DEF CON 34 – Las Vegas – Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn’t distinguish between malicious hackers and those working in good faith. But change may finally be coming.
Cybercrime is accelerating rapidly, requiring a holistic approach to curb threats. Security researchers who responsibly disclose vulnerabilities are one way to address burgeoning risks against governments, businesses, and individuals, but many countries have not updated their policies and laws to reflect that, Katharina Sommer, NCC Group’s director of government affairs and analyst relations, tells Dark Reading.
Sommer found that 15 countries worldwide have implemented or are considering some level of legal protection for researchers. But that’s less than 10% of countries, considering 154 have cybercrime statutes, so risks remain high.
New research by Sommer demonstrates that it is possible for countries to implement policies that safeguard both ethical hackers and user privacy, offering a blueprint for broader reform. She presented the research, which she will use to lobby the UK government, during a DEF CON 34 session titled, “Legally Hacked: How Countries Decide When Security Research Is Allowed.”
“It hinges upon how you structure the law and write the legislation, and how much trust you have in your judicial system ultimately,” Sommer says. “And I think that’s the common challenge.”
‘It’s Still Done in Good Faith’
NCC Group has, for the past seven years, been running a campaign to reform the UK Computer Misuse Act, which served as the catalyst for Sommer’s new research. Though it serves as the primary UK law to address unauthorized access to computer systems, hacking, and general cybercrime, UK Parliament enacted it in 1990 and does not differentiate between malicious activity and good faith research. Therefore, security researchers could face imprisonment or fines if found guilty of breaking the law.
In theory, the law makes sense — it states hackers need the consent of the system owner — but it’s outdated, and that affects the way security and threat intelligence research operations run, Sommer warns.
“But as threats have grown and attackers have advanced, and sort of cybersecurity has evolved as a profession, there is now a lot of security and vulnerability research happening that isn’t consented to, or isn’t authorized,” she adds. “But it is still done with good faith intention and with the purpose of improving cyber resilience for the greater public good.”
Working with policymakers to improve cybersecurity regulations can be frustrating. Sometimes it feels like screaming, “Would anyone like to talk about cyber?” into the void, Sommer says, noting policymakers often dump it in a bucket with general technology laws.
And while awareness of threats continues to grow, she notes an attention curve issue where major incidents are repeatedly viewed as “wake-up call” events, only to dwindle away until the next attack occurs.
Updating Cybercrime Laws
During King Charles’ speech in May, the UK government made a commitment to a national security bill that would encompass reforming the Computer Misuse Act, including legal defenses. Those actions inspired Sommer to take the research further.
Now, she hopes reforms will happen as quickly as possible, but knows she still has work to do.
“We looked at what a lot of other countries have been doing, so we can say to the UK government, ‘You’re falling behind, guys, let’s do something,'” Sommer says.
Learning what Portugal did was a “watershed” moment for Sommer, who says the country made massive strides when policymakers implemented two directives. In 2025, Portugal lawmakers modified their cybercrime law to establish a safe haven for good-faith security researchers.
“This legislative initiative arises from an awareness not only of the pressing seriousness posed by multiple cyber threats, but also of the high disruptive potential of their hostile actions against digital assets,” the decree law states.
Once Sommer discovered Portugal’s updates, she decided to examine other countries. Language barriers presented difficulties, but she fed the United Nations (UN) Trade and Development agencies Global Cyberlaw Tracker into a large language model (LLM) and prompted it to tell her which countries had some kind of safe harbor or legal protections for good faith security researchers. She used the results as the baseline of the research.
Sommer discovered some surprises too; many Latin American countries, including Argentina, Chile, and Panama, all implemented some level of defenses. “Panama, I think, is probably the most relevant because they’ve implemented something that protects people who produce hacking tools,” she says.
Understanding the CICIC-Based Taxonomy
Prior to traveling to Las Vegas, Sommer informed the UK government of her impending DEF CON 34 talk and research, highlighting the long list of countries that already implemented new policies. More importantly, she created an actionable plan based on five principles referred to as “CICIC”: conduct, intent, consensus, institution, and conditionality.
Conduct, for example, refers to laws that examine and regulate the activity rather than the actor. Legal defenses should apply to anyone undertaking activity for the purpose of improving cybersecurity, which is more scalable and covers a broader range of security researchers, she explains.
Consensus defines what “good faith” activity actually looks like. For example, researchers should willingly report vulnerability findings in a timely manner and not extort anyone, she says. Conditionality refers to conditions researchers must follow, such as not deploying distributed denial of service (DDoS) attacks and not retaining personal data for longer than necessary.
“We’ve engaged with the security research community and, more or less, asked them where they would draw the line on the kind of activities that they would want to be able to undertake under a defense, and they were incredibly cautious and incredibly responsible about,” she says. “So, for us that was really proof to say to law enforcement, ‘We’re not going to open the floodgates.'”


