that decoupling from the US definitely has advantages. It should have happened years earlier, but as always nobody is interested in doing the intelligent thing until reality bites. As they say in the John Wick movies: "Consequences".

        2. doublelayer Silver badge

          Re: I read this as propaganda

          That works better with the Oracle example than it does with the Microsoft example. The difference is that in the case of Oracle, there's still a substantial amount of stuff specifically developed for Birmingham's particular needs by someone, whether that's Oracle themselves, some other business using them, or Birmingham's hired programmers. On that, I agree with you; calculating costs is very difficult for both approaches and trying to claim that one is easy and the other isn't is unconvincing.

          But if we're looking at something like Office365, there's a lot less code being written for the individual user. People already know most of the features involved in this, what they cost, and, if they're already using 365, whether they need them. Figuring out how much it costs to add Intune for device management is mostly a licensing question with some calculation of how long it should take to make the policies that will be enforced. Compare that to developing or adapting an open source device management system. The costs for that will be hard to determine, because if you are building it for the new government Linux distro you're also creating, you'll have more things you need to build in but more control over the system so more ability to integrate them during development, whereas if you have to manage fleets of lots of operating systems, you have to develop many different clients and deal with OS makers breaking things you relied on. That is, in fact, more difficult to calculate and it's likely that, if you only consider finances, it's more expensive. A proper comparison needs to also compare the expected features, maintenance cost, risks, and all those complicated things which makes both prices, but especially those for the system that doesn't exist yet, hard to calculate.

          Another reason this is hard is that we're not just comparing two alternatives. We haven't decided whether this should be a single government body making all the software they no longer want to buy, a process where other businesses are asked to do it and sell the result to the government, a process where businesses are given cash and asked to make the result open source, a process where existing software is supposed to be used unmodified, or separate methods for different parts of the government. That makes the calculations hard, and although they're well worth doing, many of those who would have to would prefer not to.

    4. Najh

      Knocking the government for doing the same as everyone else

      Can anyone that's suggesting the government made a bad choice in going with MS point to a FTSE100 or equivalent sized organisation that's successfully adopted open source at scale, particularly in the EUC space?

      For those that don't lile funnelling cash to non uk vendors, I agree and when a viable alternative is presented Im sure it will be given due consideration. To assume that organisations and particularly the people with authority to set strategy do it blindly is discourteous. For you to assume 400-500 people at the UKs largest organisations all made the wrong choice speaks volumes.

      1. Doctor Syntax Silver badge

        Re: Knocking the government for doing the same as everyone else

        400-500 people constitute a herd, following each other. In fact the basic argument seems to be that if everyone else is going along the same route it must be right. In fact it puts everyone into a dangerous situation, not particularly because it's Microsoft, Oracle or whatever but simply because of a monoculture.

        Even with simple things such as so-ans-so's cloud going TITSUP for a few hours that's maybe entire organisations - and many organisations - with staff sitting idle or trying to revert to manual operations. How many organisations were temporarily flattened by Crowdstrike and that was only an add-on to the main platform.

        If there is a vulnerability that gets exploited the damage isn't going to be a few hours, it's going to be months.

        That applies whether it's proprietary S/W or FOSS. It's the over-dependence on a single platform that's the risk. Proprietary does, however, carry the additional risk that we now realise proprietary software coming from a single country could carry a political risk.

        Even if the latter is improbably it's likely to be the one tat actually wake politicians up. There are an awful lot of Creese's "public sector business leaders" who are going to be left floundering if their political masters start asking about their plan B as are a lot of their private sector equivalents if their boards start to look around. And where that question gets passed onto them there are quite a few folks here who would be equally flummoxed.

        1. Najh

          Re: Knocking the government for doing the same as everyone else

          Might be a little1 late for this article.. My comment received a lot of down votes but not one person was able to meet the challenge of noting an organisation that has gone open source.. For all the people that down voted my comment why aren't you in a position to lead the charge to open source? Most organisations look for cost efficiency so the sell should be straightforward right?

          1. Doctor Syntax Silver badge

            Re: Knocking the government for doing the same as everyone else

            To a large extend what a commercial organisation does with its data is between its management, shareholders and customers. As long as I'm not one of their shareholders or customers it's their problem how leaky their systems although they really should be doing due diligence.

            When it comes to my government, however, I can't help but be concerned because it's my taxes paying for it and it's inevitable that at some point one of them might be handling my data. I'd hope, therefore, that they do their due diligence in which case they should be taking note of factors such as this: https://www.computerweekly.com/news/366632040/Microsoft-hides-key-data-flow-information-in-plain-sight which more or less confirms that Brad Smith admitted in France. They can't provide data sovereignty.

            It will very likely not take many of the sort of suits against the police that the CW article talks about to start CEOs asking their IT departments if that's a risk for them. What are they going to say? "Well, everyone else is doing it" isn't going to be adequate.

      2. HMcG

        Re: Knocking the government for doing the same as everyone else

        How about the entire French Gendarmerie IT system, Gendbuntu?

        1. Anonymous Coward
          Anonymous Coward

          Re: Knocking the government for doing the same as everyone else

          One very specific organisation that primary runs electronic forms through a wen browser.

          Look at Munich for a government organisation that tried for many years to move to OSS, it was hated by users, they still ended up having to run both and eventually had to give up as it just wasn't practical and workable for everything like Microsoft was.

          1. Kavalor

            Re: Knocking the government for doing the same as everyone else

            You should not forget that a big part of the time and cost of the Munich Linux Project was spent on Standardization.

            Before, every City-Department had their own separate IT Infrastructure, with widely diverging processes, applications ,documents, forms etc.

            That harmonization took the longest time on the project, the development work for the software was I think the smallest part of the whole thing.

            And the end of the project was a change in the city government, when the new mayor was a Microsoft fan and one of the longtime critics to even try to get away from Microsoft.

            But to my knowledge, the Accenture study proving Microsoft was cheaper did not separate the standardization costs from the software cost ...

            And don't forget that Microsoft miraculously moved into the city limits of Munich instead of just outside, so the business taxes flow to the city now. I call that bribery. Although it might be legal.

            I am sure that move would not have happened if Munich did not return to Windows.

            I am working with Linux all day, but on the desktop it has issues which won't be solved without investments, but nobody wants to invest, unfortunately.

            1. Anonymous Coward
              Anonymous Coward

              Re: Knocking the government for doing the same as everyone else

              https://youtu.be/duaYLW7LQvg?feature=shared

      3. I could be a dog really Silver badge

        Re: Knocking the government for doing the same as everyone else

        The problem with the argument is that for a large business, there is little practical choice.

        I think all but some ill informed FOSS fans agree that at the moment we simply do not have a replacement - Linux+LibreOffice+Thuderbird isn't a replacement for M365. I use exclusively LibreOffice at home and no longer have any MS software installed - the last MS Office I had was something like 2018 old (or older, I don't recall.)

        For a commercial business of (almost) any size I can think of, the cost of pulling together all the bits needed (they do actually exist I believe) and integrate them into something resembling a unified system would be impractical and impossible to justify to the board. But until someone does exactly that, there won't be any competition and MS will further consolidate their dominance - they've spend a decade or two boiling the frog to reach the position they are in now.

        What it really needs is government (or coalition of government) sponsorship to develop such a system - to the point where it becomes a turnkey option for all public bodies. And if you think about it, if we're spending close to £2B a year, you wouldn't need to save all that much to pay for such sponsorship. Just think how much could be achieved if we worked with the rest of Europe - by the time you'd shared out the cost, it wouldn't be all that expensive. But it needs a lot of political will - which seems to be a bit lacking, and even an admission by MS execs that we don't have sovereignty of our information (which is a legal requirement under UK and EU GDPR) doesn't seem to bother most politicians.

        1. I could be a dog really Silver badge
          Facepalm

          Re: Knocking the government for doing the same as everyone else

          was something like 2018 old

          Oops, make that 2008

      4. Roland6 Silver badge

        Re: Knocking the government for doing the same as everyone else

        Back in 1990, when the "decision" was made, there were plenty of companies and even in 2000 there where viable choices. The decision of governments (not just UK) to exclusively go with Microsoft rather than ensure they had a second source, meant the governments created the monster we have today.

        1. I could be a dog really Silver badge

          Re: Knocking the government for doing the same as everyone else

          Absolutely - not just governments, businesses fo all sizes. Collectively a massive "never mind the future, it's convenient today" attitude ignored the problem and allowed it to happen. As you say, strategically, governments should have seen this coming and taken action to prevent it happening - it would have been a lot easier than fixing it now. Not too dissimilar with defence, where for years we've taken the cheap/easy options - and now suddenly there's a realisation that we've let our industrial capabilities wither and are now trying to reverse a decades old mistake.

  4. Anonymous Coward
    Anonymous Coward

    Panglossian

    "more accepted by staff who use the same software at home"

    - circular argument: they use it at home because they are expected to use it at work (and they pay, directly or indirectly, for the home versions).

    "public sector business leaders, accountable for and able to demonstrate return on investment, benefits realization, and UK public value for money"

    - the polite response is that the voters will be sceptical on that assertion. ("Fell off chair laughing" would be the colloquial version.)

    1. Scotech

      Re: Panglossian

      "more accepted by staff who use the same software at home"

      - circular argument: they use it at home because they are expected to use it at work (and they pay, directly or indirectly, for the home versions).

      Circular arguments aren't fallacies in and of themselves. In this case, it's describing a self-reinforcing cycle, which is legitimate. And how is whether those staff pay or don't for their home use of the software in any way relevant to the argument for or against public sector adoption of it?

      "public sector business leaders, accountable for and able to demonstrate return on investment, benefits realization, and UK public value for money"

      - the polite response is that the voters will be sceptical on that assertion. ("Fell off chair laughing" would be the colloquial version.)

      Value for money in UK public sector IT (or rather, the general lack thereof) has a lot more to do with the fact that so much of the money is spent on external consultants and implementation partners instead of building and retaining those skills internally, than it does with any particular software vendor's pricing.

    2. Anonymous Coward
      Anonymous Coward

      Re: Panglossian

      Users are less and less using computers at home, they are using phones and tablets.

      The "digital natives" are computer illiterates already.

      For MS, the end of Windows is looming ahead, hence the move to AI.

    3. I could be a dog really Silver badge

      Re: Panglossian

      But for the record - I don't use any of it at home.

      And the other bit that caught my eye ...

      provides considerably better functionally

      You wouldn't write that if you'd heard me swearing out loud as I tried to persuade work to do something really really simple - copy and paste some information in Excel (i.e., effectively in a table) into a table in Word, but keeping the formatting of the table in Word. I ended up pasting it as a grotesque mess which didn't resemble the right formatting in the least, then cutting the contents of each cell of that and pasting it as plain text into a cell in the original table. Someone, somewhere, will have had flames off the side of their heads at that masterpiece of "user friendly functionality".

      is more accepted by staff who use the same software at home

      Speak for yourself. Mrs Icbadr comments that she knows if I'm doing something with her (Windows) laptop as it's the only time she hears me swear so much.

    4. Sudosu Silver badge

      Re: Panglossian

      I always found that "because they used it at home" they ended up treating their work computer like their home computer.

  5. Greybearded old scrote
    Joke

    FUD! FUD! FUD! FUD!

    Lovely FUD! lovely FUD!

    I would present my counter arguments, but those above are close enough.

  6. Filippo Silver badge

    >[...] the value that Microsoft brings indirectly, including [...] high levels of security and trust, [...] innovation such as AI [...]

    Sir, I salute your bravery. That said, for the sake of your health, though, I advise you to stop reading this comments page. It will not go well.

    1. FirstTangoInParis Silver badge

      So let’s separate “value” from investment. If gov had decided years ago to straighten their processes out and make it work, then custom software is the only possible best fit solution. And by custom I don’t mean bastardisation of SAP or Oracle or MS. What someone high up decided was that MS had something that vaguely looked capable of doing the job so we must bend our processes to that now.

      Take a good hard look at the gov.uk website these days. Yes GDS got a massive slagging off in the early days but just look at it now. It works properly and is fit for purpose. Heck I even digitally signed my mortgage deed on the land registry just recently. I’ve no idea what the back end is, but by golly it works. Now imagine that built on MS Forms or some other noddy general purpose software that was crowbarred to fit.

      I see this everywhere; hey let’s go with vendor X because they’ve given the C suite the best pitch so let’s roll it out partially and the great unwashed users will have to like it.

      1. I could be a dog really Silver badge

        Absolutely, as an enforced user I can assure you it's very true - so much of what we do is geared up to "how M365 supports doing it". Not "what's the best way to do it", but "what's the easy way to do it with M365". And if you suggested that's not always the best way, I would agree with you.

        And so many times I want to scream across the office that "Excel is not a ****ing database, stop throwing this unusable **** at me".

  7. Anonymous Coward
    Anonymous Coward

    Don't forget UK-specific training benefits

    Thinking of this from the point of the UK, who would presumably rather spend money helping UK people than USA people. Not that we're anti-American - I mean USA has NASA how cool is that? - but every country is supposed to prioritise its own people in resource allocation. So would you rather (a) give a billion to Microsoft for use of their software or (b) give the same billion to a bunch of UK developers to pay them to learn and improve the open source up to a professional standard.

    Either way, you get software that does the job (if we assume "it's done right" in both cases of course). But with the second option, you also get a whole bunch of Brits that you've trained. Which can then be used either on that or on other projects. Whereas if you'd just given it to Microsoft, well, *their* engineers tend to be in Redmond.

    There's precedent for this in Japan's KL-1 project, which was considered a failure in terms of the system it produced, but was still considered a success because of its immense value in giving training and experience to local Japanese engineers who could then go on to do other jobs in Japan. So maybe the UK needs a KL-1 like project, just try to make sure it actually ends up with a usable system as well this time as that would be a nice bonus right?

    1. Doctor Syntax Silver badge

      Re: Don't forget UK-specific training benefits

      "*their* engineers tend to be in Redmond."

      Are they? Not in India?

      1. HMcG

        Re: Don't forget UK-specific training benefits

        Or China, in the case of the recency security debacle over Sharepoint and the USA DOD leaks.

  8. abend0c4 Silver badge

    This is not really an IT issue

    The public sector is generally lamentable at procuring anything much beyond paper clips - high speed railway lines, aircraft carriers, accommodation for migrants, face masks, large buildings, ...

    Now, some of those things are exceptional and it wouldn't make sense maintaining the permanent capability within the public sector to deliver them when required. However, there is a constant ongoing requirement to replace hospitals and schools and railway signalling and roads and sewers and telecommunications and so on and while you wouldn't want every last person doing those things on the public payroll it seems really remiss not to have staff in the public sector who have sufficient expertise to commission, design and oversee the necessary projects. HS2 has largely been a fiasco as it was immediately put into the hands of a specially-created company and it appears no-one was left in government with the knowledge to keep it in check.

    Why aren't we building enough houses? Because we're leaving it to the private sector. In the 1950s my father worked for the architects department of a county borough. Local authorities employed architects (and, indeed builders) and that was the only way the post-war governments could deliver the promised new schools, hospitals, libraries and public housing. There were still private builders and other professionals involved, but there was a sufficient group of people, directly employed, to drive the projects forward and to maintain the expertise necessary to manage the contractors.

    If the public sector needs services on a large scale over a long period of time it really ought to be operating those services itself. It already has the scale to operate efficiently and it's never gong to develop the skill to do so if it's simply handing over money to third parties and - in the case of multinational conglomerates - is funneling money overseas rather than keeping it in the UK where it will pay for local training and be subject to local taxation.

    And, quite frankly, it's absurd to have a dilettante civil service in a world dependent on profound scientific and technical complexity.

    1. elsergiovolador Silver badge

      Re: This is not really an IT issue

      while you wouldn't want every last person doing those things on the public payroll

      Fortunately government thought about that too, thanks to IR35 they don't have to worry about that. There is now no incentive to even start such a business and the usual suspects got very much permanently embedded into to labour procurement pipeline, making massive mark up, while there are still mugs going into professions knee capped by captive labour market.

  9. Doctor Syntax Silver badge

    "But it should be limited and controlled, not led by the technologists, but by public sector business leaders, accountable for and able to demonstrate return on investment, benefits realization, and UK public value for money."

    Good idea. When are they going to be recruited. Actually, maybe not even a good idea because the usual complaint about business leaders in general is that they're likely to be technologically clueless and apt to believe anything the salesman tells them.

    1. Scotech

      Biggest issue in public sector IT is that the technologists business leaders are listening to are almost always external consultants being paid to sell the vendor's products regardless of how well they fit the business requirements, rather than internal permanent salaried professionals being paid to find the right solution to balance and hopefully address the various competing business requirements.

  10. This post has been deleted by its author

  11. Will Godfrey Silver badge

    Exactly

    I was going to comment, but the previous commentards have already said everything I'd want to.

  12. Anonymous Coward
    Anonymous Coward

    Hrrmph!

    > *Are the alternatives truly viable and comparable?*

    Not if you listen to the M$ sales team. Yes if you go looking for someone to implement your business model and not theirs.

    > *Is Microsoft a good value for money, despite its seemingly high cost?*

    No. MS365 + SharePoint + Teams + Win 11 is sickening every droid in my Government Department, from middle-management down. Since we moved from traditional desktop office + on-prem networked document databases, productivity has been nosediving.

    > *The Answer?*

    Anybody remember David Cameron? His Cabinet Office tried hard to promote Open Standards and Software across their fellow Departments. Small lip service is now paid to standards, but software met with blank incomprehension and/or apathy. Barriers such as updating the list of approved suppliers, already 15 years out of date, proved insurmountable. The answer is; education, education, education. Oh, yes, and legal obligations. Remember that even though various Germans once tried and failed, they have subsequently felt obliged to come back and try again. France gov too has a lot more F/LOSS than UK. It's not rocket science, it really isn't any more. Time to stop pretending it still is.

    > */The Register will present an opposing view tomorrow and you can have your say on Friday./*

    Looking forward to the flamefest. What we need is Vulture branded popcorn!

  13. 51mes

    We can spend forever goign over why the problem exsists and blame the usual suspects both in terms of the departments and the suppliers. Both are caught in that trap.

    The question is now people are finally waking up and smelling the roses - how do we get ourselves (the nation) out of the challenge.

    Unless one central authority builds that alternative and controls the narrative we are going to end up in a worse place. Multiple suppliers, with varying levels of compatibility he says, she says slopey shoulder support issues, and a proliferation of development training and support functions for the different variants all driving cost.

    If you really think UK Government could build such a thing and develop the ability to deploy and support it at scale - whilst keeping the lights on for the current estate, without using resources from the Multinational tax shy megacorps - I have a bridge I'd like to sell you....

    What this would take is nothing less than the nationalisation of the government desktop, rolled across education , local and central government with specialist considerations for areas such as defence, it's not a matter of months or even years but potentially a decade or more of effort. Is it worthwhile - of course it is I can see nothing more important than regaining and retaining our sovereignty and having control of our own digital destination as a nation. With the accompanying rebalancing of trade/investment in national rather than international resources and the retention of a skilled workforce.

    At that scale and involving our institutions - there would be room for the innovation and research that we get from the mega corps, but going it alone does one thing - in these days of globalisation the fact we are not on what is effectively a global defacto standard - how will this affect workforce mobility - going for a job in Australia or the US requiring experience in the US of M365, not UK365..

    There are no end of unintended consequences here.... Thankfully I'm not far from retirement so someone else can hurt their head thinking of them!

    1. Doctor Syntax Silver badge

      You're near retirement. So if the top team at wherever you work, public or private, look what happened to organisations as diverse as the BL and M&S start asking what alternatives you have, will that be your answer?

    2. Anonymous Coward
      Anonymous Coward

      > so someone else can hurt their head thinking of them!

      My brain hurts!

      That decade or more of effort can be shortened if gov.uk realises that it can engage the F/LOSS community for rather less money than MS365 licensing, and jointly work on business integration. That in turn will require new contract models, in which suppliers are obliged to publish the code under a permissive license and unknown third parties may add their own ideas for their own businesses. You know, a bit like those Linux VMs the infrastructure and infosec gurus keep slipping under the radar, or that MediaWiki instance our pointy-haired managers can never get our AD RBAC working with (I mean, an unstructured user community editable by all staff? sheesh!)

      F/LOSS does exist, to a greater or lesser extent within various Departmental IT systems, but the management problems are many and systemic. The way forward is evolution not revolution.

      1. HMcG

        > if gov.uk realises that it can engage the F/LOSS community for rather less money than MS365 licensing,

        This cannot be stressed highly enough. The article creates a false dichotomy between a very expensive Microsoft solution, and a zero cost open source one. The real solution is a middle ground of sufficient government funding to open source projects.

        Unfortunately that might take a few years for the returns to be achieved, and UK governments refuse to plan beyond the end of their term in office ( if that!).

        It’s no wonder that China has dominated manufacturing. Industrial manufacturing on a large scale requires long term planning, and neither current capitalism nor democratic governments plan beyond the next quarter.

      2. 51mes

        You miss the point,

        Building the system isn't the big challenge and definitely not writing code.

        The challenge is the several million plus users that will need to be trained in how to use it and the development of the capability in support teams who can support them doing so.

        And what do you think they will be using while the evolution/revolution happens - and of course if it's an evolution how much will you save as you will still need to pay the MS tax as you evolve.

        You have to realise the level to which MS has embedded itself into the psyche of those that see a computer as a glorified typewriter, and who recoil in fear at the mention of anything other than Outlook and Word and Excel. It starts in school - where document formats other than word for essays and papers are often refused... It then goes on into job applications where Microsoft Office Skills are a requirement.

        That is what takes time to resolve..

        1. Roland6 Silver badge

          Step 1: Ban the teaching use of Microsoft products in schools and education establishments.

          This solves the long term problem as these people will be familiar with non-MS products when they enter the workforce in the future, additionally, their skills will act as motivator to industry to move - its why Unix and C did so well.

          Step 2: Re-establish a credible CCTA, complete with teeth and funding...

          Step 3: Specify a core set of (office) document Standards that must be supported - ie. a specific release suite of ODF and PDF standards.

          Step 4: Invest in re-establishing the independent testing environment which existed in the 1980's who can test and arbitrate between products and their differing implementations of the Standards.

          All the above could be up and running within 2 years, given the political will.

  14. Anonymous Coward
    Anonymous Coward

    Appreciate the joke/poke etc. I'm sure you're not serious

    But: I think rather than OSS vs COTS - perhaps we should consider what is commodity? And, what drives vs stifles competition and innovation.

    OS's, (Win/Mac/Linux/Android/IOS), file and print servers, and Office suites are commodity nowadays. What's not perhaps is collaboration and security of your files.

    Microsoft hasn't done a good job with security for AD/filesystems for a long time (every ransomware seems to be AD used to get to VMWare), which has pushed people into 365 - where there's MFA at least!, and is currently orders of magnitude better security (but messier than ever!)...

    Collaboration software, from MS/Google/Apple etc is cumbered with commercially encumbered protocols. (stifling innovation, market movement).

    Open software, and open standards, has driven costs down: look at everyone building KVM hypervisors to displace Broadcom! It's so funny!

    Our MS license doubles every several years... how sustainable is that?

    All in with any monopoly is doomed to failure eventually. It's just when will that bubble pop.

    I know regulation is a hinderance, but mandating open gateways between communications protocols, and requiring a Google 'takeout' type - "move my business" between the 'clouds' - I think really should be mandated. And we, as consumers should keep to the open standards stuff wherever possible.

    Although many here are Google/AWS/Oracle haters too - the value proposition is often better for the commodity parts of their business. (K8s, hosting etc)

    Can't wait to see the opposing article!

  15. coderguy

    Do we have to explain the difference between Open Source and Free Software again?

    For the impatient.

    Closed source

    You can't read any code, safety is ensured on a "trust me bro it's safe" basis. Maintenance whenever the vendor feels it's needed.

    Open source

    You can read the code. You may not do anything useful with it though. Maintenance is usually done by a single entity.

    Free software

    You can read the code. You are allowed do what you like with it**. Maintenance, can be handled by anyone who can donate the development hours.

    ** There are edge cases.

    All types could be free to use.

    All could be commercially funded through licences.

    Just because it's free to use, doesn't mean you are absolved of paying for support.

    1. doublelayer Silver badge

      Re: Do we have to explain the difference between Open Source and Free Software again?

      It appears we do, because we've got another person who doesn't know and is making up some definitions. Welcome to the class, coderguy.

      When we talk about "open source", we're referring to stuff that is either completely compliant with or very close to the OSI's definition. We may disagree about certain parts of that, but most of that is considered required to qualify. Your definition: "You can read the code. You may not do anything useful with it though. Maintenance is usually done by a single entity." is not that. Those who try to pretend their software is open source when it would qualify only as your definition will earn our scorn because it's not open source. In case you're interested, they can also lose a lawsuit because our definition, the one where you have the right to fork and distribute, is considered so correct that courts have ruled that those who don't intend to provide it are lying about being open source. Now, we've explained.

      1. steelpillow Silver badge

        Re: Do we have to explain the difference between Open Source and Free Software again?

        > the OSI's definition.

        Except, when it comes to everyday manglement, they have only ever dared listen to Microsoft's definition.

  16. Boris the Cockroach Silver badge
    Linux

    FOSS vs m$

    "We cant change... everything is on office/wins and our staff only knows office wwwhhaa we cant change. costs too much etc etc."

    We have 4 5axis machines all the same, same control, same table size, same manufacturer. staff got to use them and get used to the controls and howto set them up.

    The boss gets a bargain, a 5 axis cheaper than the first 4 ... downside.... it has a slightly different control layout... gawd you would not have believed the amount of complaining from the staff. 2 weeks later its in use and the staff are like 'meh... lets get the job done'

    If your average office drone cant cope with the difference between office and libreoffice, how the fook will they cope when m$ decides to change the office interface (as well as tweaking the file format again)

    1. Roland6 Silver badge

      Re: FOSS vs m$

      >"We cant change... everything is on office/wins and our staff only knows office wwwhhaa we cant change. costs too much etc etc."

      But we can foist the change from Office 2003 to 2007 - Ribbon, and the change in Windows XP/7 to 8 and now 10 to 11 on our users without any specific training because it is still Microsoft Windows and Office; which our users are familiar with...

  17. Anonymous Coward
    Anonymous Coward

    For f*--sake

    Honestly, if I couldn't be any less impressed by the public sector ... £1.9 Billion in software licenses.

    What a joke.

    We all know how it is. Fools and their money and boy are there an awful lot of fools in charge of public finances.

    I've run a company pretty much on open source for twenty years and spend a fraction of what I would have spend on proprietary software.

    Any idiot can spend money, what counts is when you can achieve the same and often a better outcome, if you know what you are doing) for a tenth of the cost and that is what open source can achieve.

    These idiots of all parties will bankrupt this country becaus they really don't understand the details.

    1. Doctor Syntax Silver badge

      Re: For f*--sake

      "These idiots of all parties will bankrupt this country becaus they really don't understand the details."

      If we were at that stage we'd be making progress. Right now they don't seem to understand the basics.

  18. Roo
    Windows

    The 1990s called, they want their FUD back.

    Jeez, this article may as well have been written 30 years ago.

    It is a damning indictment of the author that they are *still* pedaling this crock after THREE --ing decades and at least *FIVE* major "retraining required" releases of Windows. The costs of using something other than your favourite business lunch provider's products are still "hidden" because you haven't actually gone out and done your --ing job which is to *find* out what those hidden costs are... 30 wasted years - all on the tax payer's shilling.

    Give your head a wobble.

    1. Anonymous Coward
      Anonymous Coward

      Re: The 1990s called, they want their FUD back.

      Company I work for is refusing to move off Win10 to Win11 simply for one reason, the cost of retraining 780 people in a new O/S. When we moved from desktop to Office365 it was a month of refresher/update courses on offer to everyone with the basics course being mandated for every single employee, even IT so we knew what stupid questions to expect.

      I remember when we moved off WinXP and it took 2 months of HR mandated courses for every single employee. After work every Thursday evening we'd find the training consultants in the local designated "IT pub" buying lots of rounds!!

      1. Anonymous Coward
        Anonymous Coward

        Re: The 1990s called, they want their FUD back.

        Now make that a gov org with 200k users - same problem, different attitude.

        it was a month of refresher/update courses

        Try, a few hints and tips pages on the intranet - if anyone can find them with MS's "write only" Sharepoint where it seems nothing is findable (we used to have Bing Work, which worked, so naturally MS turned it off !)

        One big problem we have is that the costs are hidden. Many times it's been mentioned/asked "is there a timesheet code for IT issues" - and it's either ignored or "we've decided not to do that". It's almost as if manglement don't want to know how much time is being wasted by user having to muddle along. Several in our team have already had their Win 11 updates - and let's just say it's not gone smoothly and I don't think anyone has not had significant problems with something or other not working afterwards (one's waiting for a replacement laptop to be delivered as they can't fix the issues remotely.) I've set aside tomorrow as a "get nothing done day" as one of my laptops has reached the front of the queue and told me it's coming (I've deferred twice today, might as well waste a quiet day doing it tomorrow.)

  19. ovation1357

    Grand Enshittification

    I've always hated Microsoft and pretty much everything it does, but in the present day it's just going from bad to worse.

    Just this evening I i caught a brief part of a programme on the radio where a lady was saying that doctors are leaving the NHS because of the terrible IT - I think the example cited by the interviewer was reports of systems taking 30 mins just to log on.

    Whilst I happily run a Linux-based laptop which isn't even the latest and greatest but boots and it's ready to use in under 30 seconds, my 'corporate' Windows laptop can take anything from 5 minutes to to an hour to boot and fully log in. I see this all over the place in both public sector and private sector devices.

    Window is pretty rubbish at booting and even worse at logging in - connect it to a domain, add a load of group policies and q bundle of "security" software plus Office 365 and OneDrive and you've got yourself a total clunker.

    It would seem (from taking to colleagues who have recently been 'upgraded') that Win 11 is even slower and worse than 10 was.

    Now I know that some of this will be down to the way the image was built in house (e.g. resetting default file associations at each login, where the default program for opening PDFs is Adobe Acrobat for which there's no licence, so it blocks you even from just reading the open document), however its all built upon a pretty awful foundation to begin with.

    I personally despise the modern UI in Windows which began back with Win 8 and Metro and i think Outlook is an appalling bad email client. But even if i were to overlook all that, there's still the fact that the whole experience is persistently excruciatingly slow! Logging in presents a spinning circle for an indefinite (but usually long) time and then trying to open my documents on OneDrive takes 10+ seconds to open the folder view and 30+ seconds to open a word document. All on a recent laptop with an SSD and 16GB RAM! It's like walking through treacle.

    Meanwhile my Ubuntu machine with Thunderbird and Libre Office happily opens even remote file shares within a split second and takes no more then a few seconds to open a document in Libre Office, meanwhile Windows is still trying to log in.

    It's got to the point that Microsoft has enshittified the end user experience so much that people are quitting their jobs because of bad IT. Put some clunky, over engineered business application on top and it's easy to see why people can't cope any more.

    FOSS could help enormously in this case but it would need a huge shift in corporate attitudes to even think about using it. Microsoft has a very powerful monopoly and it's not about to roll over and give up all that juicy pubic money.

    1. doublelayer Silver badge

      Re: Grand Enshittification

      I've seen that on occasion, but my personal laptop, if I boot to Windows, has it started and logged in within 20 seconds and my work machine in about 40, most of that being the dual login system. So I don't think Windows can be fairly blamed for that.

      1. Chz

        Re: Grand Enshittification

        Have to agree with that. No dual login here, so the work laptop is up and logged in in around 20 seconds.

        I do not recognise the OP's take. It certainly *was* like that, once upon a time, but that was the days of spinning rust and Linux didn't boot too quickly either.

        1. ovation1357

          Re: Grand Enshittification

          It's a very very long time since I set up any kind of domain joined Windows machines and the ones I ever did would only have signed in on the local network and not via an remote solution.. So it's useful to hear that it's now possible for business machines to boot and login quickly.

          Until today I've only witnessed or experienced poor start up and login times. And my friends working for a variety of organisations from Banks to Government generally seem to moan that their computers take forever to start up so it's certainly not unique to where I'm based.

          I'm pretty sure mine is still using an on-prem AD for authentication and I think my home drive is now running on OneDrive (although the previous on-prem shared storage home drives were no better).... I wonder if the user experience is better if you're using Azure AD or a Microsoft online account?

          There's little to nothing I can do at my organisation to influence or change the IT which is all outsourced to a big company which is, no doubt, charging top dollar for delivering the bare minimum. So like many users (in addition to the thousands in my organisation) I'm stuck having to use a corporate laptop which is slow and horrible :-(

          To be fair, I'm sure a Linux based environment could also get bogged down in things which make it run very slowly but I'm sure I've only ever seen one example of that in my whole career.

          MS software and tools seem to make it extremely easy to deliver a poor experience.

          I'd personally love nothing more than to live through the fall of Microsoft. It has relentlessly abused its position of power over the years and its current fluffy warm stance on open source and loving Linux all of a sudden is merely a wolf in sheep's clothing. Mark my words - if I were into betting I'd place money on it - one day, Microsoft is going to bite FOSS really hard in order to strengthen its dominance.

    2. steelpillow Silver badge
      Windows

      Re: Grand Enshittification

      To be fair, it's not just Microsoft. All the big dot coms are filling our CPU's lives with blood-sucking cross-site javascript, while "because privacy" is doing the same with multiple-layered certificate servers in the attempt to staunch the flow. All this "collaborative web" shit doesn't help either, just adds more layers of trans-domain tangle. Give M$ due credit, their stuff doesn't just barf and die, it keeps trying to re-establish that third certificate server's connection after the seventh timeout - or at least offers a "Try again" button.

      F/LOSS can help a bit, but the real need is to standardise and simplicate the constructive remote web-office calls, while stamping down on the remote blood-suckers.

      P.S. Never thought I'd ever say anything kind about the Beast. I must be getting old.

    3. Anonymous Coward
      Anonymous Coward

      Re: Grand Enshittification

      Those doctors would likely have to set up their own private practice if they want to get away from bad healthcare IT because I read similar complaints from Europe and America.

    4. Just Enough

      Re: Grand Enshittification

      "I happily run a Linux-based laptop which isn't even the latest and greatest but boots and it's ready to use in under 30 seconds, my 'corporate' Windows laptop can take anything from 5 minutes to to an hour to boot and fully log in."

      So you want to know why your home laptop, connected to your home network, boots faster than your corporate laptop, connected to god knows how many layers of corporate network and security?

      Why can I be on my bike and cycling down the road in seconds, when it takes over an hour to refuel and board an airplane before it takes off?

    5. Anonymous Coward
      Anonymous Coward

      Re: Grand Enshittification

      Check the routing table on any corporate machine and compare it to your personal machine!

      The last time I looked at the routing table on my work PC was about 4 months ago and it was about 2-3 pages! Now throw the AV, VPN and infosec mandated GPOs into the mix and and you begin to see why it literally takes 5 mins for a work PC to boot and be ready.

      These days I only reboot my work PC once a week on Monday morning when the weekly patches/updates come out at Sunday midnight, rest of the time I leave it up and logged in as it's just quicker than waiting 8-10 mins.

  20. cuna

    This article reads like it was written by a consultant with a brief to push Microsoft products. I’m not saying Microsoft’s solutions don’t work, but when I see a line like “Open source also comes with a range of less measurable costs – training, over-engineering, reliability, security maintenance, data interchange and interface complexity”, it’s hard not to roll my eyes.

    Training? Please. Your average Microsoft user isn’t a power user, and IT staff can retrain easily — it’s literally part of their job. And are we seriously going to pretend Microsoft products are somehow better engineered, more secure, easier to maintain, less complex, and more reliable than open source alternatives? Don’t make me laugh. Seriously.

    1. Strahd Ivarius Silver badge
      Facepalm

      IT staff? what IT staff?

      I got a supposedly level-2 on-site support tech unable to execute a simple command because he didn't create the output folder before running it, and was asking what to do...

  21. Frank Leonhardt

    "It is very difficult, for example, to quantify the value that Microsoft brings indirectly, including ... high levels of security and trust,"

    Microsoft brings high level of security and trust? This must be a different Microsoft.

    1. sitta_europea

      [quote]

      "It is very difficult, for example, to quantify the value that Microsoft brings indirectly, including ... high levels of security and trust,"

      Microsoft brings high level of security and trust? ...

      [/quote]

      Yeah, that bit about "...high levels of security and trust..." must have been a quote from Truth Social or something.

      What's the average number of critical vulnerabilities in a Patch Tuesday? And what's the trend in that number?

      Somebody must have all the data, but from the sample immediately and easily available to me it doesn't exactly look inspiring:

      https://www.theregister.com/2019/06/11/patch_tuesday/ [...88 CVE-listed flaws...]

      https://www.theregister.com/2019/07/10/patch_tuesday_july/ [For Microsoft, July brings fixes for a total of 78 CVE-listed vulnerabilities.]

      https://www.theregister.com/2019/08/13/windows_rdp_patch_tuesday/ [Among the 93 CVE-listed flaws patched this month are four particularly serious remote-code execution bugs...]

      https://www.theregister.com/2019/09/10/patch_tuesday_abode_sap/ [and the kitchen sink...]

      https://www.theregister.com/2019/10/08/october_patch_tuesday/

      https://www.theregister.com/2019/12/10/patch_tuesday_december_2019/

      https://www.theregister.com/2020/01/14/patch_tuesday_january_2020/

      https://www.theregister.com/2020/03/11/patch_tuesday_march_smbv3/ [No patch available yet!]

      https://www.theregister.com/2020/04/14/april_patch_tuesday/

      https://www.theregister.com/2020/07/15/july_2020_patch_tuesday/ [Windows DNS servers (mostly also domain controllers). Huge issue. Been there ~20 years.]

      https://www.theregister.com/2020/08/11/patch_tuesday_august/

      https://www.theregister.com/2020/09/08/patch_tuesday_september/ [Horrifying, but slightly better than typical.]

      https://www.theregister.com/2020/10/13/microsoft_patch_tuesday/

      https://www.theregister.com/2020/11/11/patch_tuesday_updates/ [One hundred and twelve Microsoft security patches this Tuesday.]

      https://www.theregister.com/2020/12/08/patch_tuesday_fixes/ [Quite a selection.]

      https://www.theregister.com/2021/01/12/patch_tuesday_fixes/ (...again).

      https://www.theregister.com/2021/04/13/patch_tuesday_april/

      https://www.theregister.com/2021/05/11/microsoft_patch_tuesday_exchange_hyperv/

      https://www.theregister.com/2021/06/09/june_patch_tuesday/

      https://www.theregister.com/2021/07/14/patch_tuesday/

      https://www.theregister.com/2021/08/10/microsoft_patch_tuesday/ [This made the news - only 44 vulnerabilities this month!]

      https://www.theregister.com/2021/10/12/microsoft_patch_tuesday/ [This month: 1 low severity, 68 important, 2 critical.]

      https://www.theregister.com/2021/11/09/microsoft_spreads_patch_tuesday_joy/ [55 important vulnerabilites, including 6 critical, patched on tuesday 9th November 2021.]

      https://www.theregister.com/2022/01/12/january_patch_tuesday/

      https://www.theregister.com/2022/01/13/microsoft_patch_tuesday_titsup/

      https://www.theregister.com/2022/01/18/patching_patch_tuesday/

      https://www.theregister.com/2022/03/09/microsoft_patch_tuesday/

      https://www.theregister.com/2022/04/13/microsoft_patch_tuesday/ [Over 100 fixes including ten critical vulnerabilities in this month's Patch Tuesday.]

      https://www.theregister.com/2022/05/11/microsoft_patch_tuesday/ [Only seventy-odd this month, seven critical.]

      https://www.theregister.com/2022/06/15/microsoft_patch_tuesday/

      https://www.theregister.com/2022/07/12/microsoft_july_patch_tuesday/ [June's zero-day fault gets patched in July...]

      https://www.theregister.com/2022/08/09/august_patch_tuesday_microsoft/

      https://www.theregister.com/2022/09/13/microsoft_patch_tuesday_september_2022/

      https://www.theregister.com/2022/10/11/october_patch_tuesday/

      https://www.theregister.com/2022/11/09/microsoft_november_2022_patch_tuesday/

      https://www.theregister.com/2022/12/14/microsoft_december_patch_tuesday/

      https://www.theregister.com/2022/12/14/microsoft_patch_tuesday_vm/

      https://www.theregister.com/2023/01/11/patch_tuesday_january_2023/ [98 vulnerabilities patched in the first Patch Tuesday of the year - some of them already under exploit.]

      https://www.theregister.com/2023/03/14/microsoft_patch_tuesday/

      https://www.theregister.com/2023/04/11/april_patch_tuesday_ransomware/

      https://www.theregister.com/2023/05/09/microsoft_may_patch_tuesday/ [This month, a relatively low number of fixes: only 38.]

      https://www.theregister.com/2023/07/11/microsoft_patch_tuesday/ [One hundred and thirty vulnerabilities addressed - but a zero-day one-click compromise isn't.]

      https://www.theregister.com/2023/08/08/microsoft_intel_august_patch_tuesday/ [Note the bypass of the bypass of the bypass of the patch of the patch of the patch!]

      https://www.theregister.com/2023/10/10/october_2023_patch_tuesday/ [Microsoft on Tuesday issued more than 100 security updates...]

      https://www.theregister.com/2023/11/15/november_2023_patch_tuesday/ [...fixes for about 60 vulnerabilities – including three that have already been found and abused in the wild.]

      https://www.theregister.com/2023/12/13/december_2023_patch_tuesday/ [Microsoft: 36. Adobe: 212. Yep, that's in one month.]

      https://www.theregister.com/2024/01/09/january_patch_tuesday/ [A relatively calm start to the year for Microsoft, only 49 vulnerabilities this month, including 12 RCE, two critical...]

      https://www.theregister.com/2024/02/14/patch_tuesday_feb_2024/ [73 vulnerabilities this month, FIVE critical and under active exploitation.]

      https://www.theregister.com/2024/05/14/microsoft_may_patch_tuesday/ [60 Windows CVEs]

      https://www.theregister.com/2024/06/12/june_patch_tuesday/ [Only 47 Microsoft security issues this Tuesday.]

      https://www.theregister.com/2024/07/10/july_2024_patch_tuesday/ [Tuesday's software updates address more than 130 Microsoft CVEs.]

      https://www.theregister.com/2024/10/08/patch_tuesday_october_2024/ [...this one is a doozy. Microsoft has delivered 117 patches...]

      https://www.theregister.com/2025/01/15/patch_tuesday_january_2025/ [...three under-attack privilege-escalation flaws in its Hyper-V hypervisor, plus plenty more...]

      https://www.theregister.com/2025/04/08/patch_tuesday_microsoft/ [...11 critical issues in its code to fix. Redmond delivered fixes for more than 120 flaws this month...]

      https://www.theregister.com/2025/06/10/microsoft_patch_tuesday_june/ [Just 66 fixes - some under active attack - this Tuesday.]

      https://www.theregister.com/2025/08/12/august_patch_tuesday/ [...111 problems in its products, a dozen of which are deemed critical...]

  22. Jim Whitaker

    Gosh you do surprise me.

  23. Dave Null

    it's not just about application software though is it?

    It's the cloud service behind it. Hosting your own OSS mail servers/team collab software/data storage etc isn't easy or cheap to achieve. Running a hyperscaler cloud offering is a massive undertaking that individual companies are going to struggle to do at less total operating cost. Think security - if a nation state decides they want your org's data - can you secure it as well as a hyperscaler? Probably not. People thinking that this spend can be removed by swapping Word for Libre Office aren't really thinking about the bigger picture...

    1. Anonymous Coward
      Anonymous Coward

      Re: it's not just about application software though is it?

      Did you miss the bit where MS finally admitted what we already knew - your data is not secure in their cloud and if they have a valid demand they'll hand it over to the US government (or agency thereof) ?

      Or the fact that it's almost impossible to understand where data ends up with the many different functions in Teams ? To be blunt, at work we really don't know what we can and can't discuss if (for example) we have a meeting that includes people calling in (from a supplier) using their organisation's Teams - though luckily we still have Skype where we do know what the rules are.

  24. RegGuy1

    Multiple providers

    I remember being involved in the national negotiations of the government license agreements with Capita, SAP, Oracle, and Microsoft in the early 2000s, which secured much better value than individual organisations could have achieved on their own.

    I didn't quite understand this. Was this one project that used all these providers? If so that could make sense. But only if there is a provider managing the whole project -- ie a single point of contact. Otherwise, at least in my experience, when you have problems you get nowhere.

    * 'Whose fault is it?' Theirs;

    * 'Who can sort it?', They can;

    * 'Who do we go to to solve it?' Somebody else, not me.

    But change the question and ask, 'I'll pay money to get this solved', and they will all to a man say 'I can solve that'.

    You need a single point of contact, through whom you bill. Then they will negotiate with all the providers on your behalf and you should just get a solution.

  25. Strahd Ivarius Silver badge
    Pirate

    Microsoft for government is fine...

    ... as long as MS is fined 1% of their global turnover each time there is a zero-day security issue in one of their product, whatever it is and even if said government is not using it.

    And payment is due immediately after the disclosure of that security hole, of course.

    If they don't pay, then it is time to send the spooks take care of the current CEO.

  26. Anonymous Coward
    Anonymous Coward

    Hidden advantages

    Open source may have hidden costs, but it also has hidden advantages namely that it will support a national software industry instead of lining the pockets of some foreign tech-behemoth. And don't forget data and application sovereignty which allow this foreign power to subpoena your data at any time for any purpose or deny you access to said data and applications.

    IMHO these two advantages are in themselves sufficient to warrant a complete switchover to open-source software, no matter what the cost.

  27. This post has been deleted by its author

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like