A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.

August 10, 2026

DEF CON 34 – Las Vegas – Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn't distinguish between malicious hackers and those working in good faith. But change may finally be coming.

Cybercrime is accelerating rapidly, requiring a holistic approach to curb threats. Security researchers who responsibly disclose vulnerabilities are one way to address burgeoning risks against governments, businesses, and individuals, but many countries have not updated their policies and laws to reflect that, Katharina Sommer, NCC Group's director of government affairs and analyst relations, tells Dark Reading.

Sommer found that 15 countries worldwide have implemented or are considering some level of legal protection for researchers. But that's less than 10% of countries, considering 154 have cybercrime statutes, so risks remain high.