DED0010
1.1. It is impossible to consider the resilience and integrity of the UK’s democratic institutions without acknowledging the role of cybersecurity professionals working to tackle and minimise the harm of cyber threats by criminals and foreign actors and, therefore, the implications of the Computer Misuse Act 1990 (CMA).
1.2. The CMA was written in 1990. 33 years on, the legislation is now the main regime covering cybercrime and criminalises a large proportion of research that UK cyber security professionals can carry out to protect the UK’s critical national infrastructure (CNI), including electoral infrastructure.
1.3. The CyberUp Campaign has long been advocating for reform of the UK’s outdated CMA to update and upgrade cybercrime legislation to protect our national security and resilience to cyber threats. The Campaign brings together a broad coalition of supporters across the UK cybersecurity sector and beyond.
1.4. A reformed Act will remove uncertainty for cybersecurity researchers as they look to help the government, citizens, and businesses tackle the cyber threats the UK Government’s National Cyber Strategy 2022 and Government Cyber Security Strategy 2022-2030 has identified, including attempts to disrupt and manipulate democratic institutions.
1.5. Sir Patrick Vallance recognised this and called on the government to urgently reform the CMA, recommending the introduction of a statutory public interest defence in the CMA as part of his Digital Technology Regulation Review in March 2023.
1.6. The Chancellor agreed to implement all nine review recommendations of Sir Patrick’s review. The Home Office has since launched a ‘multi-stakeholder process’ to consider the suitability of defences for inclusion in the Act.
1.1. The Government has now confirmed that more work was required before they could legislate, but it is the Campaign’s view that this work has already been done through extensive industry consultation.
1.2. Over 30 months have passed since the Government first announced its review of the CMA. We need urgency and pace to achieve reform quickly. By meeting the urgency required and looking to best practice from our international partners and private sector, we can help to ensure UK core democratic functions and infrastructure are sufficiently resilient against cyberattacks.
2.1. As societies move their operations online, we must ensure that they are resilient against increasing cyberattacks.
2.2. ONS data shows that computer misuse increased by 89% (to 1.6 million offences) in 2022 compared with the year ending March 2020, driven by a large increase in unauthorised access to personal information (hacking) offences.
2.3. Indeed, hacking offences more than doubled in the year ending March 2022 (to 1.3 million offences) compared with the pre-coronavirus year ending March 2020. This included victims' details being compromised via large-scale data breaches, and victims' email or social media accounts being compromised.
2.4. This is an incredibly pressing issue. Against a fast evolving geopolitical landscape, democratic societies such as the UK and allies are facing increased risks of state and state-affiliated cyber threats.
2.5. As outlined in the NCSC’s Annual Review 2023, electoral interference using mis and dis-information, cyber attacks, and other methods has – and will continue to – take place. Threat actors can exploit vulnerabilities in election infrastructure, casting doubt over the integrity of electoral processes, eroding social cohesion and support for the results.
2.6. Against this background, it has never been more important for the UK cyber industry to be able to do all it can to protect UK democratic institutions and improve national cyber resilience. A reformed Act is key to delivering effective actions against such acts and several other UK government priorities, including tackling disinformation, illicit finance and corruption, and fraud.
3.1. The cybersecurity industry works closely and in concert with law enforcement, intelligence agencies and CNI operators, including electoral bodies, to defend the UK against cyber crime and geo-political threat actors. Vulnerability researchers, for example, identify vulnerabilities in systems that could be exploited by malicious actors for nefarious purposes and work with CNI operators to fix them. Threat intelligence researchers, meanwhile, help to detect cyber attacks, gain insight into attackers and victims, lessen the impact of incidents, and prevent future ones. The UK Government’s National Cyber Strategy 2022 recognises the value of this important work, committing to build valuable and trusted relationships with the security researcher community to deliver a reduction in vulnerabilities.
3.2. This is a settled public-private partnership that helps keep the UK – its citizens and its institutions – and its international partners safe from harm. But if it is the case that current legal restrictions are holding back cybersecurity researchers from carrying out certain activities, impeding their ability to supply vulnerability research and rich threat intelligence to support national cyber defence operations and law enforcement, then the CMA is having a detrimental impact on the UK’s national security.
3.3. The CMA blanketly prohibits all unauthorised access to computer material, irrespective of intent or motive. This leaves the UK’s cyber defenders – including those who work in-house within CNI operators – having to act with one hand tied behind their back because much of their defensive work requires the interaction with compromised victims’ and criminals’ computer systems where owners have not, or are unlikely to, explicitly permit or authorise such activities.
3.4. These restrictions in gathering high quality actionable intelligence or proactively identify certain vulnerabilities make it challenging to stay ahead of hostile threat actors as the Government alone cannot reasonably provide the required capacity and capabilities given the scale of the challenge.
3.5. Evidence for this hypothesis was provided by the CyberUp/techUK survey, which found that the restrictions were having an impact. 58 per cent of researchers revealed that the CMA has acted as a barrier to them or their colleagues conducting cyber security or threat intelligence research. Separate answers also suggested that 23 per cent of researchers indicated that they believed the CMA had indeed inhibited them from preventing harm to businesses or citizens, whereas a smaller percentage (10 per cent) believed that the Act had inhibited them from preventing a threat to national security.
3.6. The figures were higher for those responding on behalf of organisations, with 40 per cent indicating the CMA had inhibited employees of their organisation from preventing harm to businesses or citizens, and 20 per cent that the Act had inhibited employees of their organisation from preventing a threat to national security.
3.7. This is consistent with other polling figures on this topic which found that two thirds of UK adults (66%) are inclined to support a change in the law to allow cybersecurity professionals to carry out research to prevent cyber attacks, such as scanning the computers of cyber criminals to gain insight into their techniques or victims – provided the professionals are acting in the public interest / good faith.
3.8. A Freedom of Information request also revealed that two thirds of respondents to the Home Office 2021 Call for Information raised concerned over the current protections in the Act or sought clarifications of those protections.
4.1. The CyberUp Campaign wants to see the inclusion of a ‘statutory defence’ in the CMA so that cybersecurity professionals who are acting in good faith can defend themselves from prosecution by the state and from unjust civil litigation.
4.2. Providing better support to our cybersecurity professionals will ensure better cybersecurity and overall security.
4.3. Our research has found that by reforming the CMA in this way, the UK could unlock a further £2.21bn in revenue for the sector, alongside creating an additional 8,700 jobs in the cyber workforce[1].
4.4. Allowing industry partners to carry out these legitimate activities would also have the effect of ‘widening the net’ that state bodies such as the National Cyber Security Centre (NCSC) and National Crime Agency (NCA) are able to cast as they look to tackle cyber threats and improve national cyber resilience.
4.5. In response to understandable questions about how a reformed CMA would work in practice—striking the right balance between protecting the cybersecurity ecosystem and prosecuting criminals effectively—the CyberUp Campaign has developed a framework, in consultation with industry and legal experts, that could guide the application of a ‘statutory defence’. This has been supplemented with additional research that establishes an industry consensus of which legitimate cybersecurity activities should be legally permissible.
4.6. This framework establishes a set of principles to be taken into account when determining whether an action should be defensible and by whom:
4.6.1. The ‘Harm-Benefit Principle’ – recommends that the (prospective) benefits of the act must outweigh the (prospective) harms, including where action was necessary to prevent a greater harm.
4.6.2. The ‘Proportionality Principle’ – recommends that an actor must also be able to show that they have taken reasonable steps to minimise the risks of causing harm in the act of unauthorised access.
4.6.3. The ‘Intent Principle’ – the actor must be able to demonstrate that they have acted in good faith, in an honest and sincere way.
4.6.4. The ‘Competence Principle’ – recommends that an actor’s level of qualification/accreditation and/or membership of a professional body becomes one of a number of factors to consider when applying a statutory defence.
4.7. As noted above, the introduction of a statutory defence in the CMA has also been recommended by Sir Patrick Vallance as part of his Digital Technology Regulation Review: “We recommend amending the Computer Misuse Act 1990 to include a statutory public interest defence that would provide stronger legal protections for cyber security researchers and professionals, and would have a catalytic effect on innovation in a sector with considerable growth potential”.
More information on those principles and consensus is available here:
5.1. The Home Office conducted a Call for Information into the effectiveness of the Act, which concluded in June 2021. Two-thirds of respondents to the Home Office’s Call for Information agreed that they did not believe that the current Act offered sufficient protections for legitimate cybersecurity activities.
5.2. On 7th February 2023, Security Minister Tom Tugendhat provided an update to Parliament stating that more work was needed to consider the feasibility of a statutory defence.
5.3. A month later, Sir Patrick Vallance recommended the introduction of a statutory public interest defence in the CMA as part of his Digital Technology Regulation Review. The Chancellor then committed to implement the review’s nine recommendations in the Budget Statement in March.
5.4. The Home Office has since launched a ‘multi-stakeholder process’ to consider the suitability of defences for inclusion in the Act. As part of this, the CyberUp campaign has been supporting the Home Office in liaising with industry to provide further clarity on key areas of concern regarding the introduction of statutory defence, namely what constitutes a legitimate activity.
5.5. During the 30th January 2024 Public Bill Committee for the Criminal Justice Bill, Home Office Minister, Chris Philp MP updated the House confirming that although “the Government broadly support the sentiment behind the new clause [introducing a statutory defence]… but this is a very complicated area.”
5.6. The Government said more work was required before they could legislate, but it is the Campaign’s view that this work has already been done through extensive industry consultation. The Joint Committee on the National Security Strategy’s recent ransomware inquiry criticised government delays and concluded that “the Minister for Security’s acknowledgement of how out of date the Computer Misuse Act is does not excuse the lack of progress which has been made to legislate in this space. It has been two-and-a-half years after its main consultation and 33 years since that dated legislation received Royal Assent. It is hard to see how the Criminal Justice Bill brought forward by the King’s Speech 2023 will sufficiently cover the gap left by the outdated CMA.”
5.7. Over 30 months have passed since the Government first announced its review of the CMA. We need urgency and pace to achieve reform quickly. By meeting the urgency required and looking to best practice from our international partners and private sector, we can ensure UK core democratic functions and infrastructure are sufficiently resilient against cyberattacks.
5.8. By committing to this essential reform and recognising its urgency, the Government would be providing the necessary reassurance to the UK cybersecurity industry that they will be given the necessary support and framework to effectively tackle 21st century cyber threats, fight fraud, misinformation, and to be able to grow and compete with international players.
6.1. The CyberUp Campaign has long been advocating for reform of the UK’s outdated CMA 1990, to update and upgrade cybercrime legislation to protect our national security and resilience to digital crime, and to promote the UK’s international competitiveness in the rapidly evolving global technology sector. The campaign brings together a broad coalition of supporters across the UK cybersecurity sector and beyond (www.cyberupcampaign.com).
5 March 2024
[1] Based on calculations from the CyberUp/techUK survey, which assessed the views of industry as to how Computer Misuse Act restrictions were affecting the ability of the industry to grow and compete. It asked respondents to put a specific value, in percentage terms, of the amount a change would increase the revenue and number of employees of their organisation. On the question of an increase in revenue, of those that responded, 33.33 per cent suggested that they would see an increase of 1-10 per cent, 16.67 per cent suggested they would see an increase of 10-20 per cent, and 50 per cent suggested they would see an increase of 20+ per cent. Averaging these, the expected revenue increase would be nearly 20 per cent across the entire sector. Multiplying this by the most recent 2022 UK government sectorial analysis of the total revenue of the cyber sector in the UK of £10.1bn, it gives an increased revenue of £2.02bn for the sector from a change in legislation. A similar calculation for responses about increases in numbers of employees found an average increase in percentage terms of nearly 15 per cent. When multiplied by the existing workforce of the sector bases on the same UK government estimations, this leads to an increase of about 7,905 jobs resulting from a change in legislation.