This article is written by Tom Read, chief digital and information officer for Ministry of Justice.


One of my favourite quotes comes from the late, great American author Kurt Vonnegut:

“Another flaw in the human character is that everyone wants to build, and nobody wants to do maintenance” — Kurt Vonnegut

In Justice Digital & Technology, the digital arm of the Ministry of Justice (MoJ), we are rarely accused of being shy about self-promotion. We talk on stage, we blog and we tweet loudly about our successes.

I make no apologies for this.

Doing transformation in government is often hard, frustrating and thankless, so we should celebrate our good work. We also need to tell the world this is a place where you can come and make a difference.

The focus of our celebration usually falls into two categories: delivering new services or projects; and rescuing a project or service from disaster. These are connected. As our projects are usually funded by capital investment, this can mean we deliver at pace, then leave software to decay until we have to step in and recover from failure.

I suspect this is also because many of our teams are still in start-up mode: move fast and break things.

Celebrating maintenance

What we talk much less about is a culture that celebrates maintenance. We have more than 700 complex systems in MoJ, and a large proportion have suffered from neglect as we have repeatedly prioritised our money and people on building new services.

We are now trying to change this by creating a more balanced change portfolio, with equal weight and celebration given to keeping services properly patched, hosted, updated and available.

To help with our prioritisation, we have taken our top 40 most critical systems and assessed them against five criteria:

  1. People: Do we have a team in place, or an outsourced supplier, who really understands the system and can keep it maintained?
  2. Technology: How well can we operate the tech through things like automated tests, CI/CD?
  3. Atrophy: Effectively rot. When was the system last patched or updated, and how many out of support components does it comprise?
  4. GDPR: Are retention schedules and auto-delete functions built in?
  5. Hosting: Is the system hosted on a strategic cloud service, or is it stuck in a legacy datacentre somewhere?

The top 40 number is a little arbitrary, but is based on some sound principles: Which contain our most sensitive data? Which would cause the biggest operational impact if they were to go down? Which would cause significant reputational damage for our department?

Addressing the problems

The risk of this approach is that we could fall into the trap of admiring the problem rather than fixing it. We discovered early on that moving services out of legacy hosting environments to the public cloud was a vital step as it makes it so much easier to deploy changes, and this has been our focus over the past couple of years.

We are now addressing some of the deeper challenges of application modernisation and, critically, ensuring that each of our priority systems has a clear owner and support structure.

This is hard for a few reasons. The first is money. Migrating services to the cloud, upgrading databases and application layers is expensive, takes time and considerable effort. The business case is built around cost avoidance of an IT disaster that might not happen, rather than having a clear return on the investment.

Unless there is an immediate issue, prioritising maintenance is a hard sell

The second is getting buy-in from business areas to prioritise this work. Unless there is an immediate issue, prioritising maintenance is a hard sell. There is always a new policy or a new feature that people believe is more important, so addressing technical risk gets pushed down the priority list. There is also a curious and pervasive view that the legacy system will be switched off any year now, so we should just keep it ticking over.

The third is the technology itself. Systems that have been ignored for years are often fragile, poorly documented, and supported by one person who built the thing back in 1993. We need to be aware that the best-intentioned technical upgrade project could go horribly wrong.

Green shoots

The good news is that we are not alone in MoJ. Stories like the TSB IT meltdown, the BA data breach and our own major outage in early 2019 has made this a topic that leaders across government cannot afford to ignore. The leadership team in MoJ understands the importance of keeping this high on the agenda as we go into the upcoming spending rounds so we can keep our vital public services running. — Tom Read

(Picture Credit: Death to the stock photo)


Make sure to share your own thoughts with the author by leaving a comment below