A retelling of Katharina Sommer’s remarks during her DEF CON 34 session “Legally Hacked: How Countries Decide When Security Research Is Allowed,” in conversation with Dark Reading.
Speaking at DEF CON 34 in Las Vegas, Sommer laid out a blunt observation about the state of cybersecurity law: most countries’ legal frameworks were never built for how vulnerability research actually happens today. As she put it, there is “now a lot of security and vulnerability research happening that isn’t consented to, or isn’t authorized” — work still done in good faith, aimed at improving cyber resilience, but technically illegal under laws written decades ago.
Her research, prompted by NCC Group’s seven-year campaign to reform the UK’s 1990 Computer Misuse Act, mapped cybercrime statutes across the globe. The findings were sobering: out of 154 countries with cybercrime laws on the books, only 15 have implemented — or are even considering — legal protections for ethical hackers. Less than 10 percent.
The UK’s own law is emblematic of the problem. Written before the modern security research profession existed, it draws no line between a malicious hacker and a researcher acting in the public interest. Both can, in theory, face prison time for the same unauthorized access. Sommer says she wants to use the international comparison to push British lawmakers to catch up.
To fix this, Sommer built a five-point framework she calls CICIC — conduct, intent, consensus, institution, and conditionality. The “conduct” principle, for instance, shifts the emphasis from the actor to the activity itself, extending legal cover to anyone working to improve cybersecurity rather than trying to define a fixed category of “authorized” researcher.
Portugal became her proof of concept. In 2025, Portuguese lawmakers created a formal safe harbor for good-faith security research — a discovery that reshaped how Sommer approached the rest of her research. Fed through an LLM to parse the UN’s Global Cyberlaw Tracker, her research turned up other unexpected leaders too: Argentina, Chile, and Panama have all built in some form of legal defense, with Panama notably protecting the people who build hacking tools themselves.
Sommer has already briefed UK officials ahead of a national security bill that promises to reform the Computer Misuse Act. Her pitch to policymakers is straightforward: the security research community itself has been the most cautious voice in the room, and codifying their own boundaries into law isn’t a loophole — it’s the missing piece keeping good-faith research legally exposed.