Skip to content

BSA Continues its Push Against Unlicensed Software in Australia

Asia Pacific has the highest rate of unlicensed software use in the world, and the BSA has been settling cases in Australia and paying rewards to the employees who report them. What that means for anyone without a defensible licence position.

Asia Pacific has the highest rate of unlicensed software use anywhere in the world. The 2016 BSA Global Software Survey, which reports on 2015, found that 61% of software installed on computers across the region was unlicensed, with a commercial value of around US$19.1 billion. Against that background it is no surprise to see the BSA active in Australia.

Australia itself is well below the regional figure. The same survey put the Australian unlicensed rate at 20%, down from 25% in 2009, representing roughly A$579 million of commercial value. (Source: BSA Global Software Survey 2016, Seizing Opportunity Through License Compliance.) The direction of travel is right, but the decline is gradual, and one in five installations is still a significant exposure — particularly given the association the BSA and IDC draw between unlicensed software and malware infection.

Firm and well-publicised legal action is clearly a central part of how the BSA intends to change that behaviour. Publicity is the point: each settlement is a message to every other business in the same sector.

The BSA pays employees who report their employers

The BSA operates a reward programme in Australia offering up to A$20,000 to, in its own words, “eligible recipients who disclose accurate information regarding unlawful copying or use of BSA members’ software”.

This is worth pausing on, because it changes the risk model. Most compliance planning assumes the trigger is a vendor-initiated audit — a letter arrives, and you have some period to respond. A reward programme means the trigger can just as easily be a departing employee, a contractor who did not get paid, or someone in your own IT team who has been uncomfortable about a deployment for two years. You do not get advance warning of that, and you cannot negotiate the timing.

By the BSA’s account the approach works. Rewards have been paid to informants in Australia, and information supplied that way has led directly to settlements.

The settled cases cluster in construction and design

In November 2016 the BSA reported settlements totalling A$58,000 across three Australian businesses, as covered by Technology Decisions:

  • Meldan (Vic) Pty Ltd, trading as Granvue Homes, a home builder — A$35,000.
  • Sosan Pty Ltd, an architectural modelling business in Brisbane — A$18,000.
  • R King Enterprises, trading as Mocare — A$5,000.

The pattern is not accidental. Construction, architecture and manufacturing run expensive, seat-limited design software — Autodesk products in particular — alongside the usual Microsoft and Adobe deployments. The licence cost per user is high enough that cutting corners looks materially attractive, and the tools are frequently installed by project teams under deadline rather than by a central IT function. That combination is where unlicensed installations accumulate.

Tarun Sawney, the BSA’s senior director for Asia Pacific, framed the enforcement this way:

It is important for the Australian economy that unlicensed software be discouraged and infringing businesses be held accountable, particularly with the growing trend in illegal cyber activity.

And on what businesses should be doing about it:

We urge all businesses, whether large or small, to conduct regular checks of software licences and deployments, and implement an effective software asset management practice.

To which we say: quite. That is the entire argument for software asset management, made by the organisation doing the enforcing.

What a defensible position actually requires

“Conduct regular checks” is easy to say and hard to do manually, because the thing you need is not a list of installations. It is the difference between what is installed and what you are entitled to run, kept current.

That means, in order:

  1. Discovery you can trust. You cannot check licences on machines you do not know about. Network discovery, agent-based inventory and agentless collection for locked-down devices all have to land in the same place.
  2. Normalisation. Raw inventory data is a mess of inconsistent publisher and product strings. It has to be resolved against a maintained recognition library before install counts mean anything.
  3. Entitlement. What you bought, under which agreement, with which downgrade and second-use rights.
  4. A continuous position, not an annual one. A reconciliation performed once a year tells you where you stood on one day. It says nothing about the day the letter arrives.

CerteroX SAM covers this chain. Software recognition resolves against the Software Recognition Database — over 3.5 million titles — so install counts are normalised rather than approximated. The effective licence position is computed continuously across purchased, used, available, required, variance and exposure, rather than as a point-in-time reconciliation. Downgrade rights and second-use entitlement are handled explicitly, as is the Exclude From Licensing workflow for MSDN, development, training and second-use devices — the exclusions that most often turn an apparent shortfall into a compliant position.

There are also dedicated licence engines for the publishers that actually pursue these cases, including Microsoft and Adobe, plus Oracle, IBM, SAP and Salesforce. And Governance Policies let you set rules against unauthorised software so that an unlicensed installation is caught when it appears, rather than during a settlement negotiation.

The point

The BSA’s enforcement in Australia is not aimed at organisations with a functioning software asset management practice. It is aimed at organisations that cannot say what they have installed and cannot produce the paperwork for it — and that will not know they have a problem until someone else tells the BSA about it.

The defence is not secrecy or luck. It is being able to answer the question on the day it is asked.

If you want to talk through your licence position, get in touch.

Related reading

Other posts covering the same ground.

  • 5 Ways Software Asset Management Improves Your Business

    SAM is usually sold as audit insurance. It is also a security control, a cost-reduction programme, due diligence for an acquisition, and the only reliable basis for rationalising your applications.

    • SAM
    • Governance
    • Security
    7 min
  • Software Vendor Audits – 8 Things you need to know

    What an audit actually is, how it differs from a SAM review, what triggers one, and what you can do about it once the letter has arrived — including whether a completed audit can still be challenged.

    • SAM
    • Governance
    • Security
    9 min
  • The Rise in Oracle Java Audits: How to gain clarity

    Oracle asks to see your Java deployments before it will sell you more subscriptions. Why Java is the hardest thing in your environment to count, what the employee-based subscription changed, and how to build a deployment record you can actually defend.

    • SAM
    • Governance
    • Security
    6 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.