The Police Service of Northern Ireland (PSNI) carries one of the most sensitive remits in British policing. Its public internet footprint is also the most hyperscaler-entangled of any force in the UK: 128 separate DNS records point to Microsoft, Amazon or Google, against 184 in total – 70% of its routable footprint.
Computer Weekly’s analysis finds that the PSNI, like almost every force, routes its email and much of its infrastructure through US-controlled services while holding UK sovereign infrastructure at the same time.
Of the 48 police forces analysed, 47 (97.9%) have at least one connection to a hyperscale cloud provider. And 46 (95.8%) route their email and identity through Microsoft 365. Microsoft, in other words, is not one supplier among many for British policing. It has achieved default status.
This article – the latest in a series that focuses on public sector hyperscaler dependence, which has also looked at UK councils and NHS trusts – uses publicly available DNS records to map which outside companies UK police forces connect to. It finds a service that has apparently standardised on a single US hyperscaler – and, in doing so, has entangled routine criminal justice data flows across two jurisdictions.

The Microsoft default
The concentration is starkest in email. Of 48 forces, 46 route their mail through Microsoft’s servers; only two – the Ministry of Defence Police and Police Scotland – do not, and none use Google Workspace. Measured by routable infrastructure – the DNS records that actually point to a server, rather than text notes used for email authentication – Microsoft accounts for 773 records, against 161 for Amazon and two for Google.
The comparison with Google and Apple is instructive. Google’s presence in policing is almost entirely about authorising email, not hosting it: 21 of its 23 records are SPF notes that say who may send a force’s email. Apple, which appears in a raw count of the data, hosts nothing at all: all 15 of its records are verification tokens for device management. Microsoft, by contrast, dominates email and hosting – roughly five times that of Amazon and nearly 400 times that of Google on the infrastructure police systems depend on.

The sovereignty tangle
The finding that matters most is not the size of Microsoft’s share but the shape of it. Some 46 of 48 forces sit in what can be characterised as a “tangled hybrid” posture: dependent at once on UK sovereign infrastructure and on US-hosted services that fall within the reach of the US Cloud Act. Only two forces escape that posture. Derbyshire is the sole force that is fully US-dependent, while the Ministry of Defence (MOD) Police is the only one that is fully sovereign, running Cloudflare and MoD-owned infrastructure with no hyperscaler at all.
For an institution that holds some of the most sensitive personal data of any part of the state, that tangle is not an abstraction. Every force that routes its email or its systems through a US hyperscaler creates a data flow that can, in principle, be the subject of a US disclosure demand. Policing has not, on this evidence, made a conscious decision to avoid that position – it has drifted into it.

Two outliers
The Ministry of Defence Police is the clearest counter-example. Its footprint is small – around a dozen records – but it is entirely hyperscaler-free: Cloudflare for edge delivery and MOD-owned infrastructure, with no Microsoft, Amazon or Google anywhere in its public DNS. It shows what a sovereign posture looks like when it is designed, rather than defaulted into.
Gloucestershire is a different kind of outlier: 280 of its 303 third-party records resolve to IP addresses registered to one Dutch company, BusinessCom, an IT and telecoms distributor that sells through resellers. It is a reminder that the registry records who holds an address block, not who delivers the service – here, there is almost certainly a UK supplier somewhere in between.

A telecoms-and-hosting long tail
Beyond the hyperscalers, policing’s public DNS is dominated by connectivity and hosting. BT is the largest single third-party dependency, at 131 records across its consumer and business ranges. Virgin Media’s cable netnames account for roughly 68 more, and Nominet – the registry that runs .uk – accounts for 36.
A further 60 records sit on an unnamed UK network that the registry does not attribute to a company. The forces’ own infrastructure is comparatively thin: 147 records, or 3.8%, are police-owned, led by Merseyside’s “merseyconstab” netname at 43 records, and Surrey and Sussex – which run a long-standing shared services collaboration – at 30.
The methodology behind the data
This analysis began with the 48 published police force domains: 43 territorial forces of England and Wales, Police Scotland, the PSNI, and three national forces – British Transport Police, the Civil Nuclear Constabulary and the Ministry of Defence Police. For each, it collected the public DNS: root records, a sweep of a subdomain dictionary that includes common policing systems, and passive Certificate Transparency logs. That produced 3,822 individual DNS records, each one a “node” in the analysis.
We then mapped each IP address to its registered owner through RDAP, the registration data protocol used by the regional internet registries, and classified each record as a hyperscaler (Microsoft, Amazon or Google), another cloud/CDN/SaaS provider, a third-party host or ISP, or police-owned infrastructure.
Two limitations matter. TXT records are the text notes a domain publishes for email authentication and third-party domain verification; they carry text rather than a destination, so they cannot resolve to an owner, and the 1,234 of them sit outside the infrastructure figures. Dorset, for example, shows 553 “nodes”, but 92% of these are TXT records, so the analysis leaves them out. The hyperscaler figures are a lower bound, and the unresolved records could only add to them. The analysis makes no causal claims, and it does not compare policing against the NHS or local government.
No police getaway route
British policing has no obvious exit from a single-supplier default. The national frameworks that keep it there renew on a rolling basis, through a procurement system under growing pressure, and every renewal narrows the window in which a force could run a competitive test of its platform. The analysis does not suggest police forces chose Microsoft badly. It may, however, suggest that, for most forces, there’s no evidence they chose at all.
Security consultant view: Microsoft dependency and fragmented cloud leave UK policing exposed
We ran our analysis past Owen Sayers, an independent security consultant and enterprise architect with over 20 years’ experience in delivering national policing systems. Here’s what he had to say:
Q: Does the near-total standardisation on Microsoft 365 match your experience of police infrastructure, or does it overstate the real exposure?
A: Since the NSIRO risk paper of 2017 authorised use of Office 365, forces have spent millions on Microsoft services, and your findings fully reflect what I would now expect to see.
In truth, it is very hard to overstate the degree to which UK policing is using and is now dependent upon Microsoft infrastructure, and these findings demonstrate that in quite an alarming way.
The means and speed by which Computer Weekly has mapped the UK police IT estate is in itself quite alarming, even though this requires only basic tools and some DNS skills. It is likely that foreign state actors and hackers have comprehensive maps of the UK policing public footprint and can now use that to find ways to compromise or interrupt those services
Q: Are there police-owned or national (PNN/PDS) ranges our keyword matching may have missed, that would change the 3.8% on-premise share?
A: To the best of my knowledge, most PNN ranges are now defunct, whilst PDS is not a force and should not be expected to be directly operating policing systems.
I would not be surprised if the publicly reachable share of on-prem policing systems is as low as 3.8%. The questions arising are: how big is the on-premise estate of forces now, and is it sufficient to meet Civil Contingencies Act 2004 obligations if Microsoft Cloud goes offline, and just exactly why would any on-premise services be exposing themselves to the internet? Prior to Microsoft adoption, these would never have been visible – they were nationally managed.
The risk of local force tenancies on Microsoft – all operated with local resources – cannot be overstated. It is, in fact, the direct inverse of the risks that cloud was supposed to address – local teams with limited resources running complex infrastructure assets.
Prior to Microsoft cloud adoption, a national provider managed all gateways, and they actually did so very well. Now you have found hundreds of possible gateways, and the likelihood of one being insecure is vastly greater than it would have been in the previous model.
Q: Is ‘tangled hybrid’ (UK + US Cloud Act exposure) the right framing for the sovereignty risk, in your view?
A: It’s an excellent term to apply. The complexity you have identified makes it very unlikely that any single person or body can hold a map of the current UK policing estate, something that was rigorously and centrally pointed out prior to cloud adoption.
What you have shown is a mass of connections, each one of which realistically presents a possible gateway to be protected. Only one of those needs to be misconfigured or poorly watched for all upstream systems to be compromised, and that reflects a highly risky position for our national policing systems and data.

