Asia Pacific has the highest rate of unlicensed software use anywhere in the
world. The 2016 BSA Global Software Survey, which reports on 2015, found that
61% of software installed on computers across the region was unlicensed, with a
commercial value of around US$19.1 billion. Against that background it is no
surprise to see the BSA active in Australia.
Australia itself is well below the regional figure. The same survey put the
Australian unlicensed rate at 20%, down from 25% in 2009, representing roughly
A$579 million of commercial value. (Source: BSA Global Software Survey 2016,
Seizing Opportunity Through License Compliance.) The direction of travel is
right, but the decline is gradual, and one in five installations is still a
significant exposure — particularly given the association the BSA and IDC draw
between unlicensed software and malware infection.
Firm and well-publicised legal action is clearly a central part of how the BSA
intends to change that behaviour. Publicity is the point: each settlement is a
message to every other business in the same sector.
The BSA pays employees who report their employers
The BSA operates a reward programme in Australia offering up to A$20,000 to, in
its own words, “eligible recipients who disclose accurate information regarding
unlawful copying or use of BSA members’ software”.
This is worth pausing on, because it changes the risk model. Most compliance
planning assumes the trigger is a vendor-initiated audit — a letter arrives, and
you have some period to respond. A reward programme means the trigger can just
as easily be a departing employee, a contractor who did not get paid, or someone
in your own IT team who has been uncomfortable about a deployment for two years.
You do not get advance warning of that, and you cannot negotiate the timing.
By the BSA’s account the approach works. Rewards have been paid to informants in
Australia, and information supplied that way has led directly to settlements.
The settled cases cluster in construction and design
In November 2016 the BSA reported settlements totalling A$58,000 across three
Australian businesses, as covered by Technology Decisions:
- Meldan (Vic) Pty Ltd, trading as Granvue Homes, a home builder — A$35,000.
- Sosan Pty Ltd, an architectural modelling business in Brisbane — A$18,000.
- R King Enterprises, trading as Mocare — A$5,000.
The pattern is not accidental. Construction, architecture and manufacturing run
expensive, seat-limited design software — Autodesk products in particular —
alongside the usual Microsoft and Adobe deployments. The licence cost per user
is high enough that cutting corners looks materially attractive, and the tools
are frequently installed by project teams under deadline rather than by a
central IT function. That combination is where unlicensed installations
accumulate.
Tarun Sawney, the BSA’s senior director for Asia Pacific, framed the enforcement
this way:
It is important for the Australian economy that unlicensed software be
discouraged and infringing businesses be held accountable, particularly with
the growing trend in illegal cyber activity.
And on what businesses should be doing about it:
We urge all businesses, whether large or small, to conduct regular checks of
software licences and deployments, and implement an effective software asset
management practice.
To which we say: quite. That is the entire argument for software asset
management, made by the organisation doing the enforcing.
What a defensible position actually requires
“Conduct regular checks” is easy to say and hard to do manually, because the
thing you need is not a list of installations. It is the difference between
what is installed and what you are entitled to run, kept current.
That means, in order:
- Discovery you can trust. You cannot check licences on machines you do not
know about. Network discovery, agent-based inventory and agentless collection
for locked-down devices all have to land in the same place.
- Normalisation. Raw inventory data is a mess of inconsistent publisher and
product strings. It has to be resolved against a maintained recognition
library before install counts mean anything.
- Entitlement. What you bought, under which agreement, with which downgrade
and second-use rights.
- A continuous position, not an annual one. A reconciliation performed once
a year tells you where you stood on one day. It says nothing about the day
the letter arrives.
CerteroX SAM covers this chain. Software recognition resolves against the
Software Recognition Database — over 3.5 million titles — so install counts are
normalised rather than approximated. The effective licence position is computed
continuously across purchased, used, available, required, variance and exposure,
rather than as a point-in-time reconciliation. Downgrade rights and second-use
entitlement are handled explicitly, as is the Exclude From Licensing workflow
for MSDN, development, training and second-use devices — the exclusions that
most often turn an apparent shortfall into a compliant position.
There are also dedicated licence engines for the publishers that actually pursue
these cases, including Microsoft and Adobe, plus Oracle, IBM, SAP and
Salesforce. And Governance Policies let you set rules against unauthorised
software so that an unlicensed installation is caught when it appears, rather
than during a settlement negotiation.
The point
The BSA’s enforcement in Australia is not aimed at organisations with a
functioning software asset management practice. It is aimed at organisations
that cannot say what they have installed and cannot produce the paperwork for
it — and that will not know they have a problem until someone else tells the
BSA about it.
The defence is not secrecy or luck. It is being able to answer the question on
the day it is asked.
If you want to talk through your licence position, get in touch.