HomeSecurityGermany: Law to protect security researchers who find flaws

Germany: Law to protect security researchers who find flaws

The Federal Ministry of Justice in Germany has drafted a law to provide legal protection to security researchers who discover and responsibly report security flaws to vendors.

See also: Chrome update fixes multiple critical flaws

security researchers law Germany

When security research is conducted within the defined limits, the responsible parties will be exempt from criminal liability and the risk of prosecution.

Furthermore, the proposed amendment to the criminal law introduces stricter sanctions for serious cases of espionage and data hacking, especially when they target critical infrastructure.

The new draft law amends Section 202a of the Criminal Code (StGB) to protect security researchers, companies and so-called "ethical hackers" from punishment under computer criminal law.

This applies when their actions are performed to identify and close a security vulnerability, as long as they are not considered “unauthorized.”

See also: CISA warns of critical flaws in ICS systems

Germany: Law to protect security researchers who find flaws

The criteria that must be met for security research are as follows:

  • The action must be performed with the aim of identifying a vulnerability or other security risk in an IT system.
  • The researcher must intend to report the security vulnerability that has been discovered to a responsible entity capable of addressing the issue, such as the system operator, the software manufacturer, or the Federal Office for Information Security (BSI).
  • The act of accessing the system must be necessary to identify the vulnerability. This ensures that the exemption applies only to the extent necessary for security testing, without unnecessary or excessive access.

The same exemption from criminal liability also applies to offences involving eavesdropping (§ 202b StGB) and data modification (§ 303a StGB) as long as the relevant actions are considered permissible. At the same time, the law introduces a penalty ranging from three months to five years in prison for serious cases of malicious espionage and data interception by security researchers (§ 202a StGB).

More details on the draft law and the proposed amendments are available here.

See also: Yahoo reveals NetIQ iManager flaws that allow RCE

Protecting researchers who disclose security flaws is crucial to advancing cybersecurity and safeguarding digital infrastructure. Security researchers, often referred to as ethical hackers, play an essential role in identifying vulnerabilities before they can be exploited maliciously. To ensure that security researchers’ contributions are recognized and they themselves are protected, it is crucial to establish clear laws and industry guidelines that protect them from potential legal repercussions. Companies and organizations can encourage responsible disclosure by offering legal immunity under certain conditions, providing monetary rewards through bug bounty programs, and developing a transparent process for reporting vulnerabilities. By fostering an environment where security researchers are supported and valued, society can strengthen its resilience against cyber threats and promote innovation in security practices.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS