Outdated Cybercrime Laws Put Security Researchers at Risk

A growing number of cybersecurity researchers are being put at risk by outdated cybercrime laws that fail to distinguish between malicious hackers and those working in good faith. A recent study has highlighted this issue, revealing that many countries have yet to update their policies and laws to reflect the evolving nature of security research.

Security researcher Katharina Sommer, director of government affairs and analyst relations at NCC Group, has been advocating for change. She has mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security researchers. According to her findings, only 15 countries worldwide have implemented or are considering some level of legal protection for researchers. This is a concerning trend, given that over 150 countries have cybercrime statutes in place.

The issue is particularly pressing in the UK, where the Computer Misuse Act 1990 remains on the books. This law does not differentiate between malicious activity and good-faith research, putting security researchers at risk of imprisonment or fines if they are found guilty of breaking the law. While the law was intended to address unauthorized access to computer systems and hacking, it has become outdated in its application.

Sommer argues that the problem is not just with the law itself but also with how it is interpreted by judges and prosecutors. “It hinges upon how you structure the law and write the legislation, and how much trust you have in your judicial system ultimately,” she says. This lack of clarity has led to a situation where security researchers are being forced to operate in a gray area, unsure whether their activities will be deemed lawful or not.

The stakes are high for those involved in good-faith security research. If caught breaking the law, they could face serious consequences, including imprisonment. In some cases, this has already happened. For instance, in 2020, a British cybersecurity researcher was charged under the Computer Misuse Act for accessing a government database without permission.

Sommer is hopeful that change is on the horizon. The UK government has recently committed to reforming the Computer Misuse Act as part of its national security bill. This development has inspired her to take her research further and push for reforms. “We looked at what a lot of other countries have been doing, so we can say to the UK government, ‘You’re falling behind, guys, let’s do something,'” she says.

As policymakers grapple with updating cybercrime laws, it is essential that they prioritize the needs of good-faith security researchers. By doing so, they can create a safer and more supportive environment for those working tirelessly to improve cybersecurity.

For readers who may be involved in security research or operate in industries where vulnerability disclosure is common practice, this issue highlights the importance of being aware of local laws and regulations. While it’s essential to prioritize responsible behavior, it’s equally crucial to advocate for change when outdated laws put researchers at risk. By working together with policymakers and advocating for reforms, we can create a more secure and supportive environment for all those involved in cybersecurity research.


Source: Dark Reading — 2026-08-10