1. Starting point
1 Vulnerabilities in IT systems have been systematically recorded in the Common Vulnerabilities and Exposures (CVE) system since 1999, In 2024, an average of over 100 new vulnerabilities were published every day. Of the more than 40,000 new vulnerabilities in 2024, a total of 5,440 (see figure below) were rated as “critical” (score of > 9). Critical vulnerabilities can, for example, enable the direct remote takeover of a system, affect a very large group of systems, have an enormous impact on protection goals or be characterized by very low complexity and are therefore easy to exploit by interested parties. In 2014, just ten years earlier, an average of 30 vulnerabilities were published every day; in 2004, there were less than five published vulnerabilities a day.
CVE publications between January 1, 2024 and December 31, 2024 grouped by risk (as of March 15, 2025)
2 The rapid increase in the number of vulnerabilities is impressive. It runs parallel to the fact that computer technology has become ubiquitous and completely intertwined with our everyday lives. IT landscapes have taken on a complexity that is often no longer manageable – even by IT experts with many years of experience. Cloud software, for example, is based on countless libraries, each of which can be a potential source of danger in its own right. In addition to smartphones, networked watches, trackers and medical devices – from pacemakers and hearing aids to insulin pumps – have become daily companions. Although only the first attempts have been made, there is no doubt that networked glasses, contact lenses and brain implants will also become an issue. But it’s not just new things that are being created. In all conceivable and inconceivable places, hardware and software is in use that has already reached the end of its life and is no longer receiving updates. In the best case scenario, such legacy devices have not yet been forgotten and are even still being actively maintained. The reality, however, looks bleak. A lack of inventory and unpatched systems have become one of the biggest risk factors. What remains in all this complexity are the “ordinary mortals” who have to rely on service providers, manufacturers and the state. They go about their daily work, interact with the authorities within the scope of their rights and obligations or maintain their social contacts with other people on a day-to-day basis. All of this is dependent on digital technology.
3 There is no doubt that people will continue to network themselves and their environment in the future. This very fundamental observation compels us to protect ethical security researchers from criminal proceedings and penalties. Criminal hackers must continue to be prosecuted. Criminal hackers cause enormous economic damage and violate the personal rights of countless people through leaks or data theft, for example.
4 Ethical hacking is synonymous with the term security research. Ethical hacking means discovering security gaps, informing the affected system operators about the security gaps and thereby helping to generally improve the security of all systems. Those who act in this way should remain unpunished. Ethical hackers carry out indispensable security research. They do good and act in the interests of society. I therefore call for a revised criminal law on hacking.
5 But first the initial situation:
1.1 Pentesting and bug bounty programs
6 Pentests involve attempts to penetrate systems on the basis of clear contractual agreements. The attackers often begin their investigations without detailed information about the systems (black box pentesting), which is most likely to simulate external attacks. Or they receive certain information about the system and network architecture from the client, which corresponds more to the scenario of internal attacks (white-box pentesting)
7 With the
Digital Operational Resilience Act (DORA), the EU has introduced obligations for the financial sector (Art. 2 no. 1 DORA), which include the introduction of risk management frameworks (Art. 6), including the performance of pentests, which must be based on current threats (Art. 26)
Swiss financial institutions are also obliged to manage cyber risks and perform regular pentests
Although there is no explicit obligation to carry out pentesting for critical infrastructures in Switzerland, Art. 8 para. 1 and 2 of the Information Security Act
(ISG) require the implementation of risk management, whereby pentests to assess current risks are part of the current state of science and experience.
8 In bug bounty programs, a mostly undefined audience is called upon to examine systems within a certain scope for vulnerabilities. Participants are compensated for their reports based on predefined criteria
9 In both pentesting and bug bounty programs, the rules that apply are crucial Can the environment be scanned and searched for further vulnerabilities after initial access to the system (lateral movement)? May data records of any kind and in any form be accessed? Is there a justification for this with regard to data protection regulations? What is the situation if a large number of previously unknown security researchers are to be targeted by the bug bounty program? These are some of the questions that arise if security researchers are to be given a legally secure framework for action.
10 To summarize: Pentesters and bounty hunters hack with authority as long as they adhere to the guidelines. This authorization excludes the possibility of a criminal offence They face neither criminal proceedings nor a penalty. The proposed revision discussed here does not affect hacks on a contractual basis, i.e. neither bug bounty programs nor pentesting orders. Likewise, no new obligations are introduced, neither sectorally nor for all system operators. The focus is only on the “freelance” hacker with altruistic intentions.
11 The approach of
Isler/Kunz/Moll , who consider the criminalization of hacking to be lawful under the conditions of justifiable necessity, is elegant. This approach is elegant because it would not require an amendment to the criminal law on hacking; a solution would already exist today. However, the justifiable state of emergency under
Art. 17 SCC contains various stumbling blocks that make it impossible for legal practitioners, and especially tech-savvy researchers, to work within a legally secure framework, i.e. to hack.
12 At first glance, the legal concept of necessity seems to fit the situation of ethical hackers well. There is an actually unlawful interference with the legal interests of others, which is lawful if the legal interests of third parties would be endangered without this interference. These legal interests to be protected must be weighted higher than the one being interfered with. Ethical hackers prototypically interfere with the legal interest of computer peace and then report their actions and the vulnerability to the system operator so that the latter can then rectify the vulnerability and increase system security. In this way, they protect not only a large number of legal interests of the system operator, but also various legal interests of other users of these systems and of persons whose data is processed on these systems.
13 By computer peace, analogous to domestic peace, we mean the right to rule over one’s own virtual space undisturbed and to freely exercise one’s own will within it. The data that may (but need not) be present in this virtual space is not covered by computer peace and thus by the hacking article Art.
143bis para. 1 StGB. Instead, the undisturbed right to dispose of data is protected by the offense of data theft
(Art. 143 para. 1 SCC) and data damage
(Art. 144bis para. 1 SCC).
14 However, the question arises as to whether the endangered legal interests that are to be saved can be recognized at all before a hack. The system operator and its legal interests can be identified or assessed under certain circumstances. Identifying the legal interests of suspected third parties, on the other hand, appears to be very difficult. Mere assumptions are not enough. Furthermore, the legal interests to be rescued under the law of necessity only include absolutely protected rights, such as physical integrity, life, liberty or property Purely contractually protected interests are not sufficient in a state of necessity, but are therefore no less worthy of protection.
15 Another problematic aspect of the institution of a state of emergency is the requirement that the threat to legal interests must be immediate Of course, the existence of vulnerabilities constitutes a danger, but not automatically an immediate one. Immediacy can also be such that there is no longer any direct proximity in terms of time, but “defense is no longer possible or only possible at much greater risk”; immediacy is also given in the case of permanent dangers However, if at all, immediacy can only be established after the successful hack. This would mean that the hack itself would no longer be supported by the emergency situation and would therefore no longer have a justifying effect.
16 Once these hurdles have been overcome, however, there are hardly any difficulties in weighing up computer peace against the saved legal interest. The vast majority of legal interests are to be weighted higher than computer peace. This is all the more true when it is the system operator itself that operates insecure systems and thereby creates a risk to the legal interests of others. If, on the other hand, only computer peace itself can be saved, but it had to be violated first, the balancing of interests is likely to fail. This would be the case if a system were hacked, in which only the legal interest of the operator’s computer peace would be violated.
17 In the analog world, the sense that immediacy is a prerequisite is self-evident. Of course, no one should be punished for breaking the window of a burning store in order to save the customers trapped inside. In the digital world, however, the ethical hacker cannot reliably determine how acutely or whether the legal interests of third parties are at risk at all.
18 It can also be problematic that strict subsidiarity is required for the emergency action to be taken. If there are milder means that would also suffice to save the endangered legal interests, they must also be used. If the milder means (recognizable to the person acting) are not used, criminal liability is no longer excluded per se. Hacking is a lengthy, analytical process, which in the vast majority of cases is preceded by countless attempts and the attack method has to be adapted countless times before the hack works. All failed attempts would not be covered by this subsidiarity; they were never even possible because they were not suitable in the first place. It is obvious that the justifiable state of emergency is not suitable for complex “deed” actions that require several iterations to achieve the goal. The movie version of the hacker who hacks from system to system at lightning speed completely misses the point.
19 One problem with legalizing ethical hacking via an emergency situation is that security researchers hardly ever know about the existence of the emergency elements. This, on the other hand, is a necessary part of the subjective elements of the offense in order for one’s own actions to be lawful under
Art. 17 SCC Secondly, the methodology and temporal aspects of a hack prevent the possibility of being able to invoke an immediate or at least timely rescue. The hack and the security report do not generally lead directly to the rescue of threatened legal interests, as the system operator still has to act first. The situation would only be different if the hackers were to plug the security gap themselves
20 Ultimately, the fact that ethical hacking is primarily driven by curiosity and the aim of increasing the security of systems is also crucial. While ethical hacking carries the idea of rescue, it is a long-term goal. One could also say that it is a “side effect”, a very welcome and useful one.
21 Overall, the justifiable state of emergency under
Art. 17 StGB is not a suitable basis for ethical hackers to operate. The digital world is just as much a part of legal reality as the analog world. Solutions such as the justifiable state of emergency in its current form fail in the face of new phenomena such as ethical hacking. One approach would be to further develop the traditional concept of a state of emergency. However, if we continue to adhere to the current concept of a state of emergency, the enormous uncertainties cannot be eliminated. Ethical hacking cannot be legalized with the instrument of a state of emergency under
Art. 17 SCC
22 Art.143bis para. 1 SCC makes it a punishable offence, upon request, for anyone who, by means of data transmission equipment, unauthorizedly intrudes into a third-party data processing system that is specially secured against unauthorized access. Intrusion must be by digital means, which also includes the direct use of a computer keyboard
Reading out a
hardcoded password (i.e. stored in code) in order to then use this password is not hacking. A hardcoded password in a binary does not represent any special security, it can be read out with the simplest on-board means and is even considered publicly accessible
23 However, the situation is different with a password that is written down on a piece of paper and kept in private rooms. Even the simple use of found passwords falls under
Art. 143bis para. 1 SCC, provided that the passwords are not publicly accessible
Ultimately, the technical skills of the perpetrator are irrelevant.
24 Hacking is a successful offense in which success occurs as soon as the perpetrator is in the system and the computer peace is thereby violated It is not relevant whether there is the possibility of taking note of data The mere presence in virtual space is sufficient to be punishable.
25 Port scanning is not punishable. This simply involves talking to a system service in a way that is intended The information obtained in this way may allow conclusions to be drawn about vulnerabilities, but the scanned system is not penetrated.
26 If hackers gain access to an unsecured system, they are not liable to prosecution for hacking. Anyone who runs a service on a system that is accessible via public networks and does not provide special protection for this service has no right to call in the law enforcement authorities and have unsolicited visitors prosecuted. This also includes cases of “path traversal”, where a service systematically tries out paths in order to check whether the access rights are set correctly.
27 A system is not “specially secured”, for example, if it has no protection mechanisms whatsoever. It is also not particularly secure if it only has a backup with standard passwords (e.g. can be read in the manufacturer’s manual) or if the configuration has been individualized but only trivial access data has been used (e.g. admin:password or user:12345678) This would not change even if a system operator took the trouble to change the standard ports of the service.
28 According to the current legal situation, ethical hackers are liable to prosecution under
Art. 143bis para. 1 StGB. They expose themselves to prosecution as soon as they make themselves known.
29 The repertoire of hacking techniques also includes
social engineering Social engineering includes all attack methods that specifically target people, their behavior and psychology. Social engineering is used to hack a person and not a data processing system
This fact alone rules out the direct application of
Art. 143bis para. 1 SCC; people are not covered by the offense
30 This also makes it clear that the proposed legalization does not include social engineering methods, but only the hacking of systems. Ethical hackers may therefore not gain access to systems by first hacking a person and obtaining their access data, e.g. through phishing, a sophisticated communication strategy on the telephone or by sending a .
31 In pentesting assignments, social engineering is generally excluded from the catalog of methods and the scope. This is because there is an almost 100% probability that someone will be outlisted. With enough time and resources, any system can be compromised via the human factor.
32 It is right that social engineering should remain a punishable offence today, even after the legalization of ethical hacking, because this method of attack does not create any added value for society. Social engineering does not close a technical gap. One could argue that it was only through social engineering that it became possible to test internal systems. That is of course true. However, the software used internally can also be tested for security gaps by setting up a test setup. The situation is only different for in-house developments that are not readily accessible.
33 Furthermore, the threat situation for the legal interests of affected persons and system operators is not the same if an intrusion into an otherwise secure system has previously been made using fraudulent access data. Vulnerabilities that can be exploited from public networks – and this is the focus of the proposed revision – pose a far greater risk to affected persons and system operators.
34 If systems are penetrated on the basis of the results obtained through social engineering (usually access data),
Art. 143bis para. 1 SCC can be applied – under current law as well as with the proposed legalization
In these cases, it will continue to be up to the system operator to decide whether or not to tolerate this breach of the law and refrain from filing criminal charges.
35 As early as 1990, the European Council looked to the future and stated: “The computer may well become the ‘Achilles‘ heel of the post-industrial society“ The first countries have already recognized the need to legalize ethical hackers under criminal law and have created a legal framework (see para. 124 below).
36 The following arguments speak in favor of exemption from punishment in Switzerland as well:
2.1 Modernize criminal law on hacking
37 The background to the first legislative efforts to create criminal law on hacking were the first parliamentary initiatives in the 1970s, which were intended to create new offenses to combat white-collar crime Later influential incidents and topics in question time with the Federal Council included a hack into the teletext system of the city of Biel in 1985 using AHV numbers, which was brought up in an interpellation, a hacking scandal in the Federal Republic of Germany, which was uncovered in 1989, and the hack into the ETH computer center in 1989 These incidents definitely brought computerization into the public consciousness. The commission of experts appointed by the Federal Council also addressed the new phenomenon of computer crime. At the same time, the European Committee on Crime Problems drew up a report summarizing the results of investigations since 1985, which was published in 1989. This report already included the motives of hackers and the advantages of hacking for security In Switzerland, on the other hand, the focus of legislators was entirely on criminalization; the issue of technical security and the value of security research was not addressed
38 On March 2, 1992, the Federal Council recommended to Parliament a formulation that provided for intent to enrich (excessive internal tendency) in the subjective offense, even though intrusion into systems in itself has nothing to do with legal interests in the sphere of property The proposed initial version also combined data theft with hacking in the same offense:
“1. anyone who, with the intention of unlawfully enriching himself or another, obtains for himself or another electronically or in a comparable manner stored or transmitted data that is not intended for him and is specially secured against unauthorized access, or unauthorizedly penetrates into specially secured data processing systems of third parties by means of data transmission equipment, shall be punished with imprisonment for up to five years or with imprisonment.
(2) Unauthorized acquisition of data to the detriment of a relative or family member shall be prosecuted only upon application.
3. if the offender acts without intent to enrich himself, he shall be liable on application to imprisonment or a fine.“
39 The version passed by Parliament on June 17, 1994, and finally enacted on January 1, 1995, ultimately separated data theft and hacking, creating Art. 143bis SCC for hacking
40 With regard to the intention to enrich, an about-turn was made at the same time
“Any person who , without intent to enrich himself, unauthorizedly penetrates a third-party data processing system specially secured against his access by means of data transmission equipment shall be liable on application to imprisonment or a fine.”
41 Hacking (with intent to enrich), which was originally prosecuted ex officio with a penalty of up to five years’ imprisonment, was thus changed to hacking without intent to enrich, which is now only prosecuted on application and carries a penalty of up to three years’ imprisonment. Hackers who acted with the intention to enrich themselves have thus slipped through the cracks.
42 In the course of the revision of the Swiss Criminal Code, the names of the types of punishment were changed as of January 1, 2007 (namely, instead of imprisonment or prison, now custodial sentences or fines). With the implementation of the European Cybercrime Convention, the much-criticized and not very useful element of the offence “without intent to enrich” was finally deleted
43 The current version has been in force since January 1, 2012. The offense of hacking has thus remained essentially unchanged. From the outset, it was characterized by the fact that the legislator found it difficult to meaningfully capture and assess hacking. Hacking was always discussed in the context of property offences and had an exclusively negative connotation, without recognizing the opportunities of hacking.
44 The counter-argument to the legalization of ethical hacking, then as now, is often that hacking is dangerous. A look at parliamentary deliberations and reports confirms this fear. The dangerousness was consistently assumed, but without being explained in more detail. The considerations were consistently that hacking violates the domiciliary rights of the system operators and then makes it possible to access, steal or delete data without authorization It is therefore not the actual aspect of hacking and computer trespassing that is responsible for these fears, but what may follow afterwards.
45 However, it would be dishonest to claim the opposite per se and say that hacking is completely harmless. Hacking can be dangerous from a technical point of view if processes crash, which could affect other processes or even the entire system. Or the hacked processes behave unexpectedly and even change data. Looking back over the last 30 years, however, it can be said that actual hacking – i.e. penetrating a system – is not dangerous per se. As far as can be seen, there are no known cases where damage has been caused purely by hacking – i.e. exclusively by penetrating a data processing system, as is punishable under
Art. 143bis para. 1 of the Swiss Criminal Code. Attacked processes generally restart themselves in the event of a crash, if they do not simply continue to work as before anyway. Cases such as DDoS (to be subsumed under coercion according to
Art. 181 StGB), ransomware extortion
(Art. 156 StGB) or simple data damage
(Art. 144bis StGB) are not hacking. Even after the legalization of hacking, they are still punishable (see para. 130 et seq. below).
46 Despite scandalous news and parliamentary questions to the Federal Council, 30 years ago the digital world was still tranquil in every respect. While hacking was only a sporadic topic in parliament 30 years ago, today the topic can hardly be quantified in parliamentary business. Cyber security has permeated all areas. Only security incidents of enormous proportions make it into today’s reports; hacks have become part of normality. In view of its origins,
Art. 143bis para. 1 SCC no longer reflects the enormous increase in danger and does not do justice to the current ubiquity of networked technology.
2.2 Criminal proceedings for ethical hacking
47 Criminal proceedings have far-reaching consequences. Just think of house searches, confiscations and deprivation of liberty. The subsequent proceedings almost invariably take a long time. In addition to the nervous strain, application processes are in limbo during this time, especially where personal security checks are required or there are other increased requirements. False information during the application process can have serious consequences under employment law.
48 While it was previously assumed that the risk of criminal prosecution was low, the picture has since changed The hack of Polish trains, the hack of the CDU app and the ModernSolutions case recently received a great deal of media attention Numerous other cases are known in which manufacturers or system operators only became aware of the value of vulnerability reports after a media outcry and the intervention of society. It is often the bad publicity that prevents the operators of hacked systems from filing criminal charges or causes them to withdraw.
49 Tolerated coercive measures are almost impossible to make up for. Confiscated private and professional IT equipment is no longer available for a long time, quite apart from the implications for privacy and confidentiality – for the accused person themselves or their customers. If the accused person has had the presence of mind to request a seal, time-consuming and cost-intensive unsealing proceedings will follow, if they are at all promising within the narrow confines of the judicially accepted lines of argument. As a rule, the accused persons cannot put forward any legal grounds for the protection of secrets
50 If the criminal application is withdrawn, even a subsequent discontinuation does not change the costs incurred (see
Art. 33 para. 1 to 3 in conjunction with
Art. 319 para. 1 lit. d StPO). The time lost in custody, at interviews, triage, hearings and in discussions with the defense cannot be compensated. It is a misconception that time can be compensated with money. Compensatory monetary payments, if they are made at all, are very modest. In any case, they can only be considered for unjustified deprivation of liberty, which is not an option today when proceedings are settled by withdrawing the criminal application, especially in the case of hacking
(Art. 430 para. 1 lit. a StPO): The hacking was unlawful, therefore the deprivation of liberty was not unjustified in principle. Ultimately, there is a risk that the ethical hackers will be ordered to pay the costs of the proceedings, despite the fact that the case has been dropped; they would always have acted culpably within the meaning of the currently applicable hacking article, despite their honest intentions
(Art. 426 para. 2 StPO).
51 As we have seen, any kind of hacking is punishable under current law. This leads to the absurd situation that ethical hackers expose themselves to the arbitrariness of the operators of the hacked system when they report it. It is the “profiteer” of this report who decides whether or not the reporting person has to face criminal proceedings. This situation is also absurd because only those ethical hackers who can be identified, i.e. who report themselves or have not (sufficiently) complied with , expose themselves to such criminal proceedings. However, OPSEC is often dispensed with precisely because people act with good intentions anyway and make a report.
52 The OECD also confirms the widespread fear of criminal prosecution in the research community and mentions various other examples of ethical security researchers who have been confronted with criminal prosecution. The enormous chilling effect that the threat of punishment has on ethical hackers is emphasized This is not surprising, as ethical hackers still have a functioning moral compass, unlike criminal actors. In contrast to criminal actors, the mere threat of punishment has an effect on ethical hackers
53 It is often argued against the exemption from punishment for ethical hacking that more hacking takes place with an exemption from punishment. This is correct, but at the same time unproblematic. Only those security researchers who adhere to the guidelines are exempt from punishment. Exempting ethical hackers from punishment will not lead to more bad hackers getting to work. Evil hackers hack just as often today as they did after the introduction of an exemption from punishment. The threat of punishment has no influence on criminal hackers, as has been impressively proven today in view of the numerous cybercrime incidents. Black hats remain punishable.
54 The fight against criminal hackers fails in another area: the general preventive effect of abstract threats of punishment without ensuring that they are enforced is negligible. The threat of punishment for cybercrime can only be effective if law enforcement officers are allocated more resources to build up skills and personnel. However, this does not mean assigning even more tasks to law enforcement officers; new tasks are simply distributed over the same shoulders by necessity. There is an urgent need for more motivated and well-trained specialists who are willing to work for the state.
55 It is also obvious that the legalization of ethical hacking will encourage more security researchers to become active. This in turn will probably increase the number of attempted attacks somewhat. It will not be possible to differentiate between good and bad attackers, especially at the first line of defense (perimeter security). But it doesn’t have to be, as security aspects have to be indiscriminate anyway. The background noise will become somewhat stronger, but it is also important to ensure that a whole armada of ethical hackers does not suddenly appear.
56 The chronic overloading of the criminal prosecution authorities needs no further explanation. An honest look at the costs of proceedings quickly reveals that the symbolic bills for official acts are backed up by far higher costs. Reports and all kinds of operations tie up resources directly on site and trigger further expenses later on; for example, reports have to be checked and included in the further investigation. It may be necessary to call in external specialists, e.g. forensic experts and system specialists. This is often the case in hacking cases and generally in cases involving large volumes of data. Additional costs are incurred which, depending on the complexity of the case, can be enormous and tie up a great deal of operational time.
57 The current legal situation is driving up the costs of all players without any justification. The security researchers and their defense lawyers spend money and time respectively. Pro bono defense also costs resources, despite the lack of monetary consequences. If an official defense is necessary, which may arise in complex cases, if the hacker is in need of assistance or to ensure equal opportunities, the state must finance both the prosecution and the defense. In such cases, the state must conduct absurd proceedings against ethical hackers and at the same time tie up resources on both sides that would be better used elsewhere.
58 Exemption from punishment does not mean simply having a free hand. Security researchers remain responsible for their actions and must adhere strictly to the established vulnerability disclosure rules. Vulnerability owners also have a duty. They owe their customers secure products and benefit financially by participating in the market. It is therefore up to them to take reported vulnerabilities seriously and to deal with ethical hackers appropriately. Without creating sustainable trust between these two players and the state, we will not get to grips with the problem of exponential vulnerability growth
59 The problem is not the white hats, but the criminal cyber actors. It is therefore logical to exempt white hats from criminal prosecution and thereby relieve the burden on law enforcement authorities. As shown, the prosecution of ethical hackers is ultimately even harmful to the general public.
2.3 Protect actions in the interests of society
60 The term “hacker” is unfortunately still associated with criminality in some people’s minds. Seen in the light of day, hacking simply means dealing with a problem in a way that was not intended With regard to information technologies, this can range from creative enhancement of functionality to tricky exploitation of technical vulnerabilities.
61 Ethical hackers (“white hat hackers”) act with altruistic intent This does not automatically mean that the search for recognition and the demonstration of one’s own technical skills cannot also be important drivers In fact, the recognition of research activity is a fundamental element that should be used for the benefit of all On the other hand, those who act selfishly and do not intend for the security vulnerabilities discovered to be closed are not acting ethically and do not deserve exemption from punishment (“black hat hackers”)
62 In between is the category of grey, i.e. those persons who cannot be clearly categorized objectively. However, there is no real problem with grey hats. Anyone who does not want to work to close security loopholes, i.e. who has not decided to act in the public interest, does not appear to be in need of protection and does not deserve exemption from punishment. It may be that someone initially acted primarily out of a desire for recognition or even with the intention of enriching themselves. However, anyone who ultimately reports the security breach for the benefit of all should still be able to benefit from exemption from punishment. In any case, it would be unrealistic to assume that any abuse can be ruled out. Just because someone could in principle provoke a self-defense or emergency situation and hope for difficulties of proof in their favor, neither self-defense nor emergency law is seriously called into question. Individual advantages and opportunistic behavior are not able to outweigh the enormous benefits and public interests.
63 The publication of vulnerabilities is a major component and core of ethical hacking. There are already recognized procedures for publication under the keywords “Responsible Disclosure”, “Coordinated Vulnerability Disclosure” (CVD) or “Software Vulnerability Disclosure”. The European Union Agency for Network and Information Security (ENISA), a globally recognized agency with enormous expertise, has evaluated that CVD aims to maximize societal benefits through the orderly publication of vulnerabilities The societal benefits of ethical security research and the publication of vulnerabilities are undeniable and have also been repeatedly recorded at global level by the UN in resolutions and working reports The international standardization organization ISO has also issued the standards ISO/IEC 29147 and ISO/IEC 30111 for vulnerability reporting and handling. The ISO states: “Vulnerability disclosure helps users protect their systems and data, prioritize defensive investments, and better assess risk“ The BACS has also recognized the need for orderly vulnerability and published a first version of its CVD in 2021. MELANI, a predecessor organization of the BACS, already explicitly stated in 2015 that clear legal regulations were desirable and emphasized that security could only be improved thanks to reports from security researchers
64 Bruce Schneier, a luminary of cryptology and cyber security, ultimately considers any kind of publication – including full disclosure without coordination with the manufacturer if necessary – to be better than withholding. He points out that the critical view of the public is the only reliable way to increase security, whereas secrecy only worsens security for everyone However, full disclosure is only appropriate if the manufacturer simply does not care about the problem. In this case, knowledge of the vulnerability is the only way for users to take precautions and, if necessary, do without the insecure hardware or software. In the short term, full disclosure increases the risk, but in the long term this is justified by the gain in security
65 In discussions with representatives of the IT industry, it is not entirely unjustified to hear the accusation that companies that actually produce good and valuable products are put under severe pressure by the reporting of vulnerabilities and run the risk of being destroyed as a result. This is a serious fear; the impact of media coverage of hacked companies can indeed be enormous. Media coverage is often driven by the cultivation of outrage. However, it has been shown that the transparent handling of security incidents is well received by the public. Concealing and making excuses, on the other hand, has a strong negative impact on the perception of a company. This also includes the often encountered reaction of confronting ethical hackers with criminal charges. These reports are made in the hope of influencing the behavior of the reported person and preventing them from communicating publicly. If the security researchers have adhered to the industry-standard principles of Coordinated or Responsible Disclosure, however, the effect of reporting is exactly the opposite. In such cases, it is the manufacturer’s responsibility to adhere to the recognized principles. Then the manufacturer will not face a media storm of indignation. If ethical hackers do not adhere to the disclosure principles, they will be harshly criticized without exception and lose their right to impunity.
66 Dealing with vulnerabilities is not only a concern for companies, but also for states. The fact that vulnerabilities are retained by state actors has been known for some time and is discussed under the heading of “no disclosure” or “weaponization”. In the USA, a so-called “Vulnerabilities Equities Process” (VEP) or “Government Disclosure Decision Process” (GDDP) is used to decide whether a vulnerability should be published or not. Advocates of such processes primarily argue that a large number of important factors (e.g. state interests and security interests) are included and that transparency is also created Such processes are preferable to a non-disclosure policy. Germany has been discussing the implementation of such a process for some time At the political level, dispensing with a non-disclosure strategy or at least adhering to transparent vulnerability management as part of a VEP/GDDP process leads to being perceived as a credible foreign policy. The positive effects of state disclosure policies also include the promotion of mutual trust and the curbing of armament spirals
67 In its national cyber strategy, Switzerland also deals with vulnerability management through publication. The BACS/NCSC is assigned a central role in CVD and vulnerability communication Unfortunately, unlike the strengthening of bug bounty and public trust programmes, there are no references to legalizing or at least considering ethical hacking.
68 At the end of 2023, the Federal Council commented on cybersecurity in a relatively concise report on CVD policies of the public administration and federal-affiliated companies. It recognized cybersecurity as a central challenge for our society in an increasingly complex environment and stated: “For cybersecurity, it is crucial that everything possible is done to minimize the risks of vulnerabilities in ICT systems” and because “a great many attacks exploit vulnerabilities in ICT systems, the prevention and closure of vulnerabilities is of central importance“. The National Cyber Strategy adopted by the Federal Council and the cantons in 2023 also clearly states that it is “essentialfor cyber securitythat the emergence of such vulnerabilities is prevented wherever possible and that existing vulnerabilities are identified in good time and quickly remedied“ In the National Cyber Strategy, ethical hacking is explicitly considered with a measure in the objective “Secure and available digital services and infrastructure”. Ethical hacking is to be institutionalized with bug bounties and “public trust” programmes and thus promoted “by improving legal certainty for ethical hackers“.
69 Germany is on the verge of legalizing ethical hacking, which has long been called for. In the draft bill of 4 November 2024 on the modernization of computer criminal law, the German Federal Ministry of Justice expresses its support for the legalization of ethical hacking in clear terms: “It must be prevented that criminal law discourages actions that are in the interest of society and therefore desirable. This is precisely what threatens to happen in the case of criminal computer law“. The legal status quo is “onthe one hand associated with uncertainties for IT security research and on the other hand does not represent an appropriate response to increasingly serious attacks“. The draft bill and the information paper published on the same day rightly described IT security as the “Achilles’ heel of the information society“ Germany has taken the right path with the intended revision. Belgium, France, the Netherlands, Latvia and Lithuania are already setting an example today (see para. 124 below).
70 With the NIS-2 Directive, the EU has prescribed measures for member states to implement in order to raise the level of cybersecurity of central communications service providers and critical infrastructure, among other things, to a high level (cf. Art. 2 NIS-2). It creates important structures at national level, such as transnationally cooperating CSIRTs, but also the obligation to introduce CVD processes and a wide range of recognized risk management methods, including supply chain security. Certain aspects of NIS-2 can already be found in Switzerland. For example, the NIS-2 Directive provides for the coordinated disclosure of vulnerabilities to be facilitated (Art. 12 NIS-2; which was initiated with the CVD Policy of the BACS) and the measures to be defined in a national strategy (Art. 7 para. 2 let. c NIS-2; cf. the Swiss National Cyber Strategy), whereby a coordination body must be designated (Art. 11 para. 5 let. c NIS-2; this role is assumed by the BACS if its CVD is complied with)
71 The
Cyber Resilience(CRA), which came into force on November 12, 2024, also aims to strengthen cybersecurity and focuses on
products with digital elements (recital 9 et seq. CRA) and consumer safety (recital 1 CRA). In the very first sentences, the CRA emphasizes the importance of cybersecurity: “
Cybersecurity is one of the greatest challenges facing the Union. […] Cyber-attacks are a matter of public interest as they have a critical impact not only on the Union’s economy, but also on democracy and the safety and health of consumers“. In terms of product development, the thrust can be broken down with the DevSecOps specification. Security must be included throughout the entire life cycle (from development to operation to end of life) of products, which also includes supply chain security, including the recommendation to maintain a Software Bill of Materials (SBOM)
72 In the aforementioned report, the Federal Council nevertheless came to the conclusion at the end of 2023 that the existing bug bounty programs were sufficient and that there was no need for action to revise criminal law. This position is justified by the fact that there would be further potential to make greater use of the existing measures. This falls short and is probably due to the report’s very limited focus on coordinated vulnerability disclosure strategies of the public administration. If there is further potential, this confirms in the light of day that a deficit exists. Citing deficits as a reason not to act makes no sense. It is also striking that the report wrongly equates ethical hacking with hacking on a legal basis. The report also lacks a well-founded discussion of the numerous scientific studies and reports by authorities and commissions in recent years. There is also no mention of foreign legislative efforts, even though they clearly point in the direction of legalizing ethical hacking.
73 With a focus on the economy, it can be seen that ethical hacking leads to better hardware and software products. Competition would increase among market participants with similar products. The existing educational institutions in the field of cyber security would be strengthened, as a broad and open discourse could emerge within the ethical security research scene in Switzerland. Switzerland would position itself at the forefront of the competition and further expand its existing locational advantages if it were to implement legalization quickly. This is all the more true as Germany, the central European economic heavyweight, is soon to follow suit.
74 Exemption from punishment does not lead to more bad hackers, but to more good hackers. More ethical hackers lead to more vulnerability reports and more secure systems. This in turn makes the work of criminal hackers more difficult, helps to prevent total economic losses, e.g. through ransomware attacks, and increases the protection of all users who communicate digitally on a daily basis. This should be the aim of modern criminal hacking law.
75 There is no doubt that the political will to strengthen cyber security has long been present both internationally and in Switzerland. The need for action has been identified and effective solutions exist. But why is ethical hacking – i.e. acting in the interests of society – still punished?
76 To summarize: Ethical hacking is punishable by law in Switzerland, unless there is a legal basis, such as in the case of pentests or bug bounty programs. Whether ethical hackers are punished or not is left to the discretion of the system operators, who have the power to file a criminal complaint. In view of the social benefits of ethical hacking and its importance for IT security and the economy, this situation is untenable. The legalization of ethical hacking is overdue.
3.1 Exemption from punishment through new para. 3 for Art. 143bis StGB
77 A revised hacking article could look as follows; the exemption from punishment in para. 3 is new:
1 Any person who, by means of data transmission equipment, unauthorizedly intrudes into another person’s data processing system that is specially secured against unauthorized access shall be liable on complaint to a custodial sentence not exceeding three years or to a monetary penalty.
2 Any person who places on the market or makes available passwords, programs or other data that he knows or must assume are intended to be used to commit a criminal offence under paragraph 1 shall be liable to a custodial sentence not exceeding three years or a monetary penalty.
3 Any person who acts in good faith in accordance with paragraph 1 and discloses his actions to the operator of the data processing system shall not be liable to prosecution.
3.2 Element of the offense “in good faith”
78 The bona fide intention constitutes a subjective element of the offense that limits the exemption from punishment exclusively to ethical hackers. Only those who hack in order to identify vulnerabilities and report them so that they can be closed are hacking in good faith Good faith is not exclusive, but it is mandatory. Anyone who additionally seeks to receive recognition or hopes for a reward is not acting dishonestly. Good faith has no direct counterpart in the objective elements of the offense arising from paragraph 1. It is an excessive internal tendency
79 The fact that exemption from punishment under the proposed revision is in line with the
Cybercrime Convention(CCC, also known as the Budapest Convention) and that the intention does not have to be purely altruistic is clear from the wording of Art. 7 para. 2 of the CCC: “
A State Party may require that the offence be committed by infringing security measures, with the intent of obtaining electronic data or other dishonest or criminal intent or in relation to an information and communications technology system that is connected to another information and communications technology system“. The proposed revision does nothing else. Dishonest” hacking remains punishable, but only “honest” hacking will be exempt from punishment.
80 Art. 40 CCC provides for the possibility of a written notification by the signatory state to “declaring that it makes use of the possibility to provide foradditional characteristics as a conditionunder Articles 2, 3, 6(1)(b), 7, 9(3) and 27(9)(e) “. The purpose of this rule is to allow the contracting parties to include certain additional elements in order to adapt the material facts covered. The purpose of this is to be able to compensate for conceptual or legal differences between the Convention states, which are more justified in a treaty with global aspirations than they would have been in a purely European context. Declarations” are understood to mean acceptable interpretations, whereas “reservations” include the legal effect of modifying or even excluding obligations
81 The Council of Europe’s Explanatory Report expressly confirms the above interpretation of Art. 7 para. 2 CCC It was precisely the fears of various signatory states that research into security gaps would be affected that prompted the open formulation of Art. 2 CCC. Due to the clear wording, it was not necessary to make a declaration on the CCC within the meaning of Art. 40 CCC in order to restrict the application of Art. 2 para. 1 CCC to dishonest hacking. The possibility of punishing only dishonest hacking exists expressis verbis for the national legislature under Art. 2 para. 1 CCC. The signatory states are free to exclude ethical hacking, i.e. honest intent in accordance with the proposed revision, from punishment.
82 Intentions have a long tradition in Swiss criminal law. Intentions are often used to describe particular subjective elements of wrongdoing. The typical wrong is thus described more precisely, which leads to a restriction of criminal liability
If they are not present, the offender is not punished. The intention to enrich oneself and derived intentions can be found in many cases, e.g. fraud or computer fraud
(Art. 146 and
147 StGB), usury
(Art. 156 StGB) or carousing
(Art. 149 StGB), etc.
83 If intentions are used not to specify criminal liability but, as here, to specify impunity in more detail, this results in a restriction of applicability, as with subjective elements of injustice: not every hack is exempt from punishment, but only if it is based on honest intent. This bona fide intention is ultimately manifested in the report to the system operator.
84 Proving intentions can be difficult. Despite ubiquitous technology, it is still not quite possible to look inside people’s heads. However, these difficulties of proof are nothing new, regardless of whether they concern elements of the offense that justify or exempt from punishment; in both cases,conclusions are drawnabout the inner attitude on the basis of “rules of experience, average judgments and everyday theories from the external circumstances, in particular the course of the offense”
85 Roughly broken down, honesty therefore results directly from the “conduct of the offense” and from the conduct in the context of the disclosure to the system operator. Inferences are drawn from the external to the internal facts. It is this type of evidence that puts opportunistic grey hat hacking in its place.
86 The procedure during the hack, the behavior before and after the hack and the digital and analog traces make it impossible for dishonest hackers to switch sides at will and evade punishment. Starting with bad intentions and then, if caught, quickly switching sides and pretending ethical hacking is only a real scenario at first glance. It would mean that law enforcement would catch the hacker before he could even make his report. In view of the time frame for reporting (see below), which an ethical hacker must adhere to, he would have jeopardized his claim to immunity from prosecution. Even if this were the case, a house search and the subsequent analysis of the equipment would make it difficult for a malicious hacker (who, contrary to the usual OPSEC measures, would ultimately have to allow himself to be caught) to explain his actions.
87 And if, for once, a grey hat hacker still manages to pass himself off as an ethical hacker, this must be accepted. There are no perfect regulations, just as there is no perfect security. The vulnerability must be reported in any case – even in the unlikely event of a grey hat hack – which always benefits the general public.
3.3 Element of the offense “operator of the data processing system”
88 According to the proposed revision, the addressee of the report is the system operator itself and not an official body. This does not assign an additional task to the BACS or the FDPIC. However, if an official reporting office were to be introduced, the reporting systems of the BACS or FDPIC would already be in place and would be suitable.
89 The proposal does not include an official reporting channel. There is no need for this, as the hack occurs in the relationship between two (legal) subjects. It does not matter whether it is a private or public law operator. The waiver of reporting to an official body corresponds to the structure of Art. 143bis para. 1 SCC as an application offense.
90 Identifying the operator of a system is rarely difficult for hackers. If web services are involved, the contact details can be found on websites, namely in the legal notice, a privacy policy or a security.. For systems that do not run any web services, information may be contained in banner messages. Another example is reverse IP lookups, which can be used to identify other domains, which in turn allows conclusions to be drawn about the operator. A reverse pointer or WHOIS query can also be useful. Under certain circumstances, analyzing a network segment can provide the necessary information or indications of other systems involved. Ultimately, it is possible to contact the hoster or ISP or then ask a responsible CERT or CSIRT, the BACS or the law enforcement authorities for help with identification. Often, the communication channel is then established in which the operator identifies itself; hosters, ISPs and authorities do not provide any direct information.
91 It is in the operator’s best interest to set up an appropriate internal organization and make it known to the outside world. Hackers must do what they can and can rely on a functioning internal organization. Many countries have also introduced transparency and labeling requirements. Properly organized system operators provide security researchers with a security.txt file containing all the necessary information – including exact details of a secure communication channel, relevant policies and required information. The minimum version may look like this
Contact: mailto:securityissues@example.com
Policy: https://example.com/.well-known/policy.txt
Encryption: https://example.com/pgp-key.txt
Canonical: https://example.com/.well-known/security.txt
Expires: 2026-01-01T00:00:01Z
Preferred-Languages: en, de
92 It is not essential that the hackers inform the legally correct entity about the hack, as long as the report is ultimately sent to the responsible body. This body should be able to rectify the vulnerability or have it rectified. Of course, this does not mean that the report can go to just anyone in order to comply with the disclosure obligation. The decisive factor will be that you turn to the body which, according to the usual course of events and general life experience, is the competent body. Every conceivable clarification does not have to be made. The initial notification should always be made with caution and it is advisable not to send the complete notification with all details or even a proof of concept to an address that could not be reasonably verified, especially in the case of ambiguities.
93 The content of a vulnerability report is confidential as it contains security-critical information. It may not be made accessible to third parties or even published (direct full disclosure)
94 If the operator does not respond to the report, i.e. does not confirm receipt of the report or confirms the report but then does not allow any further communication, the security researchers should endeavor to communicate repeatedly. In such situations, it is advisable to adhere to the principles of Responsible Disclosure or Coordinated Vulnerability Disclosure. A report to the BACS should be considered first.
3.4 Element of the offense “discloses his actions”
95 Disclosure essentially touches on two dimensions, one in terms of content and one in terms of time.
96 Content dimension: The level of detail in which the hackers must communicate their findings is not specified. It goes without saying that the disclosure must contain everything necessary for the system operator to understand the hack and thus the vulnerability. It is then up to them to use the report to identify the relevant software and hardware components or systems and to rectify the vulnerability. As a rule, the disclosure will also contain the identified vulnerabilities, as this is the only way to meaningfully document and trace the procedure.
97 As mentioned above, care must be taken when making initial contact, especially if there is uncertainty about the responsible operator. In such cases, the report should only contain the most important information so that an incompetent third party cannot use the information to get up to mischief. Once the operator has been reliably identified, all knowledge of the vulnerability must be disclosed.
98 The proposed revision deliberately refrains from specifying the content in detail. There is a broad consensus on what a vulnerability report should contain. Typically, the affected products or services are specified and it is shown how the vulnerability can be identified and, if necessary, reproduced. The code for a proof of concept may also be included. Where possible and known, the functional impact of the vulnerability is outlined
99 The ISO has addressed the disclosure of security vulnerabilities and developed the ISO/IEC 29147 standard. The
vulnerability handling process, which has also been standardized with ISO/IEC 30111, is closely linked to the CVD process according to ISO/IEC 29147. Although the ISO standards for the disclosure or coordinated publication of vulnerabilities are not binding, they nevertheless represent the
de facto procedure that is expected and practised in the IT industry
Any deviation from these standards, which are recognized in practice, should be carefully considered. In the application of the law – namely in the assessment by courts – such sources are regarded as quasi-legal guidelines or as the recognized state of science and experience within the meaning of
Art. 139 para. 1 StPO
100 Time dimension: It would make no sense to set rigid time limits at the legislative level. The industry standard already discussed and the prevailing consensus on responsible or coordinated vulnerability disclosure are sufficient. As a guideline, an initial version of the findings should be reported to the system operator within three days.
101 Based on
Art. 90 para. 1 of the Code of Criminal Procedure, three days means that the report should be made on the third day after the hack. The interpretation of daily time limits in this way is widely established in Swiss law
If time limits were to be applied in hours, the hourly time limit would begin to run after the vulnerability was identified. The system operator then usually confirms the report to the reporting person within 3 days, but certainly within 7 calendar days
This prompt exchange is crucial so that a basis of trust and a good working relationship can quickly develop between the hacker and the operator in the context of the vulnerability report
The more critical the content of the report is, the more quickly the operator should confirm the report and endeavor to deal with it.
102 The timing of the report must be based on the risk that arises from the hacker’s perspective. Aspects such as the type of data held in the system or the criticality of the system for other systems should be included in the risk assessment. However, the criticality of the vulnerability found from a global perspective can also be a criterion: Vulnerabilities in the “class breaks” category can result in a whole cascade of security breaches or affect the confidentiality, integrity and availability of entire cyber ecosystems The Heartbleed bug was an undoubtedly applicable example of such a bug, in which a fundamental component of global communication was affected with transport encryption (e.g. in https). Whether the vulnerability is already being actively exploited, i.e. “in the wild”, is another key aspect that can be used to assess the risk. If a vulnerability is already being actively exploited, both the notifier and the system operator must act very quickly.
103 It would make no sense to take a strictly objective view and require hackers to include all aspects in their risk assessment. Such requirements would be excessive and have no basis in Swiss criminal law.
104 Deadlines of 24 hours, for example, compared to the already short three days customary in the industry, lead to more false positive reports and only cause additional work without any real benefit. Ethical hackers are aware of what they are doing and generally assess the situation accurately. If they are of the opinion that an immediate report must be made, they do so.
105 In Belgium, ethical hackers have been given a 72-hour deadline within which the complete report must be made to the system operator and the Belgian CSIRT Center for Cyber Security Belgium (CCB). An initial report must be made within 24 hours (Art. 23. § 1er. 2° and 3°) Lithuania has introduced a 24-hour deadline after which a report must be made to the National Cyber Security Center (Art. 25 No. 3 of the Cyber Security Act). France has dispensed with a fixed deadline at the legislative level; when reports are sent to the French CSIRT, the Agence nationale de la sécurité des systèmes d’information (ANSSI), there are internal deadlines for the authorities to process the report. A deadline has also been waived in the Netherlands
106 There is broad acceptance that vulnerabilities should generally be made public 90 days after they are reported The fear that such publication would contribute to reputational damage is unfounded. It is socially accepted that errors can occur in products, especially in products that are IT-based. The problem is not the disclosure of security vulnerabilities, but the poor handling of reported vulnerabilities. Stalling tactics or even concealment are what tarnish the reputation of manufacturers and system operators. On the contrary, with proper vulnerability management and appropriate communication, a good reputation can even be maintained. Regular updates and the patching of vulnerabilities are a selling point for customers.
107 If the hackers do not make an effort to report promptly, they are not doing themselves any favors. If they are identified before they report (too late), they will have much more trouble presenting their actions as honest hacking. It is therefore in the security researchers’ own interest to comply with the disclosure obligation as quickly as possible. Experience with the Coordinated Vulnerability Disclosure also shows that hackers make every effort to document their discoveries on an ongoing basis and to inform the operators of the affected systems quickly.
108 As shown above, it therefore makes sense not to issue any fixed requirements at the legislative level. Should a revision variant emerge in which a central reporting office is involved and more concrete time specifications better reflect the political consensus, these specifications should be defined as guidelines and only at the ordinance level.
3.5 Element of the offense “exempt from punishment”
109 The purpose of the CCC was to ensure that all signatory states criminalize hacking However, it does not prohibit ethical hacking from being exempted from punishment. Art. 2 CCC provides that the Convention states may make criminal liability dependent on “dishonest intent” (see para. 78 et seq. above). As already shown, the proposed revision complies with the Convention.
110 Art. 8 para. 1 of the
Code of Criminal Procedure allows the authorities to refrain from prosecution
if federal law so provides. In such cases,
Art. 8 para. 4 of the Code of Criminal Procedure stipulates that the case is not prosecuted
(Art. 310 of the Code of Criminal Procedure) or is discontinued
(Art. 319 of the Code of Criminal Procedure). With the revised hacking article, criminal proceedings against ethical hackers would no longer be conducted in future.
Art. 52 SCC would already give the prosecuting authorities the option of refraining from prosecution, referral to court or punishment if the consequences of guilt and the offense are minor.
Art. 52 SCC, on the other hand, hardly applies and is to be applied very cautiously, especially in the case of offences committed on complaint
In view of the current structure of hacking criminal law, there is no possibility of refraining from prosecution on this basis; quite apart from the massive legal uncertainties that would continue to exist due to the description of “minor” guilt and consequences in the context of hacking. The unlawfulness of the action would also continue to exist. Investigations into hacking are complex and costly, which can lead to the imposition of procedural costs, even if a penalty is waived. Neither
Art. 8 StPO nor
Art. 52 para. 1 StGB are therefore sufficient to exempt ethical hacking from punishment under current law.
111 The wording of the proposed revision is based on the exemption from punishment rule for breach of the peace under
Art. 260 para. 2 SCC. Anyone who leaves the gathering after being asked to do so, despite having committed a breach of the peace, “remains unpunished”. The proposed wording is therefore a familiar formulation that can be interpreted using the usual methods of interpretation.
112 We find something similar with an optional formulation in defamation offenses, e.g. in
Art. 173 no. 4 StGB. However, an optional formulation for
Art. 143bis SCC would be the wrong approach for obvious reasons. The criminal liability of ethical security researchers must not depend on the considerations of those applying the law.
113 Exemption from punishment is therefore not alien to the SCC and can be implemented without legal uncertainty with the proposed wording “remains exempt from punishment”.
3.6.1 Obligation to report to the “competent authority”
114 It would also be conceivable to introduce an obligation to report to a competent authority – at federal or cantonal level – in addition to disclosure to the system operator:
3 Anyone who acts in good faith in accordance with paragraph 1 and discloses to the operator of the data processing system and the competent authority and the competent authority shall not be prosecuted.
115 This solution would be based on the Belgian and French regulations and has advantages and disadvantages. This solution would be advantageous because the competent body would become aware of the security-relevant circumstances and could coordinate the publication of vulnerabilities or support the coordination. Data protection would also be given a little more emphasis, as vulnerable systems also tend to lead to data breaches. This applies in particular to configuration errors or unpatched systems, which may constitute a breach of
Art. 7 para. 1 FADP (see also
Art. 1 para. 1 DPA and the state of the art according to
para. 4 lit. b DPA). The situation is different if new vulnerabilities are discovered, namely
0-day vulnerabilities. In the case of such new vulnerabilities, the advantage of a state reporting office is that these vulnerabilities are made public for the benefit of the public in a coordinated vulnerability disclosure process
These reports benefit not only the Swiss public, but the entire world. In this process, the information on the vulnerability is disclosed in an orderly manner and the manufacturer is given a reasonable amount of time to rectify it. In this context, federal vulnerabilities equities processes or “government disclosure decision” processes should also be established (VEP/GDDP, para. 66 f. above).
116 At the federal level, the BACS or the FDPIC could be considered. The technical know-how would certainly be available at the BACS, probably also at the FDPIC, and an exchange between these federal agencies would be obvious. This new reporting obligation would require additional resources at the responsible office, and the situation is already strained today. The fact that the FDPIC is already the reporting office for data protection violations if there is a high risk to the personality or fundamental rights of data subjects
(Art. 24 para. 1 FADP) would speak in favor of the FDPIC’s establishment. The existing reporting system could be expanded to include a reporting function.
117 A federalist approach with the introduction of a cantonal reporting office would also be conceivable. Criminal prosecution in the area of hacking regularly falls under the jurisdiction of cantonal public prosecutors (cf. e.g.
Art. 22 and
23 StPO). A reporting obligation directly to a specialized department of a public prosecutor’s office would be conceivable, but this does not meet with much enthusiasm in discussions with security researchers. Apart from the notoriously critical resource situation of cantonal prosecutors, as far as we know there are no processes in place for this atypical constellation that could be used as a model. This would leave the cantonal data protection authorities, where there are often already processes in place for reporting data protection violations, but which generally relate to incidents at cantonal and communal authorities
118 A solution without new competencies or tasks is preferable, neither at federal nor cantonal level: there is a risk that knowledge of the security gap will be lost if no government agency such as the BACS is involved. There is therefore a risk that the vulnerability will be fixed silently, which would be particularly regrettable in the case of previously unknown vulnerabilities. On the other hand, it must be recognized that very often private legal entities are confronted with each other and hacking is an offence of application. It would therefore be logical to leave the entire reporting process to those affected. Either way, there is no reason why a competent body such as the BACS should not issue a leaflet on how to deal with vulnerabilities for the attention of ethical hackers and system operators.
3.6.2 Only necessary procedure applied
119 Based on the German draft revision, it would be conceivable to introduce a kind of necessity clause:
3 Anyone who, in accordance with paragraph 1, acts in good faith and only to the extent necessary and discloses his actions to the operator of the data processing system shall remain exempt from prosecution.
120 This wording expresses that only those hackers who have limited themselves to what is necessary to discover and exploit the security vulnerability should remain exempt from punishment. It is very similar to the wording discussed in Germany, according to which an act is not unauthorized if “it is necessary to discover the security vulnerability”. This request is understandable; there are obviously fears of giving security researchers too much freedom.
121 However, there is no objective reason to include such wording. If this provision were to be introduced, the consequence would be that a criminal attempt would be made before a hack even works. It is inherent to security research that it is based on trial and error, which is particularly true for black box attacks. Until the exploit actually works, the attack is tested in various iterations until it finally has the intended effect on the target system. As part of the Coordinated Vulnerability Disclosures, it is also common practice to include a proof of concept with the report. In the rarest of cases, this proof is functional at the first attempt.
122 It is not possible to determine in advance whether an action was necessary or not. In many cases, therefore, this element of the offense cannot be checked by the security investigators, which runs counter to the original goal of greater legal certainty. Those subject to the law are faced with a requirement that is impossible to comply with, which is not tenable in the case of criminal offenses. In Belgium, there is a requirement that the procedure must be necessary and proportionate in order to discover and report the security breach. This wording probably weakens the necessity somewhat and could be interpreted to mean that even unnecessary failed attempts should be exempt from punishment, as they are necessary for detection and reporting. What is “proportionate” in a technical context, however, can hardly be determined conclusively.
123 It is obvious that it is not necessary to view, steal or even destroy data as part of a hack. However, such cases remain punishable (see para. 130 et seq. below), which also proves that a necessity clause is superfluous.
124 Belgium: Hacking is punishable under 550bis §1 (intrusion into computer systems) or 550bis §2 (exceeding access authorization) and with qualifying offences under 550bis §3 of the Belgian Criminal Code. Ethical hacking has been permitted since May 17, 2024 under Art. 23 § 1er. NIS2 is permitted. Prior to this, ethical hacking was already legalized under the whistleblower legislation that came into force on 15 February 2023. An initial report must be made within 24 hours, followed by a full report within 72 hours. The report must be made to the person responsible for the system and the national CSIRT. It is also required that the activity does not go beyond “what was necessary and proportionate to verify theexistence ofa vulnerability and to report it“. The vulnerability may not be published without prior permission from the national CSIRT, which could be related to an internal policy on the publication of vulnerabilities with reservations in favor of state interests (see VEP/GDDP above para. 66 f.).
125 Germany: Hacking is currently still punishable in Germany under Section 202c (1) StGB (preparation of spying and interception of data). The German Federal Ministry of Justice has drafted a revision proposal to legalize ethical hacking, which will be implemented in the near future The proposed solution is based on the insertion of a new legal definition in Section 202a para. 3 StGB, which defines what is “not unauthorized within the meaning of para. 1”. Hacking is no longer punishable if the hack is carried out with the intention of identifying a security vulnerability, this security vulnerability is reported to the system owner, service provider, manufacturer or the Federal Office for Information Security (BSI) and this hack is necessary to identify the security vulnerability. § Section 202a para. 3 StGB is equally applicable to the “hacker paragraph” section 202c para. 1 StGB. The proposed revision does not contain any time limits, but does contain a kind of necessity clause.
126 France: Since October 9, 2016, France has had an (optional) exemption from punishment under Article L2321-4 of the Code de la Défense. For the purposes of information system security, the obligation to prosecute under Article 40 of the French Code of Criminal Procedure (analogous to Article 7 of the Swiss Code of Criminal Procedure) no longer applies, provided that the person acts in good faith and reports the vulnerability exclusively to the ANSSI. There is no deadline for reporting. The ANSSI decides on the further handling of the report, whereby detailed requirements exist at the legal level. The reporting person is granted anonymity by the ANSSI by law. The protection of ethical hackers from criminal prosecution in the French model is therefore indirect and not ex lege, but ultimately based on an opportunity decision by the criminal prosecution authorities or a promise of anonymity. As in Belgium, the decision that the report may only be made via the ANSSI is probably also related to a state policy in France on the publication of vulnerabilities with reservations in favor of state interests.
127 Latvia: In Latvia, hacking is only punishable under Art. 243 of the Criminal Code if significant damage has been caused. Since hacking generally does not cause any damage, ethical hacking is legal. However, this type of regulation is not linked to any reporting process. This does not ensure that security research benefits the general public.
128 Lithuania: Since 17 June 2021, Art. 25 of the Cybersecurity Law has legalized ethical hacking. The procedure must be necessary and proportionate; the confidentiality, integrity and availability of data and systems may only be affected to the extent necessary. The vulnerability must be reported to the affected system operator and the national CSIRT within 24 hours of completion of the vulnerability search and must comply with the national CVD policy. The use of improperly obtained passwords, e.g. via social engineering, is explicitly prohibited and does not qualify for exemption from prosecution (Art. 25 No. 2 para. 6 Cybersecurity Act). Failure to comply with these provisions makes hacking punishable under Art. 198¹ of the Criminal Code.
129 Netherlands: Hacking is prohibited in the Netherlands under Art. 138ab of the Criminal Code. Based on first-instance rulings, the Public Prosecutor General’s Office has established and published an official practice Ethical hacking is not punished if it was carried out in the context of an essential social interest and the action was proportionate and necessary. The vulnerability must be reported to the organization concerned; no deadline has been set.
Overview of the legalization of ethical hacking in selected countries
4.1 What remains punishable
130 The proposed revision is designed in such a way that ethical hackers may not infringe any other legal interests, with the exception of computer security. If hackers violate other legal interests – i.e. if they make themselves liable to prosecution under a different title – the exemption from punishment has no effect on these acts. If other legal interests are violated, there may also be doubts as to whether the actions are based on an ethical conviction. This would jeopardize the exemption from punishment.
131 If the security researchers mutate into vandals and render databases unusable by deleting, encrypting, etc., they remain liable to prosecution both now and after the revision. The revision does not change the fact that this behavior is not tolerated. Nor would it be tolerated if the security researchers were to make the disclosure of their actions dependent on prize money (coercion
Art. 181 StGB and possibly extortion
Art. 156 StGB), whereby the ethical motivation in such cases would already have been lost anyway and the action is no longer exempt from punishment. If the hackers copy databases, they are still data thieves (data theft
Art. 143 SCC or unauthorized procurement of personal data according to
Art. 179novies SCC).
132 The proposed revision has a narrow scope of application and only legalizes ethical security research within the scope of
Art. 143bis para. 1 SCC. The following phenomena of cyberdelinquency remain punishable; the list is not exhaustive:
133 Social engineering is also punishable under the proposed revision. Hacking people in order to obtain passwords (e.g. phishing) and then penetrating a system is still prohibited. No technical vulnerability is researched in this procedure and no general interests are promoted.
134 Brute forcing in the sense of (primitive) testing of access data also remains a punishable offense, because in principle no security vulnerability is uncovered here, but a design weakness is exploited. Researching such design weaknesses is not wrong or punishable per se It does not, however, require that you penetrate someone else’s system. They can be analyzed on your own setup.
135 DoS: All variants of
denial of service are also not permitted under the proposed revision. Anyone who overloads systems through attacks is not hacking within the meaning of
Art. 143bis para. 1 SCC, is not exposing a security vulnerability and is not serving society.
136 Data theft under
Art. 143 para. 1 SCC or in its special form under
Art. 179novies SCC in the case of personal data remains unaffected by the legalization of ethical hacking. Anyone who copies data without authorization after a hack with bona fide intent has not violated the legal interest of computer peace in an initial phase, but has violated the undisturbed right to dispose of data. In addition, this behavior would be atypical for ethical hackers and would torpedo their own honest intentions. Ethical hackers must respect the data of others.
137 Data corruption: The deletion or alteration, including rendering data unusable, in accordance with
Art. 144bis para. 1 SCC also remains unaffected by the proposed legalization.
138 Ransomware attacks: The combination of hacking under
Art. 143bis para. 1 SCC with data damage (through encryption) and extortion under
Art. 156 SCC remains prohibited. This behavior has nothing to do with ethical security research.
139 Espionage, breaches of secrecy, etc.: Any form of espionage is punishable even after the legalization of ethical hacking. The various forms of prohibited intelligence service under
Art. 272 et seq. StGB, the violation of manufacturing or trade secrets under
Art. 162 StGB or, in a political context, the violation of voting and election secrecy under
Art. 283 StGB etc. remain punishable. The same applies to offenses under secondary criminal law, such as the exploitation of another’s performance
(Art. 5UCA) or the violation of manufacturing and trade secrets
(Art. 6 UCA).
4.2 Consequences of the exemption from punishment
140 Switzerland has every interest in putting ethical hacking on a legal footing as quickly and consistently as possible. Ethical security researchers do not take action today because they are threatened with criminal prosecution (chilling effect), even though they would act in good faith and for the common good. Unlike criminal hackers, who do not care about existing bans, the threat of prosecution has an effect on ethical actors. The legalization of ethical security research leads to more reported security vulnerabilities that can no longer be exploited by criminals and not to more cybercrime.
141 Ethical hacking strengthens the security of digital products, which are now ubiquitous and the foundation of sophisticated manufacturing processes. Today, nothing works without digital technology. This makes it all the more important to create a legal environment that offers security. If Switzerland legalizes ethical hacking, it will ensure that the Swiss research and production location not only remains competitive, but is also one of the pioneers in international comparison. A legally secure framework for security research ultimately strengthens Switzerland’s digital infrastructure and digital sovereignty.
142 The proposed revision legalizes ethical hacking at the legislative level, similar to Belgian and Lithuanian law. Germany will also implement legalization in the near future. The proposed wording avoids the rule of law and democratic policy difficulties that exist in the French and Dutch models and closely follows Swiss practice. The time is ripe for Switzerland to further develop its criminal law on hacking and make it fit for the future. The proposed para. 3 for Art.
143bis StGB is a valid way of doing this.
Roman Kost, Attorney-at-law, MLaw, BSc in Information & Cyber Security, Lucerne.