Computer Misuse Act 'putting critical UK infrastructure at risk'

The 30 year-old legislation also prevents cyber security professionals from doing their jobs, it's claimed

The key piece of cyber security legislation in the UK is outdated, inadequate and prevents cyber security professionals from doing their jobs.

With the Computer Misuse Act 1990 (CMA) turning 30 years-old this year, a collective of academics, legal practitioners and experts have branded the piece of legislation a danger to the UK’s general cyber resilience.

Advertisement - Article continues below

The CMA, in particular, is preventing cyber security professionals from carrying out threat intelligence research against cyber criminals and internationally-based hackers, according to a report by the Criminal Law Reform Now Network (CLRNN).

The legislation also imposes restrictions on journalists and academics from researching cyber threats that are in the public interest.

“The Computer Misuse Act is crying out for reform,” said Simon McKay, a barrister specialising in civil liberties and human rights who led the CLRNN research. 

“It needs to be future- and technology-proofed to ensure it can meet the challenges of protecting the embedded internet-based culture we all live in and depend on. 

“This report delivers a blueprint for the government to use and develop to make the law more effective in policing and prosecuting cybercrime.”

The CMA has been used by law enforcement agencies over the past 30 years to penalise people who attempt to access or modify data on a computer without appropriate authorisation. 

Advertisement - Article continues below
Advertisement - Article continues below

Conventionally, this covers the broad scope of malware infections and cyber attacks, as well hacking into systems to obtain information or data for future misuse.

A recent example of a prosecution under the CMA arose in 2018, when a motor industry employee was given a six-month prison sentence for accessing thousands of customers’ personal records without permission. 

One of the arguments made by the CLRNN against the CMA in its current form is that it offers a confused legal framework, with outdated and ambiguous terminology, and is too broad in its application. The inappropriate nature of this scope may serve to penalise or deter individuals carrying out cyber research that may benefit the UK’s cyber resilience but could be interpreted as criminal.

Related Resource

Strengthen your defences against cybercrime

Cyber resilience planning for email

Download now

The CLRNN report has outlined a host of recommendations for lawmakers to take into account. These include introducing a public interest defence that allows cyber security professionals, journalists and academics to carry out work that could potentially prevent future cyber attacks.

Advertisement - Article continues below

There should also be a set of new targeted guidance for prosecutors, including a laxer sentencing regime for younger offenders, as part of a wider overhaul in the sentencing guidelines.

“The legal case for reform of the Computer Misuse Act 1990 is overwhelming,” said senior lecturer in criminal law at Birmingham Law School and CLRNN’s co-director, Dr John Child."

“Experts from academia, legal practice and industry have collaborated to identify the best route to ensure proper penalties are enforced to enable prosecution of  hackers and companies who benefit from their activities, whilst permitting responsible cyber security experts to do their job without fear of prosecution.”

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now



ZLoader malware returns as a coronavirus phishing scam

27 May 2020

AnarchyGrabber hack steals Discord tokens, IDs and passwords

27 May 2020

Scammers leverage contact-tracing in hacking attempt

27 May 2020

GitLab phished its employees and 20% handed over credentials

26 May 2020

Most Popular

Microsoft Windows

Microsoft warns users not to install Windows 10's May update

28 May 2020
data breaches

EasyJet faces class-action lawsuit over data breach

26 May 2020
cyber security

Microsoft bans Trend Micro driver from Windows 10 for "cheating" hardware tests

27 May 2020