Summary
- Research publicised by Internet Society Pulse on 10 September examines roughly one million government URLs in 61 countries, covering hosting, authoritative DNS and certificate authorities.
- The researchers call concentration “structural” when government sites resemble the local commercial market and “strategic” when the distributions diverge significantly. The second pattern suggests institutional choice; it does not directly observe a procurement decision.
- Similar concentration can accompany different results. The study reports greater localisation and lower hosting latency among strategically consolidated governments, but finds little meaningful provider redundancy in either class.
- A dependency-decision receipt should connect every measured layer to the responsible authority, options available at the decision date, accepted trade-off, switching limits, exit test and review date. Without that join, an excellent warning signal can acquire more causal authority than its evidence supports.
The map sees providers, not the meeting that selected them
Government websites are now doors to taxation, health care, licensing, immigration and other public functions. A failure behind one door can inconvenience a visitor; a common failure behind thousands can interrupt the state. The new Pulse article therefore asks a better question than whether government infrastructure is concentrated. It asks why apparently similar concentration exists.
The underlying SSRN working paper, by Rashna Kumar, Fabián E. Bustamante, Marinho Barcellos and Amreesh Phokeer, covers 61 countries and more than 82% of the world's Internet population. The researchers examine about one million government URLs. They compare the providers used by those sites with commercial sites in the same country, split into high-, middle- and lower-popularity groups.
Three layers are measured separately. Hosting delivers the content. Authoritative DNS controls the answers that direct a name toward operational infrastructure. A certificate authority participates in the trust chain for a secure connection. A website can depend on different organisations at each layer, so a single label such as “the cloud” would hide important control boundaries.
The research presentation describes the method more closely. Government domains came from official sources. Collection used country-local VPN connections to observe landing-page resources and hosting organisations, authoritative nameservers and certificate authorities from TLS handshakes. Commercial domains came from CrUX; 1,000 sites were sampled from each popularity stratum. Provider concentration was calculated with the Herfindahl-Hirschman Index, then resampled 5,000 times to compare government and commercial distributions.
This design can see a pattern that a procurement database alone may miss. A framework agreement may name several eligible providers while deployed services converge on one. Conversely, one familiar brand may conceal distinct service layers or local operating arrangements. Measurement starts from the dependency that users actually encounter.
It still cannot see the meeting that selected that dependency. A network observation does not identify the purchasing authority, tender specification, security exception, renewal decision, available budget, integration constraint or risk acceptance. It cannot say whether an alternative was technically equivalent and lawful at the time. That boundary is not a defect in the research. It is the line between a diagnostic and a governance record.
“Strategic” is a statistical class, not proof of intent
The researchers call a country structurally consolidated when the provider diversity of government sites resembles the commercial baseline. If the surrounding market is already narrow, the public sector may have little practical room to diversify. They call the pattern strategic when government concentration differs significantly from the commercial comparison. The Pulse post carefully says such a divergence suggests that procurement rules, approved platforms, compliance requirements or other governance choices may be shaping the result.
That wording matters. “Strategic” can sound as if a cabinet deliberately chose a national dependency after reviewing every alternative. The measurement establishes no such universal narrative. The class says that government sites look different from the selected commercial baseline under the study's test. Institutional action is a plausible explanation to investigate.
The distinction nevertheless improves the policy conversation. The presentation describes Australia and Vietnam as structural examples. India is strategic for hosting and DNS: more than 85% of observed Indian government sites rely on the National Informatics Centre, while its certificate-authority pattern is less concentrated because eMudhra accounts for 17% of observed government CA chains. Kazakhstan and Algeria supply other illustrations. These are measured configurations, not findings of wrongdoing.
The CA layer also shows why service-specific interpretation is essential. Public Web PKI begins with a limited set of trusted issuers, so commercial and government sites can converge for reasons unlike a hosting market. A government may localise one layer, centralise another for security administration and inherit a global bottleneck in a third. Adding the three into one sovereignty verdict would destroy the study's most useful distinction.
Nor is structural concentration an absence of choice. An authority operating in a narrow market still chooses contract duration, data portability, system coupling, DNS design, recovery arrangements and the date on which it will test an exit. Market structure changes the available set; it does not erase operational responsibility.
The apparent trade-off is real, but the fallback is thin
Concentration is often treated as synonymous with fragility. The results are less convenient. The Pulse account says strategically consolidated governments often have more localised infrastructure and lower user-facing latency than structurally constrained peers. An earlier indexed version of the paper reports 16% lower hosting latency. Centralisation may therefore buy proximity, common standards, purchasing leverage or simpler operations.
But provider redundancy did not materially distinguish the two classes. Governments in both categories generally lacked independent provider fallback. That is the harder result. A site can be local and fast while still sharing a failure domain with much of the public sector. A list of two suppliers can also look diverse while both depend on the same DNS operator, certificate chain, transit path, identity service or management plane.
Concentration scores do not test recovery. HHI describes the distribution of observed provider shares. It does not establish that a secondary deployment has current data, usable credentials, adequate capacity or an exercised cutover procedure. Low concentration is not the same as independent resilience; high concentration is not proof that the accepted benefits were irrational.
This is where public guidance supplies an important complement. The UK's cloud lock-in guidance, updated on 3 September, says some technical lock-in is unavoidable. It asks organisations to monitor their portfolio, estimate the cost and time to switch, prepare contingency plans and, where useful, rebuild or test critical components in another environment. It also asks procurement, finance and technology specialists to decide together. That is a record of trade-offs, not a ritual instruction to buy from more vendors.
The EU Data Act takes another piece of the problem: written terms for switching data-processing services, assistance during transition, business continuity and known switching risks. Those duties do not automatically govern every DNS or certificate dependency in the study. They demonstrate the kind of artifact that turns portability from an aspiration into an allocated obligation.
Publish the join between observation and authority
A government should not answer a concentration finding with a press release declaring itself resilient. It should publish the join the measurement cannot produce.
For each material service, a dependency-decision receipt would identify the public function and accountable authority. It would separate hosting, authoritative DNS and certificate trust, then attach the observed provider, measurement date, denominator and method. The receipt would link that observation to the procurement or architecture decision in force.
The next fields are the ones a provider map cannot infer: alternatives considered at the decision date; legal, security, skills and market constraints; reasons for excluding an option; and the locality, latency, cost or integration benefit accepted in return for concentration. If an approved platform or emergency exception narrowed the field, the record should say who authorised it and when it expires.
Resilience needs its own evidence. The receipt should name the assumed failure domain, independent fallback, data and configuration portability, estimated switching time and cost, last recovery or exit test, unresolved blockers and next review date. A “multi-cloud” label without a tested cutover should not count. Neither should a contract clause be treated as proof that applications, data, identity and staff can leave together.
The receipt is Daniel Kade's editorial model, not a recommendation adopted by the researchers or the Internet Society. The Pulse page is a guest contribution and expressly says its views do not necessarily represent the organisation. The proposed join respects that evidence boundary: researchers own the measurement; public authorities own the explanation of their choices.
The baseline is an instrument, not an alibi
The commercial web is a useful comparison because it holds country conditions more nearly constant. It is not a neutral picture of every option government could lawfully use. Commercial sites may optimise for advertising, retail conversion or low cost. Public systems may face records laws, security classifications, accessibility obligations, data-residency rules and continuity duties. A government can rationally diverge.
The reverse is also true. Resembling the commercial market does not absolve the state. If both sectors are concentrated, the public authority still must decide how a common outage affects benefits, courts or emergency information. “The market made us do it” is a hypothesis until the available suppliers, entry barriers and rejected mitigations are recorded.
The OECD Digital Government Outlook 2026 captures this institutional tension. Twenty-seven of 36 reporting countries had dedicated digital or technology procurement guidelines in 2025, but only 20 reported using a broader set of mechanisms suited to digital delivery. Central guidance can improve consistency while also reinforcing standardisation if skills, support and flexible contracts do not accompany it.
That is why the study's classification should begin an inquiry rather than end one. Its million URLs create a powerful outside view. Governance begins when an institution supplies the inside record and permits the two to be compared.
Sources
- Internet Society Pulse — Concentration of Government Web Services Raises Questions About Underlying Drivers
- SSRN — Government Procurement and the Structure of Digital Dependency, current record
- SSRN — earlier indexed version and abstract
- Research presentation — When Consolidation is Not a Choice
- Internet Society Pulse — How Resilient Are Government DNS Services?
- UK Government — Managing technical lock-in in the cloud
- European Union — Data Act
- OECD — Digital Government Outlook 2026
- Heng Lu — The Policy Mirror
- Heng Lu — Running-Code Primacy
- Heng Lu — Reality, Not Advocacy
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

