Andrew’s right, of course:

Holding NHS IT to ransom is nothing new sadly, Friday was just a different bunch of people doing it. By me: https://t.co/tcF6b3znbp pic.twitter.com/GMLIA7cV0Z

— Andrew Greenway (@ad_greenway) May 13, 2017

And so is this:

Government not negotiating extended-extended XP support is *not* the scandal, it’s the *10 years* spent not upgrading…

— gwire (@gwire) May 13, 2017

Decisions made by government technology leaders a couple of years ago about extended-extended XP support were never about whether it’s right to spend £5.5 million on making sure the NHS is resilient. No-one involved would have questioned that.

It was whether spending that £5.5 million in that way was actually going to produce the right outcomes.

Would it lead to a serious focus on moving to more modern systems? Would it support approaches that are better for security and better for users? Would it ensure properly targeted protections for that minority of systems where that was genuinely complicated (rather than just hard)?

It was very clear to the wide group of people involved in the decision that it wouldn’t. It would simply allow the necessary changes and decisions to be kicked even further down the road, while we continue to be dependent on software that is ever harder to protect.

Collective purchasing and cross-government deals are a great idea when they’re both efficient and effective: when they make it cheaper and easier to buy the right things. They can be disastrous when they make it easiest to do the wrong thing, like not upgrade your computers from a 14 year old (now 16 year old) operating system.

People will take the path of least resistance, ignoring or externalising their risks wherever possible. Making that cheaper may make for a good sound bite but it doesn’t make for good results.

What’s necessary when you take away that support is follow-through. That requires leaders who recognise those risks, and have or find the expertise to make and follow a plan to mitigate it. Who don’t think it’s okay to not understand this stuff.

There are many systemic changes that are needed to manage issues like this.

It starts with recognising that software really is core to operations, but it’s at least as much liability as it is asset. That means you need to understand your “balance sheet”, get to grips with your supply chain, and invest effectively.

It requires recognising that no software system is perfectly secure, but that a security stance that blocks patching and updates is the worst option.

It involves structuring organisations in a way that allows these issues to be dealt with decisively, effectively and at pace.

There are plenty of areas of the NHS that need more financial investment. It may be that the way costs have been sunk means that this area does need some more short term funding, but really this is about right investment not more investment. Investment in doing the right things and doing them right, not throwing money at the problem.

If we’re going to politicise the fall-out from this situation–and our politicians absolutely ought to be discussing it–let’s make the debate about how we get the right behaviours, not whether we should have paid for a specific support contract that almost certainly wouldn’t have protected us here.