L

Lord Clement-Jones (LD)

Speaking in the House of Lords on 7 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, Amendment 164 is in my name and, I am delighted to say, that of the noble Lord, Lord Arbuthnot of Edrom. Sadly, he is tied up next door with matters of national security—I hope that I am not giving away any secrets—and is unable to speak to this amendment, but I value the support that he has given as a long-standing campaigner for changes to the Computer Misuse Act. This amendment addresses a long-standing, globally recognised and increasingly dangerous absurdity in our criminal law: the fact that our primary cyber crime statute, the Computer Misuse Act 1990, criminalises the very cyber security professionals who are actively working to defend our country. The Computer Misuse Act is now 36 years old. It was drafted in 1990—an era before the world wide web had entered public consciousness, when less than 0.5% of the British public had ever sent an email and when the entire concept of proactive, ethical vulnerability research was completely unimagined. Because the Act was drafted at such a primitive stage of the digital revolution, it contains a blanket, indiscriminate prohibition on all unauthorised access to computer material. In its current form, it draws no legal distinction whatever between a malicious hacker, backed by a hostile foreign state and seeking to sabotage our critical national infrastructure, and an ethical, good-faith cyber security researcher—a “white hat” hacker, if you like—seeking to discover and responsibly disclose vulnerabilities before criminals can exploit them. The real-world consequence of this statutory blind spot is that British cyber defenders are forced to operate with one hand tied behind their backs. Consider the day-to-day operational reality: if an ethical researcher in the UK scans an internet-facing network, identifies a critical zero-day vulnerability that leaves an NHS hospital dataset or a municipal water control system exposed, and takes the basic technical steps necessary to verify the flaw, they have technically committed a criminal offence under Section 1 of the 1990 Act. They face prosecution and imprisonment, even if their actions were undertaken entirely in good faith, strictly in the public interest and followed by immediate responsible disclosure to the National Cyber Security Centre or the affected operator. I and others have received overwhelmingly passionate representations from the CyberUp campaign, representing what might be described as the elite of our domestic cyber security industry. Alongside the Criminal Law Reform Now Network and the NCC group, its evidence is stark. It says that the chilling effect of the Computer Misuse Act is actively undermining our national cyber resilience. Leading UK cyber security companies are routinely forced to prohibit their researchers conducting proactive threat intelligence gathering and vulnerability research on UK-based infrastructure because the legal risks are unacceptable. When British researchers identify an active cyber threat originating abroad, they are legally constrained from investigating the command and control servers if doing so involves touching a remote system without explicit owner authorisation. Meanwhile, our international competitors have moved ahead. The United States updated its Department of Justice charging policies explicitly to protect good-faith security research. Countries such as Portugal, France and Australia have established clear and legal safe harbours for ethical cyber defenders. As a direct result, British cyber talent and commercial investment are migrating overseas to jurisdictions where proactive defence is recognised as a public good, rather than a criminal act. During the Bill’s passage in the other place and during our Second Reading debate, the Government’s response was to agree with the principle of reform while arguing that this Bill is not the appropriate vehicle. Ministers pointed to an ongoing Home Office review and suggested that reform must wait for a hypothetical future security Bill. We have been waiting for the outcome of that Home Office review for more than five years; it was kicked into the long grass of Whitehall interdepartmental delays while our critical network remained under siege. There is potentially a contradiction at the heart of the Government’s strategy on this issue. On one hand, Ministers are using this Bill to impose sweeping new legal duties and heavy, turnover-based penalties on operators to secure their networks; on the other hand, the Government continue to criminalise the very security professionals and ethical researchers whom these operators must hire to test and harden their systems. Amendment 164 would resolve this contradiction cleanly, decisively and safely. It seeks to insert a direct substantive statutory defence into Sections 1 and 3 of the CMA. An individual charged under the Act would have a complete legal defence if they can prove that their conduct was reasonable for the detection or prevention of crime, or that they were carrying on legitimate cyber security activities, specifically defined in the Bill as vulnerability research, penetration testing, threat intelligence-gathering or a responsible disclosure necessary to safeguard system security. Crucially, this amendment would not create a free-for-all or a loophole for malicious actors. It would empower the Secretary of State to approve a statutory code of practice, setting out the precise standards, rules of engagement and reporting protocols that constitute legitimate, good-faith cyber security activity. Anyone who acts outside those clear standards remains fully subject to criminal prosecution. Let us also consider the significant economic dividend of this reform. Independent economic modelling from the CyberUp Campaign demonstrates that introducing a statutory defence for legitimate cyber security activities would add 9,500 high-skilled, high-wage jobs and generate £2.5 billion in additional revenue for the UK economy. We cannot build a resilient nation by preserving laws written for the floppy disk era. In an age of automated AI exploits and state-sponsored ransomware, we must unchain our cyber defenders. We have been here before, and the Government’s arguments for delay have run completely out of road. During our debates and correspondence on the then Crime and Policing Bill and, previously, the then Data (Use and Access) Bill, the Government repeatedly acknowledged the strength of our case. The noble Lord, Lord Katz, stood at the Dispatch Box and conceded that the Computer Misuse Act is dangerously outdated and that the Home Office were actively preparing a statutory defence under Section 1 to protect ethical cyber security researchers. Indeed, in correspondence following those debates, Ministers confirmed that engagement with industry and system owners was well advanced, but their stock excuse for resisting our amendments was always the same: “This is the wrong legislative vehicle. Wait for the upcoming cyber security legislation”. Well, here we are—this is the cyber security and resilience Bill. If primary cyber legislation cannot fix the statute that actively criminalises our front-line cyber defenders, what on earth can? When the Government updated law enforcement powers under the Crime and Policing Act to seize domains and IP addresses, Ministers were quick to assure us that police powers are tightly bound by the Police and Criminal Evidence Act 1984 and statutory exemptions under Section 10 of the CMA. Yet independent security researchers, who discover over half of all critical system vulnerabilities before hostile state actors can weaponise them, enjoy zero statutory protections. They are left entirely at the whim of prosecutorial discretion and the threat of catastrophic legal action. The review of the noble Lord, Lord Vallance, recommended this defence three years ago. The CyberUp Campaign and techUK have drafted the ethical safeguards. In correspondence, Ministers have told us that they agree in principle. It is time to honour those commitments and put a direct statutory defence in this Bill. I urge the Minister to support this vital amendment. I beg to move.

More from Lord Clement-Jones (LD)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.