A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist.A Guardian investigation has surfaced a 2017 document signed off by then City of London police commissioner Ian Dyson, who also held the title of senior information risk owner for the entire country. That document reviewed 15 risks tied to moving police data onto Microsoft Azure. The files in question include criminal records, victim statements, internal emails, information from more than 40 UK police forces, and some material exceeding standard “official” classification, meaning it may sit at “secret” or “top secret” level.The assessment was clear. It said Microsoft software had vulnerabilities that could eventually be exploited by cybercriminals and other attackers. It also pointed to a more specific and worrying risk: “US government insiders.”“In doing so, officers accepted that “US government insiders” would be able to see the data, and that it could be “transmitted worldwide”, with “the extent of this … unknown”. According to five specialists who reviewed the Guardian’s findings, the risks identified in that document persist today. Almost every UK police force now depends on Microsoft Azure, and the UK government spends at least £1.9bn on Microsoft software each year.”” states The Guardian.“There is a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers.” reads the document.This wasn’t a general concern. It was a specific threat identified eight years ago by the official responsible for data-handling standards in British policing. Five experts who reviewed the same assessment for The Guardian said the risks are still relevant today.The proposed protections were fairly simple: use Microsoft’s built-in encryption, keep servers updated and let individual police chiefs decide whether to use the service. But experts interviewed by The Guardian, including Microsoft engineers, said encryption does not prevent Microsoft employees from accessing the data. They also said it would not necessarily prevent the US government from obtaining it.Which is exactly the geography problem Dave Michels, a researcher at Queen Mary University of London’s Cloud Legal Project, pointed to. Microsoft’s cloud infrastructure spans over 100 countries, and pieces of a single file can end up stored across several of them, Sweden to Ethiopia, for instance. Microsoft has started offering EU customers assurances that data stays within European borders, but Michels called the whole focus on data location somewhat beside the point, since the people who can access the data matter more than the servers holding it.Legally, the situation becomes more complicated. Under the US CLOUD Act, American authorities can require US-based companies to provide data they control, even when that data is stored outside the United States. In some cases, companies can also be prevented from telling the customer about the request.Microsoft, Amazon and Google have said they would challenge such requests when possible. But, as international law professor Douwe Korff pointed out:“The risk is obvious, even though the providers of the cloud and the government both have an interest in talking it down” Douwe Korff, professor of international law told The Guardian.Which brings us to the part that reads like a contradiction under pressure. Police officials told the Guardian the data stays in the UK and that Microsoft can’t share it without permission. Microsoft, meanwhile, told Police Scotland back in 2023 that data can leave the UK and that it cannot guarantee data sovereignty. Those two statements aren’t compatible, and nobody seems eager to reconcile them out loud.Every single UK police force has now put its data, wholly or partly, on Microsoft’s cloud, despite all of this being on record since 2017. One former senior policing source summed up the current state of visibility pretty starkly:“All the security guys I worked with when this policy came in expected a big breach by now, and we know it will take that to change the police’s position.” a source told The Guardian. “The truth is, however, the level of logging and information in the cloud systems would not necessarily tell us if there was a problem. We really don’t know if the data has been breached or not.”That’s the key point. It’s not saying, “we checked and everything is fine,” or “there has been no incident.” It’s saying that the available logs and monitoring might not detect a breach even if one happened.For anyone responsible for sensitive data in a large cloud environment, that’s an important warning. In a security assessment, saying “we would probably know if something went wrong” isn’t enough without evidence that the monitoring can actually detect it.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, Microsoft Azure)