UK cybercrime law faces pressure to protect ethical security researchers

0
19
UK cyber law reform could offer protection to ethical hackers
UK cyber law reform could offer protection to ethical hackers

As cyber threats grow more sophisticated, security researchers who work to identify vulnerabilities could still face criminal penalties under outdated laws. In the UK, a 1990 law does not clearly distinguish between malicious hackers and researchers acting in good faith.

Katharina Sommer, director of government affairs and analyst relations at a cybersecurity firm, said only 15 countries have implemented or are considering some form of legal protection for security researchers. With 154 countries having cybercrime statutes, that is less than 10%.

Her research examines how laws can protect ethical hackers while safeguarding user privacy. She presented the findings at a DEF CON 34 session titled, “Legally Hacked: How Countries Decide When Security Research Is Allowed.”

“It hinges upon how you structure the law and write the legislation, and how much trust you have in your judicial system ultimately,” Sommer says. “And I think that’s the common challenge.”

UK law under scrutiny

The UK Computer Misuse Act, enacted in 1990, remains the country’s main law covering unauthorised computer access, hacking and cybercrime. It requires system-owner consent but does not distinguish between malicious activity and good-faith research, potentially exposing researchers to imprisonment or fines.

“But as threats have grown and attackers have advanced, and sort of cybersecurity has evolved as a profession, there is now a lot of security and vulnerability research happening that isn’t consented to, or isn’t authorized,” she says. “But it is still done with good faith intention and with the purpose of improving cyber resilience for the greater public good.”

The UK government has committed to a national security bill that could reform the law and introduce legal defenses. Sommer’s research found examples from Portugal, Argentina, Chile and Panama. Portugal changed its cybercrime law in 2025 to create a safe haven for good-faith researchers, while Panama has protections for people producing hacking tools.

Sommer used the UN Trade and Development Global Cyberlaw Tracker with an LLM to identify countries offering such protections.

Proposed CICIC framework

Her research proposes 5 principles: “conduct, intent, consensus, institution, and conditionality.” These cover the activity rather than the person, define good-faith behaviour, establish responsible disclosure, identify institutional safeguards and set conditions such as avoiding DDoS attacks and unnecessary retention of personal data.

“We’ve engaged with the security research community and, more or less, asked them where they would draw the line on the kind of activities that they would want to be able to undertake under a defense, and they were incredibly cautious and incredibly responsible about,” she says. “So, for us that was really proof to say to law enforcement, ‘We’re not going to open the floodgates.'”

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.