Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Aptoide becomes the first rival app store to return to Google Play in the US

    August 10, 2026

    Premium seats are coming to ChatGPT Business

    August 10, 2026

    Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

    August 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Aptoide becomes the first rival app store to return to Google Play in the US
    • Premium seats are coming to ChatGPT Business
    • Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
    • TaoWeave’s TAO sales test its treasury strategy
    • 1 in 5 people may carry this hidden genetic heart risk
    • Baker Hughes furnishing Southeast Asian deepwater gas project with subsea systems
    • Russia Is Targeting Ukraine’s Traumatized Youth
    • Russian court bars only anti-war party from standing in parliamentary elections
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Outdated Cybercrime Laws Put Security Researchers at Risk

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 10, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    DEF CON 34 – Las Vegas – Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn’t distinguish between malicious hackers and those working in good faith. But change may finally be coming.

    Cybercrime is accelerating rapidly, requiring a holistic approach to curb threats. Security researchers who responsibly disclose vulnerabilities are one way to address burgeoning risks against governments, businesses, and individuals, but many countries have not updated their policies and laws to reflect that, Katharina Sommer, NCC Group’s director of government affairs and analyst relations, tells Dark Reading.

    Sommer found that 15 countries worldwide have implemented or are considering some level of legal protection for researchers. But that’s less than 10% of countries, considering 154 have cybercrime statutes, so risks remain high.

    New research by Sommer demonstrates that it is possible for countries to implement policies that safeguard both ethical hackers and user privacy, offering a blueprint for broader reform. She presented the research, which she will use to lobby the UK government, during a DEF CON 34 session titled, “Legally Hacked: How Countries Decide When Security Research Is Allowed.”

    Related:AI-Generated Patches Fail Half the Time

    “It hinges upon how you structure the law and write the legislation, and how much trust you have in your judicial system ultimately,” Sommer says. “And I think that’s the common challenge.”

    ‘It’s Still Done in Good Faith’

    NCC Group has, for the past seven years, been running a campaign to reform the UK Computer Misuse Act, which served as the catalyst for Sommer’s new research. Though it serves as the primary UK law to address unauthorized access to computer systems, hacking, and general cybercrime, UK Parliament enacted it in 1990 and does not differentiate between malicious activity and good faith research. Therefore, security researchers could face imprisonment or fines if found guilty of breaking the law.

    In theory, the law makes sense — it states hackers need the consent of the system owner — but it’s outdated, and that affects the way security and threat intelligence research operations run, Sommer warns.

    “But as threats have grown and attackers have advanced, and sort of cybersecurity has evolved as a profession, there is now a lot of security and vulnerability research happening that isn’t consented to, or isn’t authorized,” she adds. “But it is still done with good faith intention and with the purpose of improving cyber resilience for the greater public good.”

    Related:No Perfect Fix for AI Browser Prompt Injection Flaws

    Working with policymakers to improve cybersecurity regulations can be frustrating. Sometimes it feels like screaming, “Would anyone like to talk about cyber?” into the void, Sommer says, noting policymakers often dump it in a bucket with general technology laws.

    And while awareness of threats continues to grow, she notes an attention curve issue where major incidents are repeatedly viewed as “wake-up call” events, only to dwindle away until the next attack occurs.

    Updating Cybercrime Laws

    During King Charles’ speech in May, the UK government made a commitment to a national security bill that would encompass reforming the Computer Misuse Act, including legal defenses. Those actions inspired Sommer to take the research further.

    Now, she hopes reforms will happen as quickly as possible, but knows she still has work to do.

    “We looked at what a lot of other countries have been doing, so we can say to the UK government, ‘You’re falling behind, guys, let’s do something,'” Sommer says.

    Learning what Portugal did was a “watershed” moment for Sommer, who says the country made massive strides when policymakers implemented two directives. In 2025, Portugal lawmakers modified their cybercrime law to establish a safe haven for good-faith security researchers.

    Related:AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls

    “This legislative initiative arises from an awareness not only of the pressing seriousness posed by multiple cyber threats, but also of the high disruptive potential of their hostile actions against digital assets,” the decree law states.

    Once Sommer discovered Portugal’s updates, she decided to examine other countries. Language barriers presented difficulties, but she fed the United Nations (UN) Trade and Development agencies Global Cyberlaw Tracker into a large language model (LLM) and prompted it to tell her which countries had some kind of safe harbor or legal protections for good faith security researchers. She used the results as the baseline of the research.

    Sommer discovered some surprises too; many Latin American countries, including Argentina, Chile, and Panama, all implemented some level of defenses. “Panama, I think, is probably the most relevant because they’ve implemented something that protects people who produce hacking tools,” she says.

    Understanding the CICIC-Based Taxonomy

    Prior to traveling to Las Vegas, Sommer informed the UK government of her impending DEF CON 34 talk and research, highlighting the long list of countries that already implemented new policies. More importantly, she created an actionable plan based on five principles referred to as “CICIC”: conduct, intent, consensus, institution, and conditionality.

    Conduct, for example, refers to laws that examine and regulate the activity rather than the actor. Legal defenses should apply to anyone undertaking activity for the purpose of improving cybersecurity, which is more scalable and covers a broader range of security researchers, she explains.

    Consensus defines what “good faith” activity actually looks like. For example, researchers should willingly report vulnerability findings in a timely manner and not extort anyone, she says. Conditionality refers to conditions researchers must follow, such as not deploying distributed denial of service (DDoS) attacks and not retaining personal data for longer than necessary.

    “We’ve engaged with the security research community and, more or less, asked them where they would draw the line on the kind of activities that they would want to be able to undertake under a defense, and they were incredibly cautious and incredibly responsible about,” she says. “So, for us that was really proof to say to law enforcement, ‘We’re not going to open the floodgates.'”

    Cybercrime Laws outdated Put researchers Risk Security
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

    1 in 5 people may carry this hidden genetic heart risk

    Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

    OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

    Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

    When Credentials Are No Longer Enough: Device Trust in the AI Era

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Aptoide becomes the first rival app store to return to Google Play in the US

    August 10, 2026

    Premium seats are coming to ChatGPT Business

    August 10, 2026

    Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

    August 10, 2026

    TaoWeave’s TAO sales test its treasury strategy

    August 10, 2026
    Latest Posts

    Harbour Energy’s US arm advances repair plan after riser leak at Gulf of America oil & gas asset

    July 24, 2026

    Beavers restored a volcano-scarred river. Now it’s at risk again

    July 24, 2026

    China’s Tianwen-1 captures interstellar comet 3I/ATLAS near Mars

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Aptoide becomes the first rival app store to return to Google Play in the US

    August 10, 2026

    Premium seats are coming to ChatGPT Business

    August 10, 2026

    Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

    August 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.