news.mlab.sh
Back to the feed
threat-intel

Outdated Cybercrime Laws Put Security Researchers at Risk

Medium
Summary

Security researchers in the UK and globally face legal risks due to outdated cybercrime laws that don't differentiate between malicious hacking and responsible vulnerability research. Katharina Sommer, of NCC Group, has been leading a campaign to reform the UK Computer Misuse Act, drawing inspiration from countries like Portugal and Latin American nations that have implemented legal protections for researchers. Her research, based on a ‘CICIC’ framework (conduct, intent, consensus, institution, conditionality), aims to create a more nuanced legal approach that supports ethical security research and improves cybersecurity resilience.

Outdated cybercrime laws are putting security researchers at risk worldwide, particularly in the UK. The Computer Misuse Act of 1990, a primary UK law addressing unauthorized access and cybercrime, fails to distinguish between malicious hacking and responsible vulnerability research. This creates a significant hurdle for security researchers who proactively identify and disclose weaknesses, a crucial activity for bolstering cybersecurity defenses.

Katharina Sommer, director of government affairs and analyst relations at NCC Group, has been advocating for reform, citing a growing need for updated legislation. Her research demonstrates that many countries – including Portugal and several in Latin America – have already implemented legal protections for researchers, recognizing the value of ethical vulnerability research.

Sommer’s approach is built around a ‘CICIC’ framework: Conduct (focusing on activity rather than actor), Intent (defining what constitutes good-faith research), Consensus (establishing clear guidelines for responsible disclosure), Institution (creating legal defenses for researchers), and Conditionality (setting limits on research activities, such as prohibiting DDoS attacks). She has presented this framework to the UK government, highlighting the progress made by other nations and emphasizing the importance of a more flexible and supportive legal environment.

Her work stems from a growing awareness that cybersecurity threats are evolving rapidly, and that a blanket approach to cybercrime laws is no longer effective. The UK government recently announced a national security bill that includes provisions for reforming the Computer Misuse Act, providing a potential pathway for change. However, Sommer stresses that further work is needed to ensure that any new legislation truly protects and encourages responsible security research.

Read the full article at Dark Reading