The company that basically runs it for the government is being sold to an American investment company, which brings with it obvious national security risks.
The company that basically runs it for the government is being sold to an American investment company, which brings with it obvious national security risks.
There's a lesson to be learnt here, extending beyond digital infrastructures.
The Dutch government should have outsourced DigiD hosting to SURF [1] which already had extensive experience with cloud services and is virtually immune to foreign influence.
They also adore the US (as an example Mark Rutte, the current NATO boss was their foreman and prime minister for a decade) so dependency on the US was never a problem for them until 2025 when Trump turned against his allies.
Then again, they never found out about the Crypto AG communications backdoor (https://en.wikipedia.org/wiki/Crypto_AG) until 2018 as far as I know. Or they did know but since it's CIA they allowed it.
Cutting off updates would leave devices insecure.
Do some devices not have remote disabling as a security feature?
A lot of devices and software store or backup to cloud servers.
Now (2023/2025) another two have been found.
Cisco equipment has been intercepted and implanted in the past.
So definitely "the community" can find things, sometimes it just takes ages.
And to add to your Crypto AG, Anom was also a nice example of the sting like this.
If the government owns the infrastructure, but outsources the day-to-day running to a company that's one thing. But if the infrastructure is owned by the third party then that's a lot harder to deal with.
This is still very problematic. To be honest, even using foreign hardware or propietary software is problematic. But you should reduce dependence as much as possible because it is a huge vector that should the foreign government decide to turn on you openly or secretly, it could bring you down before you have a chance to detect what is happening. I believe wars between developed countries will operate at this level (i.e. by targeting foreign dependency chains whether it be national systems for id or simply cutting undersea cables)
Recovering from "Your critical national infrastructure is physically owned by someone else" is much trickier.