decrypted · 27 september 2026 · ransomware and cybercrime · vulnerabilities and patching · digital sovereignty

The Dutch build an exit from Microsoft, and Microsoft corrects its evidence to MPs

The Dutch government is building its own desktop, and the reason is a decision made in Washington. The Ministry of the Interior's DAWO initiative, short for Digitaal Autonome Werkomgeving Overheid, is a plan, reported this week, to build an alternative to the government's Microsoft workplace with a custom system built on NixOS, a Linux distribution. It is a pilot, not a rollout, but it poses a question every UK director should be able to answer: if a foreign legal order told your supplier to switch you off, what would you do on Monday?

What the Dutch are building

DAWO covers the whole workplace, not just the operating system: a NixOS desktop, office and collaboration software, cloud storage, backups, device management and AI tooling. Three state IT providers, SSC-ICT, DICTU and DUO-ICT, received the mandate in July. Eight municipalities are trialling it through their association, and the team intends a first stable version next year.

NixOS was chosen, according to It's FOSS, because it is a Dutch project that no company owns or controls. There is no vendor to sanction, buy or lean on. Think of it as owning the freehold rather than renting a flat where the landlord, and the landlord's government, can change the locks.

The trigger, and a correction to Parliament

It's FOSS says the catalyst was the US sanctions on the International Criminal Court in early 2025, which cut its chief prosecutor off from Microsoft services. The detail of what happened is disputed, and this is where UK readers come in. On 11 February, Microsoft's Hugh Milward told the House of Commons Business and Trade Committee that disconnecting the sanctioned official was the ICC's decision, not Microsoft's. The Register reports that Microsoft later apologised to the committee and asked for the record to be corrected. Dutch press reporting, also cited by The Register, says Microsoft told the ICC to cut off the prosecutor or lose email for the whole organisation. That is press reporting, not a finding.

What the defender sees, and the design lesson

In this scenario the defender sees nothing. There is no alert, no malware and no CVE. The failure is a notice from a supplier, arriving through a legal channel, in a column of the risk register that nobody filled in. Secure by Design asks that failure modes are designed for, and "supplier withdraws service for legal reasons" is a failure mode like any other.

The design decisions that prevent the surprise are dull. Keep your data in formats you can export. Do not let email and identity share one dependency. Rehearse the exit before you need it. The Dutch timetable shows the price: a stable release is a year away, and eight municipalities is a trial, not a proof. Sovereignty is not the same as security either. A home-built stack still needs patching, certification and people who understand it.

A director need not leave Microsoft to learn from this. Opinion, not advice: list the three services whose withdrawal would stop you trading, work out who could lawfully order them off, and ask each supplier in writing what it would do if told to. If the answer is vague, that vagueness is your finding. And when a supplier gives evidence to Parliament, read the corrections as carefully as the evidence.

Also this week

WordPress core, patched and then attacked. WordPress 7.1.2 fixes CVE-2026-87902, an unauthenticated flaw in how core chooses a page template, scored 9.2 under CVSS 4.0. WordPress says the fix is backported to every branch still eligible for security fixes, currently through 4.7. Code execution needs the right conditions: Patchstack says an active theme with a top-level directory starting "page-" and PHP running with register_argc_argv enabled, which it says is the default in the official PHP Docker images and in cPanel environments on PHP below 8.5. Help Net Security reports attackers were writing PHP files to disk within days of the patch, and public scanning tools exist. If an agency or supplier runs your site, ask whether the update landed, not whether it was scheduled. The Secure by Design point is that a fix nobody applies is not a control, which is why WordPress ships background updates and why they should be left switched on.

ShinyHunters and the firewall that read too literally. Google's Mandiant team reports that the extortion group, tracked as UNC6240, has renewed mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273, which Oracle fixed in June. The trick is one character: requesting /%50SEMHUB/ instead of /PSEMHUB/. Some firewall rules matched the path before decoding it, so they missed it, while the server decoded it and routed it to the vulnerable component. Google names higher education, healthcare and government among the sectors hit, though it does not name UK victims. The lesson is that a firewall rule is a bandage, not a patch. UK PeopleSoft users should apply the update and search access logs for encoded variants.

Sources

If you want a second pair of eyes on which of your suppliers could be switched off, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.