The UK’s ancient Computer Misuse Act is finally getting dragged towards reform, 35 years after it started annoying security researchers.
The long-awaited reform of the Computer Misuse Act of 1990 is being folded into a new National Security Bill. The new version was announced by King Charles III during the State Opening of Parliament on 13 May 2026.
The National Security Bill is mainly designed to make the UK a harder target for hostile foreign states and dangerous groups. It comes partly in response to the 2024 Southport terror attack and more recent incidents targeting Britain’s Jewish community.
The bill will create offences around creating and spreading harmful material online. Westminster says it will close gaps in state threats legislation and bring it closer to anti-terror laws.
The stated goal is to improve the UK’s ability to counter the full spectrum of threats facing the country. That means more powers for law enforcement and the security services.
The government said that reforming the cyber legal landscape would give cyber cops updated powers and capabilities to “remain effective in the digital age”.
It aims to create a Cyber Crime Risk Order to control the behaviour of cybercriminals. It will give new powers to search people believed to be hiding evidence for suspected offenders.
The government said: “It will also unlock the power of cybersecurity professionals to better enable them to secure computer systems. It will also seek to tackle the pervasive threat to the UK economy and businesses, posed by ruthless cyber criminals.”
The CMA was passed 35 years ago after a high-profile hacking incident involving the King’s father, the late Duke of Edinburgh. It defined the offence of unauthorised access to a computer.
That wording has helped prosecute plenty of cyber criminals. It has left legitimate researchers wondering whether doing their jobs might get them a knock at the door from Inspector Nasher of the Yard.
As cybersecurity evolved, the law’s language became increasingly vague. Bona fide security professionals have argued for years that it can criminalise legitimate research when covert access is necessary to properly test systems.
Belfast-based security consultant Simon Whittaker told Computer Weekly that police banged on his front door after his research was wrongly linked to the infamous 2017 WannaCry attack.
Whittaker said: “CMA reform would allow us to be more secure in our research. I’d love to be able to just look at things in more detail and help people secure themselves. It would allow us to focus on our jobs instead of being worried that we’re going to breach something or that something else is going to go wrong.”
The CyberUp Campaign has been pushing for reform for years. It estimates that a statutory defence for legitimate security professionals could unlock up to 20 per cent growth in Britain’s cyber sector.
That sector employs almost 70,000 people and generates £11.9bn, about €13.6bn, in revenues. For once, the lobbyists have a point that does not sound like it was laminated in a consultancy dungeon.
A campaign spokesperson said: “Today marks a genuine turning point for cyber security in the UK. For years, the CMA has left legitimate cybersecurity professionals and researchers operating under unnecessary legal risk, while hostile actors move faster and with fewer constraints.
“By including CMA reform in the National Security Bill, the Government has recognised a basic reality: cyber professionals cannot be expected to defend the country with one hand tied behind their backs. The test now is whether the legislation provides a clear, workable statutory defence for good-faith cybersecurity activity, including vulnerability research and threat intelligence. We stand ready to work with ministers and Parliament to turn this commitment into a lasting upgrade to the UK’s cyber resilience,” they said.







