(3Â weeks ago)
Grand Committee
Lord Tarassenko (CB)
My Lords, one of the advantages of being in this Committee Room for these debates in Committee is that I can use Claude—I hope that is allowed—to answer the question of what the cyber security community thinks about the Computer Misuse Act. The answer comes back in bold. I will read just the paragraph in bold: “The UK cyber security community’s view is that the Computer Misuse Act 1990 is dangerously out of date and reform efforts so far do not go far enough”. I rest my case.
My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this amendment and the noble Lord, Lord Arbuthnot of Edrom, whom I see in his place. I am sorry he was unable to attend the beginning of this debate, but we are told it was for very good reasons. I will not try to reproduce the many overwhelmingly powerful arguments that we have heard in favour of this amendment, which, on these Benches, we are also keen to support—as we support any measure on the basis that it would help organisations to protect themselves and their systems.
Penetration testing and the wonderfully named bug bounties are excellent ways to identify and address the more technically difficult vulnerabilities before they are exploited. Take one of the most widely used apps anywhere: Google Chrome, which has found that external researchers were responsible for almost a third of its patched and communicated vulnerabilities. The Government’s own consultation included respondents arguing that the Computer Misuse Act prevents cyber professionals, consumer groups and researchers undertaking this kind of legitimate public interest activity.
The amendment is wholly sensible in its design, in that it does not commit the Government to action but begins the conversation on this small but hugely important and valuable change, supported avidly, as we have heard, by everybody—more or less—within the cyber industry. It would explicitly condone good faith researchers and sanction ethical hackers to carry out their work. I cannot imagine why it would not at least be worth reviewing such a change on this basis.
I have some unsatisfied curiosity, as there are no published statistics showing how many Computer Misuse Act investigations, prosecutions or convictions involve good faith cyber security researchers, so it is hard to know how much of a dampening effect on ethical hacking the CMA is currently having. If any of the signatories to the amendment, or of course the Minister herself, could shed any statistical light on that, I would be most grateful. As I said, this amendment would allow all such considerations to be taken into account without committing the Government and, as such, I strongly support it.