L

Lord Clement-Jones (LD)

Speaking in the House of Lords on 4 March 2026

Debate

Crime and Policing Bill

Contribution

My Lords, Amendment 367 is also in the name of my noble friend Lady Doocey, and there is rather better news on this amendment as a result of conversations with the Minister. I warmly welcome the significant movement the Government have made in this area. This is reflected both in the recent policy paper on introducing statutory defences into the Computer Misuse Act, which they have shared with me, and in the constructive meeting I recently held with the noble Lord, Lord Katz, for which I thank him. The principle we have long championed, that a cyber security researcher’s intent and motivation should be a relevant factor in law, has finally been acknowledged. As the industry has told us for decades, the 1990 Act is a relic of a different era. It was drafted when only 0.5% of people used the internet. It is now being asked to govern a world of generative AI and industrialised cyber warfare. Its current blanket prohibition on unauthorised access makes no distinction between a malicious hacker and a white-hat security researcher. Under current law, our cyber defenders are forced to operate with one hand tied behind their backs, fearing prosecution for the very activities that keep our national infrastructure resilient. This is not just a legal anomaly; it is a direct threat to UK resilience. However, while the policy paper is a major step forward, we must ensure that it results in robust statutory protection, not just a vague promise of prosecutorial discretion. Reliance on the good faith of prosecutors is not a long-term solution for an industry that requires absolute legal certainty. Our amendment would provide that framework—a defence where actions were necessary for the detection or prevention of crime or justified in the public interest. I ask the Minister to address some of the following critical concerns arising from the Government’s own policy paper. Because of the time of night, I am going to abbreviate it to give him the headings and write to him subsequently. First, the accreditation bottleneck is a national security risk. The whole question of having to have chartered-level UK Cyber Security Council accreditation will create a bottleneck. The definition of “suitably qualified” suggests that only those with membership of professional bodies such as the UK Cyber Security Council will be valid, but will it recognise in due course that those with established industry experience, who may not hold formal academic credentials, will also qualify? The “no supervision” rule is operationally unworkable, and the scope of non-intrusive activity seems somewhat random. The vulnerability duty creates a legal trap. The paper requires a researcher who discovers a vulnerability to make all reasonable efforts to report it to the system owner as soon as practicable, but the paper itself acknowledges the difficulty of identifying system owners. The bug bounty market is under threat. The paper prohibits permitted persons from requesting or demanding payment for reporting a discovered vulnerability. The global bug bounty market, where organisations invite researchers to find and responsibly disclose flaws in exchange for payments, is worth hundreds of millions of pounds and is a cornerstone of modern cyber defence. The paper’s drafting risks chilling this entire ecosystem. Then we have statutory versus non-statutory protections. The paper acknowledges that reliance on the good faith of prosecutors is not a solution. Can the Minister commit to placing these defences in the Bill during this Session? If not, what vehicle do the Government envisage? Could the upcoming Cyber Security and Resilience (Network and Information Systems) Bill accommodate this reform? We need a clear answer on the legislative timetable. The paper does not seem to cover the public sector—the National Cyber Security Centre itself—yet the proposed defence appears directed entirely at privately accredited individuals. That is a question that needs answering. We cannot allow technological development to race ahead of democratic deliberation. Our cyber security professionals need the clarity of the law to protect the UK in 2026 and beyond. I very much hope that this is a moment of genuine policy momentum, so let us produce legislation that is workable, inclusive and legally certain. I am very hopeful that the Minister will continue the dialogue over this policy paper. I beg to move.

More from Lord Clement-Jones (LD)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.

Partner sites