Why G-Cloud 15 must move beyond hyperscaler lock-in

Why G-Cloud 15 must move beyond hyperscaler lock-in

Mark Boost, CEO, Civo, argues that G-Cloud 15 must move beyond hyperscaler lock-in if the UK is to strengthen national resilience, protect sovereign data and support domestic cloud providers.

The UK Government Commercial Agency has launched G-Cloud 15 as an open framework under the Procurement Act 2023, targeting an estimated £14 billion in public sector cloud spending over its four-year lifespan.

In the Government’s press release, it is billed as “the most significant upgrade to the UK’s public sector cloud procurement framework since its inception in 2012… representing a step-change in how the government buys cloud technology.”

Whitehall is also framing the framework relaunch as a triumph for domestic innovation, highlighting that 90% of suppliers on the framework are SMEs.

However, while this sounds good on paper there is a systemic reality which also needs to be addressed. And that is that cloud spend has been flowing almost exclusively to a small oligopoly of US hyperscalers for years now.

Promoting opportunities for small British businesses is a great thing to say. But in reality, Amazon Web Services and Microsoft Azure together control roughly 70 to 80% of the UK public cloud market, with Google Cloud commanding 5 to 10%.

Public sector buyers have continuously given legacy contracts to the foreign tech giants. It has drunk the US hyperscaler Kool Aid at the expense of the UK economy and its security.

The persistent confusion between data residency and data sovereignty has only made the issue worse. There has been an assumption that simply storing data on local hardware ensures protection.

This is just wrong and amounts to ‘sovereignty-washing’. Physical geography is irrelevant if you are simply renting data centre space in the UK. It does not clear foreign-domiciled providers from the extraterritorial reach of legislation like the US CLOUD Act. This means foreign authorities can demand access to UK data.

That means that when a public sector entity uses a US hyperscaler, its sensitive assets and citizen data are exposed to external forces. This is particularly dangerous in a theoretical geopolitical crisis. It effectively gives a foreign power a kill switch over the UK’s critical national infrastructure.

And not only does defaulting to foreign monopolies increase security risks but it also leads to a ‘sovereignty tax’. By this I mean a compounding penalty of aggressive technical debt, vendor lock-in, interoperability barriers and punitive egress fees. These all make exiting these platforms very hard.

As a result, public sector bodies are operating under an era of digital feudalism: they are forced to act as perpetual serfs who pay a continuous tribute to foreign tech lords.

And this has a massively damaging effect on the country as a whole because high-skilled engineering jobs, commercial value and the IP generated by British taxpayers heads across the pond rather than staying in the UK.

The UK already has homegrown providers which are capable of delivering full-stack cloud and AI infrastructure without that foreign risk. What is missing is procurement bravery.

The G-Cloud 15 framework is a good start. But if the UK is serious about national resilience, Whitehall must look past symbolic gestures. We must back our own and actively choose domestic alternatives that keep our data safe and under our own legal control.

Browse our latest issue

Intelligent Gov.tech Issue 01

View Magazine Archive