Somewhere in the UK right now, a security researcher is sitting on a vulnerability report and wondering whether sending it makes them a criminal. That isn’t paranoia. The Computer Misuse Act of 1990 has criminalized unauthorized access for thirty-six years, and “unauthorized” has always been the prosecutor’s call, not the researcher’s. A vendor doesn’t like the way you found their bug? You’re suddenly the threat.
That uncertainty has been the silent tax on UK cybersecurity work for a generation. This week, briefing documents released alongside the King’s Speech finally proposed reforming the CMA to shield legitimate security researchers from prosecution. The change is buried in a larger national security package, but for the people doing the actual work of breaking things to keep them safe, it’s the biggest story of the year.

The Law That Outpaced the Threat
The CMA was written when most “hackers” were teenagers dialing into university mainframes for fun. It treats access without authorization as the offense, regardless of intent or outcome. A researcher who probes a public-facing service to demonstrate a flaw they intend to report responsibly is, under a strict reading of the statute, committing the same offense as someone exfiltrating customer data.
Prosecutors rarely pursue researchers acting in good faith. They don’t have to. The chilling effect does the work for them. Talk to anyone who reverse-engineers commercial software for a living, and you’ll hear the same calculation: the legal risk of telling the vendor is sometimes higher than the risk of just walking away. That’s a terrible trade for everyone except the people sitting on the bugs.
Cisco Talos’s Philippe Laulheret described his work this week as breaking things to keep them safe. It’s an old description of an old craft. What’s new is the volume. AI-driven discovery systems like Microsoft’s MDASH and OpenAI’s GPT-5.5 are pulling vulnerabilities out of codebases at a pace human teams cannot match, and the UK’s AI Security Institute has now confirmed that frontier models are reaching expert-level capability for bug finding. The pipeline is about to flood. The legal framework was never going to survive it.
What Reform Actually Changes for Cybersecurity Work
The proposed reforms don’t legalize everything. They create a defense for researchers operating in good faith, with reasonable belief that their actions are necessary to identify a security flaw, and with proportionate scope. That’s narrower than the carte blanche some advocates wanted. It’s still a working framework. The Department for Science, Innovation and Technology has been consulting on this language since 2024, so the legal wording isn’t a surprise. The political will to actually pass it is.
For UK cyber security teams, the practical implications start before the bill passes. Internal red teams, threat detection engineers, and incident response staff frequently operate in legal gray zones when probing third-party services, analyzing malware that touches external infrastructure, or coordinating disclosure with vendors who’d rather sue than patch. A statutory defense changes the negotiating posture. It also changes the calculation for organizations deciding whether to maintain a vulnerability disclosure program in the first place.
The story is bigger than the UK, though. Several jurisdictions, including parts of the EU and the US, still treat researcher activity with the same default suspicion. The CMA was a model law when it was written. If the reform lands, it becomes a different kind of model: one that other parliaments will get pressure to copy.
What to Do While the Lawyers Still Catch Up
If you run a security team, don’t wait for legislation in your jurisdiction. The protection that matters most is the protection you build into your own processes. Document scope before you start. Get authorization in writing, with named systems and time windows. If you’re testing third-party infrastructure, even infrastructure your employer pays for, treat it as a separate engagement requiring its own letter of authorization. Verbal sign-off from a sysadmin won’t save you in court.
If you receive vulnerability reports, publish a security.txt file with a real address. Set clear safe harbor language: researchers acting in good faith won’t be referred for prosecution. Coordinate with legal counsel before you respond to a disclosure with anything resembling a threat. Some of the worst CMA cases in UK history started with vendor lawyers writing a cease-and-desist that the police later treated as evidence of unauthorized access. Don’t be that vendor.
For brute-force exposure on internet-facing assets, the controls haven’t changed: aggressive rate limiting, phishing-resistant MFA on every administrative interface, firewall rules that fail closed, and continuous monitoring for credential stuffing patterns. Defense in depth is what keeps a researcher’s responsibly disclosed bug from turning into a press release about your breach. The same security hardening checklist that protects you from FamousSparrow protects you from the embarrassing disclosure email you didn’t read in time.
For ongoing work, invest in your incident response runbook for the awkward case: the unsolicited report from someone you’ve never heard of. Build a triage path that doesn’t start with the legal team. Make a public commitment to non-prosecution for good-faith researchers, and mean it. The teams that handle disclosure well receive more disclosures. That’s not a coincidence.
The Real Stakes
Reforming the CMA won’t stop a single APT campaign. China’s FamousSparrow group will keep nesting in energy company networks regardless of what Parliament does this session. Ransomware operators don’t care about safe harbor language. What changes is the labor pool on the defense side. When researchers can do their jobs without lawyering up first, you get more researchers, more disclosures, and more bugs caught before nation-state actors find them. That’s the entire pitch for threat protection at scale.
Britain spent thirty-six years prosecuting curiosity. Reversing that posture won’t fix the threat landscape. It will fix the part of the threat landscape we’ve been making worse on purpose.
Frequently Asked Questions
- Does the UK CMA reform apply retroactively to past cases?
- No. The proposed defense applies prospectively once enacted. Researchers facing current proceedings still need to rely on existing defenses and prosecutorial discretion, not the pending reform.
- Will US-based researchers see similar protections soon?
- Not imminently. The DOJ updated its CFAA prosecution guidance in 2022 to deprioritize good-faith research, but no statutory safe harbor has been enacted. Several state-level efforts have stalled in committee.
- Should companies update their vulnerability disclosure policies before the law passes?
- Yes. Strong safe harbor language is independent of the statutory change and signals good faith to both researchers and regulators. It also reduces your own legal exposure when disputes arise.
Sources
- UK moves to shield security researchers in cybercrime law overhaul
- Breaking things to keep them safe with Philippe Laulheret
- OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities
- Microsoft’s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday
- China’s FamousSparrow APT Nests in South Caucasus Energy Firm
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
