M
Member
Speaking in the House of Lords on 7 September 2026
Debate
Cyber Security and Resilience (Network and Information Systems) BillContribution
164: After Clause 58, insert the following new Clause—
“Computer Misuse Act 1990: statutory defence for cyber security activities(1) The Secretary of State must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 (unauthorised access to computer material) for persons carrying on legitimate cyber security activities is necessary or desirable to improve the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities.(2) The review under subsection (1) must consider, in particular—(a) the position of cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith,(b) the conditions and safeguards (including as to authorisation, proportionality and reporting) that any such defence should contain, and(c) the approaches taken in other jurisdictions.(3) On concluding the review, the Secretary of State must lay before Parliament a report which sets out—(a) the findings and conclusions of the review, and(b) whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so.”Member’s explanatory statement
This new clause seeks to place a statutory duty on the Secretary of State to review, within 12 months, whether a statutory defence under section 1 of the Computer Misuse Act 1990 for good-faith cyber security researchers and vulnerability testing is needed to improve the UK’s cyber resilience, and to report to Parliament.
About Hansard
Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.