
Eric DeGrass
August 19th, 2025
A recent BBC investigation revealed that Her Majesty’s Courts & Tribunals Service (HMCTS) delayed addressing or potentially concealed a serious IT bug that caused evidence to go missing, be overwritten, or vanish entirely. The leaked internal report confirmed that judges across civil, family, and tribunal courts may have made rulings based on incomplete evidence, while HMCTS itself acknowledged it did not fully assess the extent or impact of the data corruption.
On the surface, this might seem like a typical example of a software defect causing “data loss”. The true significance lies in how the flaw unfolded in a real-world, high-stakes environment. This was not simply a technical glitch. It had direct and devastating consequences for justice, the lives of individuals involved in court cases, and public trust in the legal system.
This distinction underscores a vital lesson. Severity labels such as “system outage,” “data loss,” or “poor user experience” are too generic. What really matters is how a flaw interacts with context-specific business processes and real-world consequences. In the HMCTS case, even a seemingly minor technical error had potentially irreversible impact on court rulings.
Organizations must adopt their own context-sensitive risk assessment frameworks, especially when evaluating vendor-reported bugs. Vendors naturally rate flaw severity from a broad, generalized standpoint, which can miss the unique ways defects manifest in specific environments. Each organization has its own workflows, legal obligations, and downstream impacts that generic severity metrics cannot capture.
BugZero was built to address exactly this challenge. By providing built-in support for organization-specific risk rankings and seamless integration with ServiceNow, BugZero ensures that every identified vendor bug is evaluated against the organization’s own risk framework and risk appetites. This makes it possible to guarantee a managed, timely, and effective response based on the true operational impact, not just a vendor’s generic classification.
To learn more about how you can define your own Risk Ratings, https://www.findbugzero.com/contact.
Eric DeGrass
March 13th, 2025
Eric DeGrass
August 19th, 2025
Eric DeGrass
July 15th, 2025
Sign up to receive a monthly email with stories and guidance on getting proactive with vendor risk
BugZero requires your corporate email address to provide you with updates and insights about the BugZero solution, Operational Defect Database (ODD), and other IT Operational Resilience matters. As fellow IT people, we hate spam too. We prioritize the security of your personal information and will only reach out only once a month with pertinent and valuable content.
You may unsubscribe from these communications at anytime. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, check out our Privacy Policy.