Summary
- A Lords amendment would require a review within 12 months into a statutory defence for legitimate cyber-security activity.
- Researchers, vulnerability testers, and threat-intelligence practitioners are explicitly included alongside possible safeguards around authorisation, proportionality, and reporting.
- Previous reviews acknowledge legal uncertainty, while law enforcement has warned that a defence could create grey areas open to abuse.
A long-running attempt to protect legitimate cyber-security research from prosecution under Britain’s Computer Misuse Act has returned through the Cyber Security and Resilience Bill, with peers proposing that ministers be required to decide whether researchers need a statutory defence when examining computer systems without conventional prior authorisation.
The amendment, tabled by Liberal Democrat peer Lord Clement-Jones, would require the Secretary of State to complete and publish a review within 12 months of the cyber bill becoming law. That work would examine whether a defence under section 1 of the Computer Misuse Act is necessary or desirable for people carrying out legitimate cyber-security activity intended to improve the resilience of networks and information systems.
Its scope explicitly includes cyber-security researchers, vulnerability testers, and threat-intelligence practitioners acting in good faith. Ministers would also have to consider conditions and safeguards around any defence, including authorisation, proportionality, reporting, and approaches adopted in other jurisdictions.
The proposal would not itself create legal protection, nor has Parliament accepted it. Instead, it would impose a timetable on a policy debate that has continued for several years and require the government to explain whether it intends to legislate after the review.
A 1990 law governs modern security research
The Computer Misuse Act makes unauthorised access to computer material a criminal offence. Its technology-neutral language has allowed the legislation to survive several generations of computing, although the emphasis on authorisation can create uncertainty for researchers analysing malware, testing public-facing systems, or investigating vulnerabilities without a contract from every owner whose infrastructure becomes part of the work.
The Home Office’s previous review found that some respondents believed the Act inhibited legitimate public-interest activity by cyber professionals and researchers. Statutory defences were consequently included among the areas requiring further examination alongside law-enforcement powers and other reforms.
Researchers argue that uncertainty can discourage work that helps organisations discover weaknesses before attackers exploit them. Reform campaigners want professionals acting in the public interest to be able to demonstrate that their conduct met defined safeguards rather than relying principally on prosecutorial discretion or assumptions about whether authorities are likely to bring a case.
Broad protection for unauthorised access nevertheless creates a legal problem of its own because good faith can be disputed after a system has already been touched. An offender could claim to have been conducting research, while a legitimate researcher may probe further than the system owner considers proportionate after discovering an initial vulnerability.
The dispute increasingly concerns safeguards
Law-enforcement evidence has previously reflected that concern. The National Crime Agency has warned that a defence could create grey areas capable of being exploited by offenders or encouraging private vigilantism, while noting that research undertaken with explicit permission can already be carried out lawfully.
The Lords proposal attempts to move beyond a simple argument over whether researchers have good intentions by requiring any review to examine safeguards. Authorisation, proportionality, responsible reporting, and expected behaviour after a vulnerability is discovered could all determine whether particular activity qualified for protection.
Versions of those principles already operate in vulnerability-disclosure programmes, where organisations specify which systems researchers may test, techniques that are prohibited, how findings should be reported, and how much time a company receives to resolve a weakness before publication. A statutory defence would have to work more broadly, including where an organisation has not established such a programme.
The question has moved through several parliamentary routes without producing a legislative settlement. Earlier proposals were debated or withdrawn, while government reviews accepted that reform deserved further consideration. The latest amendment therefore represents another attempt to force a decision rather than the first recognition that the 1990 framework may need adjustment.
Embedding the review in the Cyber Security and Resilience Bill also connects the argument directly with the systems that security researchers are trying to protect. The wider legislation seeks stronger resilience across essential services and technology suppliers, yet vulnerability discovery and threat intelligence do not always occur inside neatly pre-authorised laboratory conditions.
Whether the Lords accepts the amendment remains unresolved, and even passage would lead first to another review rather than an immediate change in the law. Its practical effect would be to give ministers a deadline for stating whether legitimate cyber-security activity can be accommodated more explicitly inside legislation written before the commercial internet became part of everyday business infrastructure.












