Google claims US government is too reliant on unsecure Microsoft products
The tech giant suggested it might be time for the government to rethink its approach to procurement


Google has called on the US government to rethink its practice of favouring Microsoft technology when procuring technology, accusing the company of having a reputation for cyber security vulnerabilities and poor user perception.
Repeated cyber security breaches on US government systems have interrupted vital work and cost the taxpayer billions of dollars, said Google Cloud’s Jeanette Manfra, senior director of Global Risk and Compliance in a blog post.
Manfra, who has spent 20 years in the public sector, most recently as the head of the Cybersecurity and Infrastructure Security Agency (CISA)’s cyber security division, claimed that the government was at a disadvantage due to its approach to procurement, and an over reliance on Microsoft products.
She pointed to a recent Google poll of 2,600 US government workers, which found that the majority of those surveyed reported being “very” concerned about cyber attacks against their employers in the coming years. Most of those surveyed (80%) also said that the recent attacks, like the SolarWinds breach, has them concerned about their personal data and privacy, and that of their family members.
Results also showed a lack of satisfaction with legacy software, with over 50% of government workers stating that there are other products or services that could help them do their jobs better.
According to Google's data, around 84% of D.C. metro government employees primarily use Microsoft products at work, including Word, Outlook, Teams, and OneDrive. This is confirmed by another recent study by Omdia which found 85% of government employees use Microsoft productivity software.
“This reliance on a single software suite might suggest that these products are safe and secure, but the Public Opinion Strategies survey found that more than half of all respondents said that the government’s reliance on these Microsoft products actually made the federal government more vulnerable to hacking or cyber attacks,” said Manfra.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
However, a US Senate report released last August detailed that seven out of eight federal agencies had failed to protect critical data due to inadequate cyber security policies, rather than problems with their systems. It stated that most agencies failed to install security patches quickly enough, and warned that at least seven out of the eight agencies are still using legacy systems that have reached end of life, and no longer receive vendor security patches.
When survey respondents were asked why their employers used Microsoft services, 45% said the reason was because their employer has always used those products and services and doesn’t want to change, while 55% said because they are the most effective at helping them to do their job.
RELATED RESOURCE
The state of SD-WAN, SASE and zero trust security architectures
Be a leader in the deployment of zero trust, SD-WAN and SASE
FREE DOWNLOAD
Manfra said that with so many respondents reporting they're dissatisfied with their legacy IT solutions, it may be time for the government to rethink its approach to procurement.
“As governments work to meet the demands and preferences of their constituents—and their employees—it’s clear that there’s an overreliance on legacy solutions, despite a track record of cyber security vulnerabilities and poor user perception,” she added.
IT Pro has contacted Microsoft for comment.
Despite the tech giant criticising Microsoft for its cyber security, it isn't immune to these kinds of threats either. In February, it had to resolve a critical security flaw in Android 12 with its February 2022 Android security update. In the same month, the company had to release another wave of patches for seven high-severity issues affecting Chrome, including one zero-day vulnerability being actively exploited.
A report highlighted in January that Google Drive accounted for the most malware downloads in 2021, taking the top spot from Microsoft OneDrive. It accounted for 37% of all malicious downloads last year, while OneDrive fell to second place with 20% of downloads.
Google Cloud also revealed in November last year that 86% of compromised Google Cloud Platform instances in 2021 led to cryptocurrency miners being dropped into customers' environments. Its customers were heavily targeted by attackers who were attempting to leverage the high levels of compute available to them without having to pay for it.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
UK cyber experts on red alert after Salt Typhoon attacks on US telcos
Analysis The UK could be next in a spate of state-sponsored attacks on telecoms infrastructure
By Solomon Klappholz
-
Healthcare data breaches are out of control – here's how the US plans to beef up security standards
News Changes to HIPAA security rules will require organizations to implement MFA, network segmentation, and more
By Solomon Klappholz
-
The US could be set to ban TP-Link routers
News US authorities could be lining up the largest equipment proscription since the 2019 ban on Huawei networking infrastructure
By Solomon Klappholz
-
IBM: Data governance for data-driven organizations
whitepaper Master your data management
By ITPro
-
US government IT contractor could face death penalty over espionage charges
News The IT pro faces two espionage charges, each of which could lead to a death sentence or life imprisonment, prosecutors said
By Ross Kelly
-
US identifies and places $10 million bounty on LockBit, Hive ransomware kingpin
News Mikhail Pavlovich Matveev was linked to specific ransomware attacks, including a 2021 raid on the DC police department
By Rory Bathgate
-
Breach at US Transportation Department exposes 240,000 employee records
News An investigation is underway into the breach, which affected former and current employee data
By Rory Bathgate
-
IRS mistakenly publishes 112,000 taxpayer records for the second time
News A contractor is thought to be responsible for the error, with the agency reportedly reviewing its relationship with Accenture
By Zach Marzouk