80% of cyber professionals say the Computer Misuse Act is working against them
techUK report calls for "rapid modernisation" of the 30-year-old law that's "stifling" penetration testing
 
 
Four in five UK cyber security professionals are worried about breaking the law due to confusion caused by the ageing Computer Misuse Act (CMA).
The 30-year-old legislation is restricting pen-testers and white hat hackers with strict and often out-dated definitions, according to a survey commissioned by teckUK and the CyberUp Campaign.
The survey, which was circulated between 46 respondents representing 11 organisations and some 25,120 employees, found that the legislation was stifling security teams in the UK, with 80% of respondents saying they have been worried about breaking the law when researching vulnerabilities or investigating cyber threat actors.
Around 40% of those surveyed said the CMA has acted as a barrier to them or their colleagues and had even prevented employees from proactively safeguarding against security breaches. Furthermore, 91% of businesses believed that the law puts UK consultancies at a competitive disadvantage with other countries.
Some of the answers also suggested confusion about what counts as a criminal offence under the CMA. In fact, in only three cyber incident examples - 'web scraping' (74%), 'open source internet scanning' (68%), and 'default credentials in login panels exposed to the internet' (74%) - did respondents reach a reasonable level of consensus.
The Computer Misuse Act was enshrined in 1990, long before the internet became the essential tool for businesses it is today. Although it has been updated a number of times, both techUK and the CyberUp Campaign are calling for the government to open a consultation within the industry to put the law through "rapid modernisation".
"I know from my time in this industry that there are now real concerns among the cyber security community that this law is impeding professionals ability to protect the nation from the ever-evolving range of cyber threats we face, and preventing the sector from establishing its leadership position on the international stage," Conservative MP Ruth Edwards wrote in the report.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"If ever there was going to be a time to prioritise the rapid modernisation of our cyber legislation, it is now, when our reliance on safe, reliable and resilient digital technologies has been brought into stark relief by the coronavirus pandemic."
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
- 
 Manufacturers report millions in losses as downtime wreaks havoc on operations Manufacturers report millions in losses as downtime wreaks havoc on operationsNews UK manufacturers are losing up to £736 million every week due to downtime, according to new research, with outages lasting for several days on end. 
- 
 Microsoft gives OpenAI restructuring plans the green light Microsoft gives OpenAI restructuring plans the green lightNews The deal removes fundraising constraints and modifies Microsoft's rights to use OpenAI models and products 
- 
 Pentesters are now a CISOs best friend as critical vulnerabilities skyrocket Pentesters are now a CISOs best friend as critical vulnerabilities skyrocketNews Attack surfaces are expanding rapidly, but pentesters are here to save the day 
- 
 Cyber professionals call for a 'strategic pause' on AI adoption as teams left scrambling to secure tools Cyber professionals call for a 'strategic pause' on AI adoption as teams left scrambling to secure toolsNews Security professionals are scrambling to secure generative AI tools 
- 
 Bugcrowd’s new MSP program looks to transform pen testing for small businesses Bugcrowd’s new MSP program looks to transform pen testing for small businessesNews Cybersecurity provider Bugcrowd has launched a new service aimed at helping MSP’s drive pen testing capabilities - with a particular focus on small businesses. 
- 
 Building a new approach to security with the next generation of penetration testing Building a new approach to security with the next generation of penetration testingSponsored Combining human-led testing with continuous automated scanning can elevate your security regime 
- 
 OpenAI to pay up to $20k in rewards through new bug bounty program OpenAI to pay up to $20k in rewards through new bug bounty programNews The move follows a period of unrest over data security concerns 
- 
 Kali Linux releases first-ever defensive distro with score of new tools Kali Linux releases first-ever defensive distro with score of new toolsNews Kali Purple marks the next step for the red-teaming platform on the project's tenth anniversary 
- 
 Podcast transcript: Meet the cyborg hacker Podcast transcript: Meet the cyborg hackerIT Pro Podcast Read the full transcript for this episode of the IT Pro Podcast 
- 
 The IT Pro Podcast: Meet the cyborg hacker The IT Pro Podcast: Meet the cyborg hackerIT Pro Podcast Resistance is futile - offensive biotech implants are already here 
