Don’t do SECURITY. Do business SECURELY.

Computer Misuse Act reform announced in the King’s Speech

The Government will legislate for a statutory defence for legitimate security research under the Computer Misuse Act 1990.

Today’s King’s Speech confirmed that the Government will legislate to reform the Computer Misuse Act 1990, including a statutory defence for legitimate security research and vulnerability assessment.

The security industry has long argued that the 1990 Act, written before the modern internet, can criminalise good-faith research that helps organisations find and fix vulnerabilities, discouraging UK researchers and threat-intelligence teams.

What happens next?

  • The detail of the defence, including safeguards and conditions, will be set out in the Bill.
  • Until it is enacted, the existing law applies in full.
  • All penetration testing and scanning must continue to be expressly authorised in writing by the system owner.

Once the reform is enacted, organisations should review their vulnerability disclosure policies and testing authorisations. We will provide an update as the Bill progresses.

Source: King’s Speech 2026: background briefing notes (GOV.UK)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights