The UK government has announced plans to reform its outdated Computer Misuse Act to provide statutory defenses for ethical hackers and security researchers, aiming to protect them from prosecution when responsibly disclosing vulnerabilities. British security minister Dan Jarvis emphasized the need for these changes, acknowledging that the current law constrains legitimate research and that updated legislation would help strengthen the country's cyber resilience. The proposed reforms would allow researchers to spot and share vulnerabilities under certain safeguards, aligning the UK with similar protections already enacted in countries like the Netherlands, France, and Belgium.
Meanwhile, Portugal has passed new legislation granting protections to security researchers, provided they do not seek financial gain or breach data protection laws. This move has been welcomed by the security community and increases pressure on the UK to modernize its own laws. The Portuguese law is described as "tightly scoped," requiring that security actions be strictly proportionate, and is seen as a positive step toward creating a safer environment for responsible vulnerability disclosure across Europe.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
The UK government said it intends to examine reforms to the 1990 Computer Misuse Act, including creation of a statutory defense for security researchers, signaling a policy shift but not yet a finalized change.
Portugal amended its cybersecurity law to protect security researchers who identify and disclose vulnerabilities in good faith, provided their actions are proportionate, in the public interest, and not aimed at improper economic gain.
The UK Computer Misuse Act became law in 1990, creating offenses for unauthorized access that later drew criticism for exposing good-faith security researchers to legal risk.
Security researcher Daniel Cuthbert was convicted under the UK Computer Misuse Act for good-faith testing, a case frequently cited as evidence of the law's inflexibility toward ethical hacking.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.