Opened the debate
Dr Jamie Wallis highlighted the need to reform the outdated Computer Misuse Act 1990, stressing that British cyber-security professionals face legal risks for obtaining actionable intelligence. He cited a report by the CyberUp Campaign and techUK which found four out of five cyber-security professionals worry about breaking the law when conducting essential research in good faith. Wallis emphasised the importance of introducing a statutory public interest defence to protect these professionals, citing instances such as gathering threat intelligence, responsible vulnerability research, active scanning, enumeration, use of open directory listings, identification, and honeypots. He noted the chilling effect on security researchers due to prosecution threats, and the necessity of reforming the CMA for national security infrastructure protection against hostile technologies from countries like Russia and China. Wallis also mentioned a recent case involving TikTok where Government cyber-security experts uncovered potential risks in data collection methods, reinforcing the need for safeguarding vulnerability research and threat intelligence related to defensive measures. He concluded by stressing that reform would foster innovation, economic growth, and international regulatory influence.