# The Law That Treats Ethical Hackers Like Criminals Is Still on the Books


If you found a critical flaw in a hospital's patient portal and responsibly disclosed it, you might expect a thank-you. In the United Kingdom, you might get a criminal record instead.


That's not hypothetical paranoia. The UK Computer Misuse Act — enacted in 1990, when the web didn't exist, when "ethical hacker" wasn't a job title, when the most prominent cybersecurity concern in Parliament was probably someone reading a fax they weren't supposed to — remains the primary law governing unauthorized computer access. It does not distinguish between a criminal breaking into systems to steal data and a researcher who finds a vulnerability and reports it. The legal exposure is the same.


At DEF CON 34 in Las Vegas, Katharina Sommer, NCC Group's director of government affairs, presented research that maps where the world actually stands on this problem — and the picture is worse than most in the security industry assume.


---


## Thirty-Five Years of Inaction


Sommer has spent seven years running NCC Group's campaign to reform the CMA. The persistence alone tells you something: this is not a problem that self-corrects. Parliament has repeatedly had the opportunity to modernize the law. It hasn't.


The core issue is consent. The CMA holds that accessing a computer system requires the owner's permission. In theory, sensible. In practice, a researcher who discovers a misconfigured S3 bucket containing user data didn't get permission — but they also didn't break anything, steal anything, or harm anyone. If they report it, they've technically admitted to conduct that could be prosecuted. Many don't bother. The vulnerability stays unpatched.


This chilling effect is exactly what makes outdated cybercrime law dangerous. It's not primarily about researchers going to prison — it's about the vulnerabilities that never get disclosed because the researchers made the rational decision to stay quiet.


---


## Less Than 10% of the World Has an Answer


Sommer's research surveyed 154 countries with cybercrime statutes on the books. Fifteen have implemented or are actively considering legal protections for good-faith security research. That's roughly 9.7%.


The United States — after years of watching the Computer Fraud and Abuse Act weaponized against researchers — issued Department of Justice guidance in 2022 saying prosecutors shouldn't pursue charges against researchers acting in good faith. That's policy, not law, and it can change with an administration. The EU's Cyber Resilience Act and NIS2 directive are pushing member states toward vulnerability disclosure frameworks, but legal protection for researchers varies enormously across the bloc.


Elsewhere? Largely void. A researcher in Thailand, Brazil, or Nigeria disclosing a vulnerability to a local company operates with essentially no legal cover. The countries that most need security research infrastructure to protect their digital economies often have the least legal clarity about whether that research is permitted.


---


## A Blueprint, Not Just a Complaint


Sommer's DEF CON session wasn't just a grievance catalogue. She presented a five-point framework for what countries need to get right if they want to protect legitimate security work without creating loopholes for malicious actors.


The framework hinges on a concept she identified as the common thread in jurisdictions that have made progress: specificity in how good faith is defined. Laws that try to draw the line at "intent" tend to fail — intent is hard to prove and easy to claim. The more durable protections are procedural: researchers who follow coordinated disclosure practices, notify vendors within defined windows, don't profit from the vulnerability itself, and refrain from accessing data beyond what's necessary to demonstrate the flaw exist in clearer legal territory.


The judicial culture matters enormously too. Sommer flagged that identical statutory language can produce radically different outcomes depending on how prosecutors and judges actually apply it. That's a harder problem than writing better laws — it requires building institutional knowledge about security research inside legal systems that currently have almost none.


---


## What the Industry Keeps Getting Wrong


The security community has tended to frame this as a niche problem — something that matters to professional pen testers and bug bounty hunters but not to mainstream enterprise security. That framing is mistaken.


Bug bounty programs, which most major technology companies now run, implicitly depend on researchers being willing to engage. The $50,000 payout for a critical vulnerability only works if the researcher felt safe enough to report it rather than sell it on the gray market or simply move on. Legal uncertainty tilts that calculus. As disclosure risk rises, the pool of researchers willing to engage with responsible disclosure shrinks — and the pool of buyers for undisclosed vulnerabilities doesn't.


Sommer's research will be used to lobby the UK government directly. Whether it moves the CMA closer to reform than NCC Group's previous seven years of effort is an open question. But DEF CON is a useful venue for making the case: the people in that room are the ones whose work either gets recognized by law or criminalized by it.


---


## HackWire Analysis


The timing of this presentation matters more than it might appear. The UK is currently operating under significant political pressure to demonstrate that it takes both cybersecurity and innovation seriously — two goals that are genuinely compatible but require legislative coherence to achieve together. A law written four years before the first web browser is not that law.


What's missing from most coverage of this story is the second-order effect on the vendor ecosystem. When researchers don't disclose, vendors don't patch. When vendors don't patch, breach timelines extend. The UK government's own National Cyber Security Centre runs a coordinated vulnerability disclosure program that implicitly assumes researchers can report findings without fear of prosecution. That assumption is legally unsupported by the current CMA, which creates a bizarre situation where the government's own security apparatus operates in a gray zone it refuses to clarify.


The five-country comparison Sommer builds her framework from is also worth watching closely. Countries that have created clear researcher safe harbors — the Netherlands being the clearest European example — have seen measurable increases in coordinated disclosure activity. This isn't idealism; it's a policy intervention with documented outcomes. The UK should be studying those outcomes, not waiting to see if the problem resolves itself.


For defenders in organizations running bug bounty or vulnerability disclosure programs, the immediate practical implication is liability documentation: ensure your program's scope, authorization language, and reporting procedures are unambiguous and legally reviewed. In jurisdictions with weak researcher protections, what looks like an invitation to find vulnerabilities can still expose a researcher to legal risk if the scope language is vague. That's your problem as much as theirs — because the ambiguity is what drives talent toward silence.


The broader reform effort is slow. The chilling effect is not.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)