The Register Home Page

back to article UK told its Big Tech habit is now a national security risk

Britain has spent years wiring its public sector into US Big Tech, and a new report says that dependence could quickly become a national security headache. The warning comes from Open Rights Group, whose latest report, "Tech Giants and Giant Slayers," argues that the UK has let a small group of American megacorps entrench …

  1. Doctor Syntax Silver badge

    Slight correction of tense

    "could quickly become a national security headache"

    The only way it could become a headache if to start thinking about it which obviously HMG so far hasn't. For anyone who has thought about it it already is a headache.

    1. Guy de Loimbard Silver badge

      Re: Slight correction of tense

      Indeed!

      I echo your thoughts Doctor Syntax.

      We have been riding the coat tails of everyone else for far too long in the UK.

      The UK, and others, should start to look at the next decade's worth of investment and think where it truly needs to be.

      No "Sovereign" Cloud will cut it I'm afraid.

      We need to support the minnows and help them, where applicable, get a fair market share.

      Also, we need to wean ourselves off all this US centric software that we don't truly need.

      Just my opinion of course, or do we need to get a manumission to be free?

      1. Doctor Syntax Silver badge

        Re: Slight correction of tense

        If, by "Sovereign" Cloud you mean the usual Greeks bearing gifts, I agree. What's needed is actual sovereign not-quite-cloud, i.e. services not run on somebody else's computers.

        1. Guy de Loimbard Silver badge

          Re: Slight correction of tense

          Love the analogy Watch out for those Greeks.

          There's an opportunity, IMHO, that the UK and other could workout what the new world order technology requirements are and start investing, researching and developing, as required.

          1. milliemoo83

            Re: Slight correction of tense

            I'd be more wary of Trojans... they're complete smegheads.

        2. John Robson Silver badge

          Re: Slight correction of tense

          If by this you mean you wouldn't consider amazon's internal use of AWS to be "cloud" computing then yes.

          It *sort* of still is, in that it uses exactly what anyone would use to operate, but at the same time it isn't that simplistic definition "someone else's computer"

    2. elsergiovolador Silver badge

      Re: Slight correction of tense

      It is very easy to stop thinking over a wine and steak.

      It's a shame that folks working at NCA or SFO think that their job is to draw salary and look away.

      1. Doctor Syntax Silver badge

        Re: Slight correction of tense

        As far as I can make out sometime about last October you missed out on a free meal with a very unimaginative menu. Or perhaps that's when you heard you'd missed out. Or somebody told you you'd missed out to wind you up.

    3. Anonymous Coward
      Anonymous Coward

      Re: Slight correction of tense

      The only time they thought about it was to shut down our national champion and sell out to US Tech and Consulancy.

      Thanks Tories, thanks NuLabour.

      https://en.wikipedia.org/wiki/Central_Computer_and_Telecommunications_Agency

  2. Dr Paul Taylor

    Palantir in Parliament

    There is a debate in Westmister tomorrow about the Palantir NHS contract. Write to your MP, correction: the MP in your constituency.

    M$ and gmail send my email to spam: I wrote on Mathstodon about this and have just passed 1000 boosts and 1000 favorities, so join the club!

    1. Paul Herber Silver badge

      Re: Palantir in Parliament

      Palantir => Mordor => Sauron

    2. elsergiovolador Silver badge

      Re: Palantir in Parliament

      Do you think MP will cancel wine and steak dinner because unwashed pleb doesn't like their data being misused? You have to wait until around the elections, when MPs wake up from the freebie coma and realise they need votes to continue sitting in the gravy train.

  3. Anonymous Coward
    Anonymous Coward

    Conflict?

    I work with the UK branch of a US multinational supporting a system that fall into the remit of GDPR-UK and the Official Secrets Act..

    I really have issues with things like the US Cloud Act, and how it relates to GDPR-UK and the Official Secrets act.

    If an instruction comes from the US holding company to leak data, it is not just the UK subsidiary that would be breaking UK law, it is everybody involved in the extraction in the UK who support the systems who would also be breaking the law at a personal level.

    I have actually asked my management chain about this, and I've been told that the situation would never arise, but I've made it clear that if I was asked to break UK law in order to knowingly provide information to the US parent in breach of data protection, I would walk, but I don't think that everyone around me would take the same decision.

    In this case, there is a bit of a get-out, as the actual systems are owned and air-gapped in local data centres operated by this UK organisation we run them for, and we are just the maintainers and administrators. There is an approval process involving the client that should/would stop large scale export of data, which would make it clear if something is being asked for under the covers, as it would have to avoid the change process.

    1. elsergiovolador Silver badge

      Re: Conflict?

      , as the actual systems are owned and air-gapped in local data centres operated by this UK organisation we run them for,

      This is just a coping mechanism. If request comes they need to make it available. You cannot evade a control-based legal regime by playing dress-up with ownership. A UK badge on the bonnet does not help if the steering wheel is still in California.

      1. Anonymous Coward
        Anonymous Coward

        Re: Conflict?

        And that is why I would walk.

        It's an interesting conflict though. No matter what the US laws say, the data is domiciled in the UK, run on systems owned by the UK client, by a UK limited company (albeit owned by a US one), and run by people who have been vetted and also signed the acknowledgement that they understand that they are covered by the Official Secrets Act (as is everyone in the UK, whether they've signed it or not).

        UK law should be the prevailing law, no matter what the US thinks.

        Nobody from outside specific UK sites is allowed any access, especially remote access from abroad, and nobody gets access to these sites without either being escorted, or signing the aforementioned acknowledgement. This makes it a personal offence, punishable by prison in the UK, to export the data to the US.

        So the US government can fine or otherwise penalise the US company, but they should have no way short of cyber warfare to get access to the data without someone in the UK risking arrest. This is not a US run Cloud operation where data can be duplicated or moved within the Cloud infrastructure out of the UK at the click of a button.

        1. elsergiovolador Silver badge

          Re: Conflict?

          The CLOUD Act works by compelling the US parent, not by sneaking into a UK data centre.

          If the US parent controls the company, it doesn’t need ‘access from abroad’. It can instruct the UK operation to produce the data. That instruction doesn’t have to look like ‘export secrets to the US’. It can look like routine work: generate reports, enable logging, run queries, adjust backups. No one on the ground needs to think they’re committing an offence.

          And if the parent refuses, the US can enforce compliance where it actually has power: against the parent company and its executives. At that point, the internal pressure to comply is overwhelming.

          1. Anonymous Coward
            Anonymous Coward

            Re: Conflict?

            It can attempt to compel the people with access. That does not absolve the the prople in th UK from the effects of UK law. In order to comply with the compulsiom, the authorized people in the UK would be breaking UK law, and would be subject to arrest and trial, and it is very probable that the UK subsidiary would also be breasking GDPR-UK and other security laws.

            And as I tried to point out, people outside of the reach of UK law have no acces to the data so are not in the process.

            You are correct that it could be disguised as regular work, but such work is overseen by a process including the client. I was involved in officially exporting data out of one pf the data centres, and the hoops to jump through to do it were significant. And at any point, if it was thought that the data was being done inappropriatly, I would have stopped.

            1. elsergiovolador Silver badge

              Re: Conflict?

              You’re imagining a whistleblowing moment. In reality, it looks like a Jira ticket.

              If you push back, it doesn’t trigger a dramatic legal standoff. It becomes a performance issue, or the work is reassigned, or the requirement is reframed until it fits within existing process. Large organisations don’t rely on one person agreeing to do something obviously improper, they route around friction.

              And crucially, the obligation isn’t being enforced on you in the UK, it’s being enforced on the US parent. That’s where the real pressure sits. Once the parent decides it must comply, the question internally stops being ‘should we do this?’ and becomes ‘how do we do this in a way that fits our processes?’

              At that point, the perimeter controls and sign-offs you’re describing don’t stop it, they just shape how it’s done.

              1. Anonymous Coward
                Anonymous Coward

                Re: Conflict?

                I respectfully disagree. I suppose I'm fortunate enough that the environment I'm supporting makes it very difficult, both by design and architectural differences, to export data in volume. Any attempt involving physical media has to get client approval. I'm lucky that way and I'm late enough in my career that the consequences would make little difference to me, either work wise, or personally.

                The point at which the UK subsidiary decides "How should we do this?" is the point where they have to make up their mind as to whether they will break UK law, and as such, is a decision about whether they still want to be a company operating in the UK, and whether the people in control of the UK subsidiary want to become criminals. If the Government finds out, and decides that at a corporate level, the UK subsiduary has breached the law is the point at which they can fine and ultimately shut down the UK company, These are not toothless regulations.

                There is an absolute obligation under UK law and enforceable in the UK by the UK authorities. Even if you are subtly compelled, you can still be personally liable. Such is the nature of the Official Secrets Act. "Only doing it under orders" is not a defence if you have any idea whatsoever what is going on. If you are bound by it, I strongly suggest that you re-read the UK Official Secrets Act, and possibly the GDPR-UK regulations.

    2. Anonymous Coward
      Anonymous Coward

      Re: Conflict?

      In this case, there is a bit of a get-out, as the actual systems are owned and air-gapped in local data centres operated by this UK organisation we run them for

      But that's not the case for an awful lot of stuff. I'm pretty sure that if the orange buffoon make the right noises to Microsoft, they could effectively shut down UK defence (along with the rest of UK government). Such is the degree to which we're now entwined with Microsoft's clouds. Doesn't matter that some of it is hosted on-prem, I'm fairly certain that we now use MS's AD and authentication etc. - so they can stop us logging in.

      1. Anonymous Coward
        Anonymous Coward

        Re: Conflict?

        I'm afraid that you're correct, especially now Windows is effectively becoming an OS-as-a-service, having to check in with the mothership on a regular basis for authorisation to allow it to keep running,

        And anything relying on Azure, AWS or the Google Cloud is equally vulnerable to this type of service denial.

        In my case, being a non-Windows environment several arms distant from MS services, we could keep my part running without MS's approval, but the infrastructure around it is not so fortunate.

  4. Doctor Syntax Silver badge

    Having flicked through the report it does seem extremely over-wordy but the executive summary is a bit lightweight. Politically they should have promoted the Labour MP's foreword over the the Green's.

  5. elsergiovolador Silver badge

    No sh*t

    Sherlock. See title.

  6. Anonymous Coward
    Anonymous Coward

    Lock-in, pay-out

    I was reminded recently of the financial crisis of 2008 onwards. One of the features then was the intertwined nature of investment banking with retail banking. Everybody was happy with this in rising markets when the investment gains were cross-subsidising retail. Not so much when the investments went bad on such a scale that Govts had to step in to prop the banks up.

    I can see a scenario now where some (all?) of the US tech giants get burnt on AI investments and need to cover their losses by squeezing their "retail" customers - in this case those rather badly advised public bodies over here that are locked in. So the UK (local or national) taxpayer will end up paying that bill for them.

    1. Doctor Syntax Silver badge

      Re: Lock-in, pay-out

      There's a further point of comparison.

      Back then there was an assumption that an economy could exist which was able to ignore the inflationary effects of rising house prices to maintain low interest rates.

      Nor there's an assumption that an economy can exist which is able to ignore the amount of money already burnt on AI data centres to provide a return on investment.

  7. Anonymous Coward
    Anonymous Coward

    UK burned by Brexit again

    Tech independence and data sovereignty would have been much easier to achieve if the UK could have joined the EU in developing solutions which each European nation could deploy domestically. Scale matters.

    But someone just loved their ring a little too much, and one of the ironically-named results is Palantir, which just happens to report back to an aggressively interventionist dark lord in a foreign land.

    There's a lesson about unity in there, brought to us by one of the greatest British writers of all time.

    1. VoiceOfTruth Silver badge

      Re: UK burned by Brexit again

      This is nothing to do with Brexit. You may have noticed that the entire EU is in the same boat.

      The EU's efforts to kick out the American horse of Troy so far have amounted to very little.

      1. Anonymous Coward
        Anonymous Coward

        Re: UK burned by Brexit again

        The UK has no bandwidth to push allies to actually solve the problem because it chose to go it alone.

        Sure, MPs can win votes giving speeches complaining about the problem, but it takes software engineers to actually solve it. Scale helps.

        1. DS999 Silver badge

          Re: UK burned by Brexit again

          Just because the UK isn't part of the EU doesn't mean they couldn't partner with the EU for solutions to de-USify themselves. They would just have to accept that any EU wide solution that was developed would have to be operated under EU law which would mean it couldn't be located in the UK or operated by UK based companies.

          1. Anonymous Coward
            Anonymous Coward

            Re: UK burned by Brexit again

            But that involves a lot more friction than pushing fellow EU members to fund a common code base which each nation can deploy on their own, sovereign hardware.

            Only some of it is from scratch. Particularly, the national security related stuff which competes with Palantir.

            Many existing use cases for everyday software are already being addressed, they just need funding. Take, for example, Nextcloud or desktop Linux. The cost to turbocharge development under the helm of longtime open source leaders and European universities is a drop in the bucket compared to what Brussels spends on a regular basis.

            As they say in politics: if you're not at the table, you're on it.

            The UK is not at the table.

            1. VoiceOfTruth Silver badge

              Re: UK burned by Brexit again

              The EU is better off without the UK. The UK would only act as the USA's proxy. The EU knows this, even though it won't state it. De Gaulle did.

    2. ITPerson
      Stop

      Re: UK burned by Brexit again

      So how long is Brexit to blame for things?? When has it been long enough???

      1. Anonymous Coward
        Anonymous Coward

        Re: UK burned by Brexit again

        I guess as long as Gordon Brown, Thatch or Tony Benn still get blamed for things.

        Closing down most UK Nuclear and abandonment of technical known how/research (remember Dounreay) and a ‘Dash for Gas’ now also seems ridiculous for Electricity Generation from 1990’s and 2010’s Tories…. Esp. This week where Rolls-Royce got a £1/2bn bung for SMR’s.

        Much that’s shit in the US can be tracked back to Regan Era who was Thatch’s Buddy.

  8. VoiceOfTruth Silver badge

    The UK is owned by the USA

    This is already a national security issue, and should be treated as one. But it won't be, because 'our' politicians see themselves as petty princes in the American kingdom. Britain is a rump state.

    The USA has built profiles on every British politician. This is aided by the self-inflicted security hole of granting the USA unfettered access to all of parliament's email, files, data, address books. In times gone past, this would have been seen as a security issue.

  9. WSWS

    "Politicians across the spectrum" is Labour and the Greens, is it?

  10. Anonymous Coward
    Anonymous Coward

    Back To The Future?

    Link: https://www.theregister.com/2026/04/13/digital_sovereignty/

    Quote: "....you need to partner with reliable open source providers to run an IT stack that you, not Trump, control...."

    Once upon a time, CIOs were wedded to having their own data centres!

    Once upon a time, CIOs were wedded to having their own back up data centre!

    Of course, the software running in those data centres might come from SAP, or ORACLE, or IBM........

    .....but the CIO could look in the mirror and smile and say "At least I control the IT stack which operates my company".

    That was then......and now we get Steven J. Vaughan-Nichols telling us that this retrospective picture MIGHT HAVE BEEN CORRECT ALL ALONG!!!

    Back to the future!

    Sigh!!

  11. Anonymous Coward
    Anonymous Coward

    And Cloudflare Is Checking Up On Me Again!

    Please stop!!!!

  12. drankinatty Silver badge

    We gave up our sovereignty

    It wasn't long ago when every government entity and each company owned it's own hardware, handled its own networking, hosted its own web server, ran its own mail host, hosted its own databases, and had some expertise somewhere in the organization over what it took to make it all work and likely employed a few IT "professionals" who while not getting rich, made enough to put a roof over their heads, a car in the garage, food on the table and clothes on the kids. We were all sovereign at the time. Many of the vultures here recall.

    But as with the most common ills of the past 30 years, the hype-machine started extolling the virtues of cloud storage, governments, companies and individual were lured to keep their documents and photos on somebody else's hardware. The same play was made for e-mail and web hosting and finally complete IT solutions all with the promises of huge savings in IT spending. Each time promising expertise in all areas of tech where the cloud could do it better, faster and more secure relying on economies of scale to create magic savings and improved security. Soon governments and companies fired or laid-off their IT staff, removed their hardware and over time lost all "corporate knowledge" of how to make it all work.

    The articles in The Register provide a daily chronicle reminding us all of there being no more truth to the promises of IT savings or data security by Big Tech than there was in the orange lunatic portrayed as Jesus claiming he thought the depiction was of him as a doctor. We've done it to ourselves.

    I'm not sure data sovereignty necessarily means our Big Tech Bros here against your Big Tech Bros. The problem seems to have been the Big Tech Bros all along, regardless of where they reside.

    Learning is expensive, and the best lessons -- are very expensive, but if we've learned nothing over the past 30 years in this area, that turning your hardware, software and data over to companies that over promise and under perform, then there is still some expensive learning to take place. Instead of rushing to turn every part of your IT over to someone else closer to home, perhaps the better and more sovereign path is to buy only those services you can't provide for yourself, and keep the rest in-house -- just as we all used to do it.

  13. Richard Pennington 1

    It was ever thus

    I'm retired now, but more than once I joined a vibrant UK IT company doing interesting techie stuff ... only for it to get taken over and turned into a UK sales arm for a US firm.

    Being as introverted and as techie as I am, that was never what I signed up for.

  14. Jeff Smith

    Important to note

    Rectifying this is going to cost an absolute fortune, and take a very long time.

  15. Anonymous Coward
    Anonymous Coward

    85 years late

    > Open Rights Group says years of reliance on US giants have left Britain exposed

    "Reliance on US giants" is purely the natural result of Britain being, de facto, a US colony, along with the rest of Western Europe.

    Lend-lease did the trick for the UK, as the Marshall plan did for the continentals.

    For their part, the US were hedging both ways, with Germany's side of the war being financed and enabled, to a large extent, by US capital (hello Mr Prescott Bush) and companies (the likes of Ford, the owner being a fervent fascist and raging antisemite, or IBM, who supplied the computers that processed the numbers tattooed onto the arms of my grandfather's family and many others).

    So, isn't it a bit late to start acting all surprised?

  16. Anonymous Coward
    Anonymous Coward

    These Americans

    Not our friends

    Not our allies

    Not our long term future

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon