A 1990 Law Could Send Ethical Hackers to Prison. Dozens of Countries Are Fixing That.
Researcher Katharina Sommer mapped which nations protect good-faith security work and built a five-point blueprint to push the UK's creaking Computer Misuse Act into the present day.

Key points
- The UK Computer Misuse Act, passed in 1990, does not distinguish between criminal hackers and security researchers acting in good faith, leaving the latter exposed to prosecution.
- Only 15 countries worldwide have implemented or are actively considering legal protections for ethical security researchers, out of 154 that have cybercrime laws at all.
- NCC Group director Katharina Sommer presented her comparative research at DEF CON 34 in Las Vegas, having first briefed the UK government before attending.
- Portugal updated its cybercrime law in 2025 to create an explicit legal safe harbour, meaning a protected space, for good-faith security researchers.
- The UK government committed, during King Charles' May speech, to a national security bill that would include reforms to the Computer Misuse Act.
Security researchers spend their careers breaking into systems on purpose. The goal is to find the weak spots before criminals do, then report them so they can be fixed. Most of us benefit from that work every day, even if we never think about it.
But in the United Kingdom, doing that job could land you in prison.
Why would ethical hackers face criminal charges?
The Computer Misuse Act, the UK's main law against unauthorised access to computer systems, is 35 years old. Parliament wrote it in 1990, before the modern security-research profession existed, and it contains no carve-out for people acting in good faith. Break into a system without the owner's explicit permission and you are, technically, a criminal, even if your only intention was to help.
Katharina Sommer, director of government affairs at cybersecurity firm NCC Group, has been pushing to fix that for seven years. At DEF CON 34, the large annual security conference held in Las Vegas, she presented new research mapping how other countries handle the same problem, first reported by Dark Reading.
Her finding is stark: only 15 countries out of 154 that have cybercrime statutes on the books offer researchers any meaningful legal protection. That is fewer than one in ten.
Which countries are getting this right?
Portugal is the standout. In 2025 its parliament amended its cybercrime law to explicitly shield good-faith security researchers. The decree law states plainly that lawmakers recognised the "pressing seriousness" of cyber threats and the disruption hostile actors can cause.
Sommer called discovering Portugal's approach a "watershed" moment. Latin America surprised her too. Argentina, Chile, and Panama have all put some level of protection in place. Panama's version is especially broad: it covers people who build hacking tools, not just those who use them in research.
To map the full picture, Sommer fed the United Nations Trade and Development agency's Global Cyberlaw Tracker into a large language model, which is an AI system trained to read and summarise text, and asked it to identify countries with researcher safe harbours. She used those results as her starting point, then dug into the details herself.
What does a fair law actually look like?
Sommer's blueprint organises around five principles she calls CICIC.
| Principle | What it means in plain English |
|---|---|
| Conduct | The law judges the activity, not who did it |
| Intent | Good-faith purpose must be demonstrable |
| Consensus | Researchers must report findings promptly and not extort anyone |
| Institution | Regulators and courts both have a role |
| Conditionality | Certain acts remain off-limits regardless (for example, DDoS attacks, which flood a system with fake traffic to knock it offline, and holding personal data longer than needed) |
Sommer consulted the security-research community itself while drawing up the conditions. She was struck by how cautious researchers were about where they would draw their own line. "For us that was really proof to say to law enforcement, 'We're not going to open the floodgates,'" she told the DEF CON audience.
What should ordinary people take from this?
Legal uncertainty does not just hurt researchers. When researchers cannot work freely, flaws in the apps, medical devices, and banking systems you use go unfound for longer. Criminals find them instead.
The UK government's commitment to a national security bill that would reform the Computer Misuse Act is a real step. It is not law yet, and Sommer is clear she has lobbying work still ahead. But 2025 Portugal shows the change is achievable.
If you use any digital service, that reform affects you directly.
Common questions
Do I need to do anything because of this?
Not immediately. This is a policy debate, not an active attack. The risk here is long-term: fewer legal researchers means fewer discovered flaws means more vulnerabilities sitting open in products you use.
Why does this keep being a problem if everyone agrees researchers are helpful?
Policymakers often group cybersecurity with general technology law, and attention tends to spike after a major incident then fade. Sommer's comparison of 15 countries is designed to make the argument harder to shelve by showing the UK what it is missing.



