An exception is possible if after a risk assessment and the determination that no state secrets may be exposed, a government body decided to use a commercial cloud provider.
The private cloud providers list is then filtered by whether or not their country of origin / incorporation, or effective control, has an effective cyber-control program it runs against the Netherlands or against Dutch interests. This arguably includes corporate espionage programs.
* central government departments
* local authorities
* the armed forces
* the NHS
* the emergency services
* GP surgeries
* state-funded schools
looks quite critical to me
The UK made a different choice.
[1] https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-...
Doesn't seem that critical to me. Important, but doesn't pass the sniff test of "is this a matter of national security" that would justify self-hosting ultimately slowing down development and making it more expensive and in effect less feature-rich for taxpayers
EDIT the API docs suggest this is used for sending formal Notifications en-masse rather than mission-critical comms
It's not likely to be anything critical.
I stressed a bit when after a year I was trying to find the paper letter, until I eventually realized xD
As an IT professional, I would question whether that makes sense.
But what do I know? I'm sure the people who run the country -- people of the calibre of Liz Truss, no less -- know what they're doing!
If you made a democratic poll and asked people, "would you like national data stored in your own country or elsewhere?" there would be no ambiguity in the answer. And that would not be an "uninformed" poll, since matters of public trust should direct policy and not technics and economics.
Of course there are good reasons for outsourcing, like geographical diversity, but those raise a new and I think separate questions like "Who would you trust with our backups?". That nuance of examination seems to be missing in the UK at present.
And if you ask the question "how much more would you pay to host UK data in the UK with UK owned providers only", you get the answer £0. So it doesn't happen.
[0] https://www.ncsc.gov.uk/news/ncsc-warns-of-emerging-threat-t...
In the UK government services go through information security classification to determine what level of security is needed, with the most confidential stuff still being self-hosted.
I assume most countries operate that way.
https://www.civilserviceworld.com/news/article/cabinet-offic...
https://www.fgould.com/uk-europe/articles/cutting-the-cost-o...
Good: Not so much
Unfortunately, cloud provision isn't very competitive and is very US/China centric.
I was at a talk recently around how one of the UKs major infrastructure providers was building their architecturrle, and I was pretty freaked by the level if vendor lock in.
Would love to see more governments viewing this as the security risk it is, but I'm not holding my breath.