Written by 9:28 am Blog

Peers propose report into Computer Misuse Act reform

beebright – stock.adobe.com After previous proposals were brushed aside, Computer Misuse Act …
Peers propose report into Computer Misuse Act reform

beebright – stock.adobe.com

After previous proposals were brushed aside, Computer Misuse Act reform may be back on the agenda under a new amendment to the Cyber Security and Resilience Bill

By

Published: 27 Aug 2026 14:28

The UK government will have 12 months from the passing of the upcoming Cyber Security and Resilience Bill (CSRB) to publish a review of whether it is “necessary or desirable” to change the Computer Misuse Act of 1990 to shield legitimate cyber security professionals from the possibility of prosecution in the course of their regular duties – should new amendments to the bill introduced this week go forward.

In an explanatory statement, Tim Clement-Jones, who is backing the amendment, wrote: “This new clause seeks to place a statutory duty on the secretary of state to review, within 12 months, whether a statutory defence under section one of the Computer Misuse Act 1990 for good-faith cyber security researchers and vulnerability testing is needed to improve the UK’s cyber resilience, and to report to Parliament.”

The amendment revives the long-awaited possibility of reform of the outdated CMA, which earlier this year appeared to be getting somewhere after being slated for inclusion in a new National Security Bill, announced during the King’s Speech in May.

As previously reported by Computer Weekly, the CMA, which was introduced in the dying days of Margaret Thatcher’s premiership, defines the offence of unauthorised access to a computer, but more than 30 years on the legislation’s wording fails to account for the need for legitimate threat researchers, ethical hackers and red teams to occasionally access a system covertly in the course of their work.

According to campaigners who have been trying for years to get the government to enact changes to the CMA, the introduction of a statutory defence for security pros could unlock massive growth for the UK’s cyber security industry, potentially up to £2.4bn per annum.

Clement-Jones’ proposed review will consider factors such as the position of cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith, the conditions and safeguards around areas such as authorisation, proportionality and transparent reporting that a statutory defence should contain, and the approaches taken in other countries to the issue.

On conclusion of the review, the final report will have to set out whether or not ministers intend to advance proposals for a statutory defence, and the timetable for doing so.

A spokesperson for the CyberUp campaign for CMA reform said: “This amendment rightly recognises that providing legal certainty for legitimate cyber security activity is essential to strengthening the UK’s cyber resilience. If the UK is to remain a world leader in cyber security, it must give professionals the confidence to identify and address emerging threats.

“While the government has already committed to CMA reform in the forthcoming National Security Bill, we welcome the continued efforts of supportive parliamentarians to keep Computer Misuse Act reform on the Parliamentary agenda.”

Previous reform attempts rebuffed

Clement-Jones has previously been vocal on the need to reform the Computer Misuse Act. At the end of 2024, he teamed up with Chris Holmes in an attempt to introduce amendments to what was to become the Data (Use and Access) Act 2025.

These amendments, had they made the final cut, would have tweaked the CMA in such a way that security pros would have been able to prove actions that went against the letter of the law were either necessary to detect or prevent crime, or otherwise undertaken in the public interest. However, they were withdrawn after the government described them as “premature”.

A second attempt in January 2025 was ultimately shot down by the then science minister Patrick Vallance on the basis that the amendments could be used as a loophole by malicious actors, and that more robust oversight and safeguards were needed to prevent any changes to the CMA from becoming a burden or hindrance to law enforcement activities.

This article was updated at 18:45 BST on 27 August to include a quote from the CyberUp campaign and remove an erroneous reference to the National Security (State Threats) Act 2026.

    Read more on Hackers and cybercrime prevention

    Article Source

    Close