Cybersecurity Researchers Face Prison Time Due to Outdated Laws
A growing concern in the cybersecurity community is the outdated laws that put security researchers at risk. In some countries, including the United Kingdom, security researchers who responsibly disclose vulnerabilities can face imprisonment or fines under laws that don’t differentiate between malicious hackers and those working in good faith. However, change may finally be coming.
Katharina Sommer, director of government affairs and analyst relations at NCC Group, has been advocating for reform. Her research highlights the need for countries to update their policies and laws to reflect the rapidly evolving nature of cybercrime. According to Sommer, only 15 countries worldwide have implemented or are considering some level of legal protection for researchers. This is a mere 10% of the total number of countries with cybercrime statutes.
Sommer’s research demonstrates that it is possible for countries to implement policies that safeguard both ethical hackers and user privacy. She presented her findings at DEF CON 34, a conference focused on cybersecurity and hacking. Her aim is to use this research to lobby the UK government to reform the Computer Misuse Act, which has been in place since 1990. This law does not distinguish between malicious activity and good faith research, putting security researchers at risk.
The Computer Misuse Act was initially enacted as a way to prevent unauthorized access to computer systems and to address cybercrime. However, it is now outdated, and its provisions are no longer suitable for the current cybersecurity landscape. Sommer notes that with the advancement of threats and attackers, there is now more security and vulnerability research happening without consent or authorization. This is done in good faith intention, aiming to improve cyber resilience for the greater public good.
Sommer’s work has focused on improving cybersecurity regulations through policy reform. However, she acknowledges that working with policymakers can be challenging. She notes that while awareness of threats continues to grow, major incidents are often viewed as “wake-up call” events, only to dwindle away until the next attack occurs.
The UK government has made a commitment to a national security bill that would encompass reforming the Computer Misuse Act. This includes establishing legal defenses for security researchers. Sommer hopes that these reforms will happen quickly but acknowledges that there is still work to be done. She notes that other countries, such as Portugal, have successfully implemented policies that safeguard good-faith security research.
For cybersecurity professionals and enthusiasts, this story serves as a reminder of the importance of advocating for policy reform. By supporting efforts like Sommer’s, we can ensure that our researchers are protected while they work to improve cyber resilience. As policymakers continue to grapple with the complexities of cybersecurity, it is essential that we raise awareness about these issues and push for meaningful change.
As you navigate the complex world of cybersecurity, remember that outdated laws can put security researchers at risk. Stay informed about policy reform efforts and advocate for changes that support good-faith research. By working together, we can create a safer and more secure online environment for everyone.
Source: Dark Reading — 2026-08-10