Saturday, 21 March 2015

The system is fine. It's the users that don't work

It has fallen to Bryan Glick, the estimable editor of Computer Weekly, to perform the first post mortem on the Rural Payments Agency's (RPA) computerised Basic Payment Scheme (BPS) which was discontinued yesterday and replaced with paper – "successive software releases failed to resolve the problems with the mapping tool".

We have known for two years that Mr Mike Bracken, the executive director of the Government Digital Service (GDS), was heavily involved in the development of BPS. "I'm on the Board", as he told us, "I'm trying to help them every week ... GDS will be working very closely with them ... it's going to help us deal with Europe in a different way, and quite rightly we're building it as a platform. It's going to be another example of government as a platform".

Mr Glick reveals that in addition, Mr Liam Maxwell, the Government's Chief Technology Officer is also the senior responsible owner of BPS, "overseeing progress", and that this is a mark of "the importance of RPA to the GDS strategy".

These are highly respected people:
Highly respected, but it doesn't seem to have helped with BPS.

Perhaps the cheerleaders who voted for Messrs Bracken and Maxwell should have looked harder at that GDS strategy, which was heavily criticised at the time by at least four professors:
  • The professors deemed the strategy to be too flimsy, the detail was missing, it was going to be of no practical assistance to a large local authority or, as it turns out, to RPA.
  • The strategy underestimated the complexity of ultra-large-scale government systems, it ignored the relevant academic studies that might have helped GDS to understand the "complex cultural, political and regulatory environment" in which the "technologically diverse, long-lived set of transactional services" of government have to operate.
  • Against that, the appeal to open source, agile, the cloud and SMEs is "over-simplistic", the professors said. "There are risks that rapidly changing [agile] services will deter the takeup of digital services, not encourage it" and "the [Government Digital Strategy] is remarkably (perhaps alarmingly) silent on the issue of how to coordinate SMEs in project delivery":
  • Both of those problems have been experienced by BPS according to Mr Glick. "The iterative development process was also causing problems for farmers. “The system is frequently going down at short notice for upgrades, making it difficult for farmers and agents ...".  One of the suppliers is a "Belfast company that uses offshore developers in Gdansk, Poland", there are "hundreds of IT experts" also involved and more than 100 products that need to be integrated.
  • "We see little discussion of a concrete and practical change management process to support the 'digital by default' strategy", the professors said, back in January 2013. Two years later, that is clearly still a problem.
And what does Mr Glick say?
... the complex guidelines for the new Basic Payment Scheme (BPS) runs to 84 pages ... the situation differed considerably from the days of SPS [the predecessor system].
Clearly we're not dealing with anything "ultra-large-scale" here. That can't be the problem. Nor can the considerably different situation – there are still only 84 pages and the RPA have had at least two years and £154 million to work on BPS with the assistance of GDS's agile expertise.

"Scalability of the system had already been identified as one of the biggest challenges", according to Mr Glick:
GDS chief Mike Bracken acknowledged the complexity involved in a blog post in December 2014. “It’s not just the policy that’s complex. For this exemplar alone, we’re talking about roughly 110,000 farmers and 1,200 land agents,” he wrote.
By no stretch of the imagination is 112,200 111,200 people a large user base, 84 pages do not make for a complex policy – wait till GDS see the 15,000 pages of our tax code – and if the problem of scalability had been identified why did anyone inflict the system on the poor unfortunate users, particularly GDS, who claim to put the user uniquely first?

Mr Bracken is further quoted as saying:
Farmers themselves are a diverse group of people, whose properties can range from a smallholding to an industrial-scale business. The average age of farmers in the UK is also quite high, with many in their 60s and 70s.
Is Mr Glick complaining or being asked to complain that farmers aren't standard enough? And that they're too old, damn them? And too stupid: "There must have been question marks around how less digitally literate farmers would cope"? And even worse, that they live in the countryside?
Broadband access in remote rural areas was another issue, said ... a report in Farmers Guardian.
The system is fine? It's the users who don't work?

GDS will be working very closely with them ...
It's going to be another example of government as a platform ...

Friday, 20 March 2015


Just another government IT failure, BBC news website:
A multi-million pound government IT system to process EU subsidy payments for farmers has been largely abandoned following "performance problems".

The system will be re-launched next week with farmers asked to submit Basic Payment Scheme claims on paper forms.

Farmers say they have struggled with the £154m website for months ...
Or is it?

Perhaps this government IT failure is special.

DMossEsq's millions of readers will remember that the Government Digital Service (GDS) used to entertain us once a week with their Friday Message. Here's an extract from their message of 11 January 2013, an interview with Public Servant of the Year ex-Guardian man Mike Bracken CBE CDO, executive director of GDS and senior responsible owner of the non-existent identity assurance programme:
Interviewer: Looking back at the end of 2012, what do you think about?

PSotY: I think about delivery. I think it was a brilliant year, and it was capped off in fine style by the publication of the departmental digital strategies. I think getting those departments to make that ambition statement was a tremendous achievement, because it gives us our next step of our mandate. Martha gave us our publishing mandate, and we've now got our transaction mandate. It's going to be fantastic.

Now we can get on with the job of delivering major transformation right across the government's estate: tax, land management, justice, all those departments, all the great stuff to come.

Interviewer: You've just recently come back from Reading...

PSotY: I have. I go weekly now. I go to the meeting of the Common Agricultural Policy Reform Group. It's the RPA. It's the Rural Payments Agency.

Why I'm so excited about that is because they've embraced agile completely. They're going with an agile build out of a whole new programme. That's going to affect everyone in this country, and how they deal with land management, all the farmers, all the people who deal with crops, all the data. It's going to create, I think, a data industry around some of that data.

It's going to help us deal with Europe in a different way, and quite rightly we're building it as a platform. It's going to be another example of government as a platform.

I'm on the Board, and I'm trying to help them every week, and GDS will be working very closely with them to deliver that.

I've already seen a prototype. We're going to be showing that soon. It's really, really exciting. It was created so quickly, such a small amount of money compared to some of the big IT programmes that have preceded it. It's just a new way of working, and RPA have really embraced the whole spirit, as well as the whole emphasis behind the digital strategies.
No wonder he didn't mention DEFRA in his Guardian article earlier this week, Firms still have time to adapt to the digital age – but they're cutting it fine, in which he lectures the ignorant on GDS's putative agile successes.

Or is it?

Thursday, 19 March 2015

Budget travel to Estonia

The UK Chancellor of the Exchequer delivered his 2015 Budget report yesterday.

The media have clocked all the good jokes, please see for example How George Osborne's Budget jokes cost Britain £81m.

A selection of press release jokes issued by the Department for Business Innovation and Skills some time ago without anyone laughing:

All po-faced, they say: "While Tory MPs cheered a series of one-liners aimed at Ed Miliband and Labour, taxpayers will be covering the bills". Taxpayers cover the bills whenever politicians open their mouths. Yesterday's announcements were no different.

And while they were busy being all reproving, the Puritan press missed the bad jokes, see particularly p.27:

1.76 Budget 2015 announces that the digital ambition will extend beyond central government and arms-length bodies, to consider local services. HM Treasury, the Department for Communities and Local Government and the Government Digital Service will collaborate with partners in local government, as the sector develops a set of proposals that will enable more customer-focussed, digitally-enabled and efficient local services in time to inform future budget allocations.

1.77 In this Parliament the government has delivered significant savings from centralising the procurement of goods and services. Budget 2015 announces that, following a successful trial, the government will implement ‘GOV.UK Verify’ – a new way for people to prove their identity online when using government services – across central government. This means that departments will use the same tool for their digital services, reducing duplication. Further, to prevent individual departments paying different amounts to either build their own data centres or outsource this service, the government will create a joint venture to host departments’ non-cloud based servers, which could save up to £100 million.

And p.37:

1.108 Building on these foundations, Budget 2015 announces that the government will transform the tax system over the next Parliament by introducing digital tax accounts, removing the need for annual tax returns. By the end of the next Parliament over 50 million individuals and small businesses will be able to see and manage their tax affairs online.

We have noted this government's green ink fascination with Estonia before, please see for example Francis Maude seeks future in Estonia and RIP IDA – The Road to Estonia.

Estonia provides all or most of its public services on-line. So we are to have digital-by-default in the UK.

Estonia only needs one website. So we are to have one website in the UK for all of central government and for all of our 450 or so local authorities (para.1.76 above), never mind the fact that the entire population of Estonia is little bigger than the London Borough of Ealing.

Estonia relies on issuing everyone with a central government ID. So we are to have GOV.UK Verify (RIP) in the UK (para.1.77 above):

The UK should be more Estonian

Estonians can complete their tax returns in 19 seconds. So we are to have digital tax accounts (para.1.108 above) in the UK:

There will be all sorts of promises about the security of these systems. You can't put them in the bank but never mind, the Chancellor must have his little joke, let's go all the way, Tallinn here we come, for "Estonia", read "the UK": Estonia hit by 'Moscow cyber war'.

Tuesday, 17 March 2015

The lesson of the web? There. Is. No. Such. Thing. As. A. Secure. Website.

There is no such thing as a secure website.

You know that.

You've read the papers, listened to the radio, watched TV and browsed the web. You know Sony were hacked. You know JP Morgan Chase were hacked. And Lockheed Martin and the US State Department.

You know that. They know it and so does everyone else – there is no such thing as a secure website.

Knowing that, if someone offers you a web service and promises that it's secure, how do you react?

It doesn't matter who that someone is, it doesn't matter how often they claim to take security seriously, it doesn't matter if they claim to have learnt the lessons about privacy and confidentiality and security, the promise is suspicious.

Does this someone believe that you can't read or understand the news or draw elementary logical conclusions from the unmistakable evidence?

They must do.

They must think they're marketing to cretins.

It's extraordinary that anyone in the 21st century is still offering security on the web. We all know that it's not available. That's the lesson of the web. There is no such thing as a secure website. If you don't get that, you don't understand the web.

Anyone who takes your intelligence seriously will acknowledge that when they market to you. They will say that they take all due care and they expect you to take all due care but that security breaches are inevitable and that there is a well-oiled compensation scheme in place for when they happen.

Anyone else now, today, in the 21st century, looks like nothing more than an old-fashioned mountebank.

