Skip to main content
ANCVEIRS
Public participationAnalysisDigital Governance

Can Ethical Hacking Be a Form of Civic Participation?

Independent researchers can provide public institutions with technical early-warning signals. The difficult part is defining when that becomes legitimate civic contribution rather than unauthorised activity.
Zigmārs AncveirsTechnology Leader in FinTech & RegTech · Cybersecurity & Ethical HackingPublished: 26 September 2026Reviewed: 26 September 202612 min

Introduction

Public participation usually evokes policy consultations, petitions, citizens' panels, public hearings or participation in working groups.

Cybersecurity creates a different kind of situation.

An individual with technical skills notices a vulnerability in a publicly accessible government or socially important digital service, validates only what is necessary, documents reproducible evidence and hands the issue to the organisation or a CVD coordinator before a malicious actor exploits it.

Is that merely a private technical report?

Or can some forms of security research also be understood as civic participation?

My answer is deliberately qualified:

not as an automatically existing legal status, but as a useful governance and policy model — in some circumstances, yes.

I call that model operational civic participation in cybersecurity.

The phrase is not intended to relabel “hacking” as a civic virtue.

It only makes sense when there is a hard boundary between socially useful technical contribution and unauthorised, disproportionate or harmful conduct.

Formal public participation is a specific legal process

Latvia provides a useful illustration of why terminology matters.

Cabinet Regulation No. 639 governs public participation in development-planning processes led by state and municipal institutions. Its stated objective is meaningful, effective, open, inclusive, timely and responsible participation, and individual natural persons can participate alongside formal and informal groups.1

The framework covers established participation forms such as:

  • proposals and opinions;
  • public consultations;
  • discussions;
  • working groups;
  • other development-planning participation mechanisms.1

Coordinated vulnerability disclosure should not simply be inserted into that legal category by analogy.

CVD is primarily a cybersecurity and vulnerability-handling process, not a development-planning procedure.

So the claim:

CVD is legally recognised public participation in Latvia

would go beyond what the current framework supports.

Civic contribution can also be understood more broadly than formal consultation

The relationship between citizens and public institutions is not limited to commenting on policy documents.

People can contribute specialised knowledge in practical ways:

  • environmental monitoring;
  • citizen science;
  • reporting infrastructure defects;
  • professional volunteering;
  • supplying verified risk information to authorities.

The European Commission's open-science policy explicitly includes active engagement of society and citizen science as ways of opening research systems to society.10

Citizen science is not vulnerability research.

The analogy is narrower:

people outside an institution can generate specialised, verifiable information that the institution itself did not possess.

In cybersecurity, that information may be a previously unknown security condition.

Democratic participation and operational participation are different things

I would separate two concepts.

Democratic or policy participation

A person takes part in:

  • consultation on cybersecurity legislation;
  • a national strategy process;
  • a ministry consultation;
  • preparation of policy proposals;
  • an expert working group.

The contribution is aimed at rules, priorities or policy.

Operational participation

A person with relevant technical skills:

  • discovers a security weakness;
  • validates it within lawful and proportionate limits;
  • documents evidence;
  • transfers it to a competent recipient;
  • helps reduce a concrete risk to a socially important digital service.

The person is not voting on policy.

They are supplying an external operational signal.

“Operational civic participation” is not a term defined by Latvian or EU cybersecurity law.

It is an analytical governance concept.

NIS2 creates infrastructure for external technical contribution

Article 12 of NIS2 requires each Member State to designate a CSIRT as a coordinator for coordinated vulnerability disclosure. Where necessary, the coordinator acts as a trusted intermediary between the person reporting a vulnerability and the manufacturer or provider that needs to address it.2

EU cybersecurity law therefore clearly recognises a functional role for an external vulnerability reporter.

NIS2 does not call that person a civic-participation actor.

That distinction should remain explicit:

regulated CVD function versus a governance interpretation of the public value of that function.

This prevents a policy thesis from being presented as current legal doctrine.

Latvia has already institutionalised external technical contribution

CERT.LV's vulnerability-reporting platform is designed for reporting and processing vulnerabilities identified in resources of public-sector institutions and companies registered in Latvia.3

The platform records reports and communications between participants, with CERT.LV acting as the CVD coordinator.4

As of September 2026, the platform includes programmes for organisations such as:

  • Latvia's State Revenue Service;
  • the Central Election Commission;
  • Latvenergo;
  • Sadales tīkls;
  • LVRTC.56789

These programmes do not make researchers public officials.

They demonstrate something simpler and more important:

public and socially significant organisations already operate controlled mechanisms through which external technical competence can produce security value.

That makes the civic-participation question meaningful rather than purely theoretical.

When does security research begin to resemble civic participation?

Not every finding.

Not every bounty.

Not every penetration test.

I would apply six conditions.

1. There is meaningful public value

The research concerns, for example:

  • a public digital service;
  • essential infrastructure;
  • a large population of users;
  • protection of personal information;
  • integrity of a trusted digital process.

A paid vulnerability in a private game does not need to be reclassified as civic participation simply to make the activity sound socially important.

2. The activity has a lawful and procedural basis

Public purpose does not legalise unauthorised access.

The researcher must still respect:

  • legal authority;
  • programme scope;
  • VDP/CVD terms;
  • method restrictions.

3. Evidence is limited to what is necessary

The purpose is to establish the security condition.

Not to maximise exploitation.

4. Harm is minimised

The research avoids unnecessary:

  • data collection;
  • service disruption;
  • persistence;
  • third-party impact.

5. The finding is handed to a responsible recipient

Public value is not complete at:

I found something.

The intended path is:

6. The researcher remains accountable for their own conduct

“Public interest” is not a wildcard.

The researcher should be able to explain:

  • what was done;
  • why;
  • how far;
  • when testing stopped;
  • what was disclosed to whom.

Only with these constraints does the idea of operational civic participation become useful.

finding
→ responsible handoff
→ validation
→ remediation

The researcher does not replace public cybersecurity capability

A reasonable objection is:

Is government simply trying to outsource cybersecurity to unpaid volunteers?

That would be a bad model.

The organisation or state still owns responsibility for:

  • secure design;
  • professional security staffing;
  • threat modelling;
  • testing;
  • monitoring;
  • incident response;
  • remediation;
  • operational resilience.

The external researcher is an additional sensor, not a substitute security service.

The same boundary matters in Secure by Design Before External Research.

A vulnerability researcher is not automatically an incident responder

Roles should also remain distinct.

A vulnerability researcher typically:

  • identifies;
  • validates;
  • reports.

An incident responder:

  • investigates compromise;
  • contains;
  • eradicates;
  • recovers;
  • coordinates the incident.

One person may have both skill sets.

That does not automatically grant both mandates.

Operational civic contribution should include a clean handoff, not uncontrolled role expansion.

Payment does not automatically remove or create civic character

Another objection is:

If the researcher receives a bounty, this is no longer civic participation.

That is too simple.

Socially valuable work can be professional and paid.

The opposite claim is also wrong:

every bounty hunter is a civic participant.

Many bounty relationships are primarily commercial:

There is nothing wrong with that.

The civic interpretation becomes more plausible where the research also produces clear public value within a trusted system for reducing socially significant risk.

Whether money changes hands is not the sole criterion.

Function and context matter more.

security finding
↔ reward

“Public interest” cannot become self-declared immunity

This is the most important limiting principle.

A person cannot simply state:

I act in the public interest, therefore I may do whatever I consider technically necessary.

That would erase the boundary between good-faith research and unilateral action.

A public-value model needs externally assessable behaviour:

  • proportionality;
  • minimisation;
  • scope discipline;
  • evidence;
  • coordination;
  • accountability.

Good intent matters.

Good intent alone is not enough.

Citizen science is a useful analogy — but only up to a point

European citizen-science initiatives involve members of the public in activities such as:

  • data collection;
  • observation;
  • data processing;
  • research-question formation;
  • assessment of outcomes.11

The useful similarity is decentralised observation.

Many outsiders can detect something a central professional system misses.

The difference is the risk model.

A bad bird observation usually does not compromise an information system.

Security research may touch:

  • access controls;
  • personal data;
  • availability;
  • third-party systems.

Cybersecurity therefore needs much stronger authorisation and stopping rules than many citizen-science activities.

CVD turns an individual observation into institutional security work

Without a process:

With a functioning process:

This institutional conversion is central.

Civic contribution is not only the researcher's desire to help.

The institution also needs the capacity to absorb the contribution safely and competently.

person discovers issue
→ random email
→ uncertainty
→ frustration
→ disclosure conflict
researcher
→ known reporting route
→ coordinator / owner
→ validation
→ remediation
→ feedback
→ closure

Participation requires feedback

If institutions want external technical contribution, researchers should not be treated as one-way sensors.

Within legitimate confidentiality constraints, a process should provide enough feedback for the researcher to understand:

  • the report was received;
  • whether it was substantiated;
  • whether remediation is occurring;
  • whether closure was reached;
  • whether disclosure is possible.

That does not mean the researcher is entitled to sensitive internal information.

It means the relationship should have a professional feedback loop.

Without it, “participation” becomes:

give us information and disappear.

For the broader ecosystem question, see Permission Is Not Participation.

Should “operational civic participation” be written into law?

Not necessarily.

The law may need to answer narrow questions:

  • what is authorised;
  • how vulnerabilities are reported;
  • how information is protected;
  • where liability boundaries sit.

The phrase operational civic participation may be more useful in:

  • cybersecurity strategy;
  • programme design;
  • administrative methodology;
  • public communication;
  • researcher-engagement policy.

A concept is not useful because it sounds attractive.

It is useful if it changes how institutions design the relationship with external researchers.

What changes when the researcher is treated as a legitimate external signal source?

If the researcher is perceived only as:

an outsider creating legal risk,

the natural institutional response is to minimise contact.

If the researcher is treated as:

a free penetration tester,

the institution externalises its own security responsibility.

Both are incomplete.

A third model is:

an independent external source of security evidence, operating within defined rights, boundaries and accountability.

That perspective can support:

  • better vulnerability intake;
  • clearer rules;
  • technically stronger triage;
  • meaningful feedback;
  • researcher recognition;
  • better escalation;
  • greater trust in the CVD process.

The point is governance quality, not special hacker privilege.

Objections that the model needs to survive

“This romanticises hackers”

It would, if applied to any unauthorised conduct.

That is why good faith, scope, proportionality and responsible handoff are mandatory boundaries.

“Only technically skilled people get this kind of civic role”

Technical contribution is only one form of participation.

It does not replace elections, policy consultation, community organisations or other civic mechanisms.

“Government will exploit free labour”

That risk is real.

External research should supplement funded professional security capability, not replace it. Recognition, compensation and sustainable researcher relationships should be designed separately.

“Researchers have no democratic mandate”

Correct.

In this model, researchers do not make policy decisions.

They provide technical evidence.

Responsible institutions retain decisions on remediation, prioritisation, disclosure and policy.

“The finding may be wrong”

Also correct.

CVD requires validation and reproduction.

Participation does not make an external technical claim automatically true.

A minimum operational-participation model

I would express it as:

This is not draft legislation.

It is a governance model.

1. OPEN DOOR
   a safe, discoverable reporting channel

2. CLEAR BOUNDARY
   understandable permitted and prohibited actions

3. MINIMUM EVIDENCE
   sufficient PoC without unnecessary impact

4. TRUSTED HANDOFF
   a coordinator or competent resource owner

5. VALIDATION
   the external claim is technically checked

6. REMEDIATION
   the finding receives ownership and treatment

7. FEEDBACK
   the researcher receives process and closure status

8. ACCOUNTABILITY
   both sides preserve a reconstructable evidence trail

What government can do without inventing a special legal class of “ethical hackers”

A symbolic status is not required.

More practical measures include:

  • operating high-quality CVD infrastructure;
  • clarifying authorisation boundaries;
  • reducing unnecessary legal uncertainty;
  • publishing understandable test scope;
  • recognising high-quality contributions;
  • providing closure feedback;
  • creating progression opportunities;
  • using bounty or controlled research where appropriate;
  • measuring process effectiveness.

CERT.LV's current platform already provides a concrete foundation for several of these elements.34

Further choices are matters of policy design.

Conclusion

Ethical hacking is not automatically civic participation.

And “public interest” is not permission to cross system boundaries.

But the opposite framing is also too narrow:

the external researcher is merely a stranger whom an institution reluctantly allows to send an email.

In a digital society, independent technical expertise can create public value in a very concrete sequence:

detect risk → prove the minimum → hand it over responsibly → help enable remediation.

When that happens inside a clear legal and procedural framework, I think it is useful to describe the function as:

operational civic participation in cybersecurity.

Not as a legal status.

As a governance model.

It should not be romanticised.

It should be designed.

Frequently asked questions

Is CVD legally a form of public participation in Latvia?

Not automatically. Latvian Cabinet Regulation No. 639 governs participation in development-planning processes. CVD is a separate cybersecurity process. “Operational civic participation in cybersecurity” is an analytical term used in this article.1

Does acting in the public interest authorise someone to test government systems?

No. Public-interest intent does not itself create testing authority. Applicable law, programme scope and specific testing terms still govern what may be done.

Can bounty hunters be civic participants?

Commercial and public-value functions can overlap, but receiving a bounty does not by itself make research civic participation. The function, context and public value matter.

Does this model mean governments can spend less on professional cybersecurity?

No. External researchers supplement professional security capability. They do not replace it.

Does a researcher have authority to require the institution to implement their proposed fix?

No. Researchers provide evidence and may suggest remedies. Risk-treatment and governance decisions remain with the responsible institution.

Why use the civic-participation concept at all?

Because it helps design CVD as more than a legal inbox: a structured way to turn external technical competence into validated and remediated public-security value.

Source status

Sources and Latvian legal status checked on 25 September 2026. The term “operational civic participation in cybersecurity”, the six-condition test and the eight-step model are the author's analytical/policy framework, not a legal category defined by Latvian or EU law.

This article is a conceptual analysis of cybersecurity governance and civic participation, not legal advice on whether any particular testing activity is authorised.

Sources

  1. Latvia, Cabinet Regulation No. 639 of 15 October 2024, Procedures for Public Participation in the Development Planning Process, current status checked 25 September 2026 · Likumi.lv
  2. Directive (EU) 2022/2555 (NIS2), particularly Article 12 on coordinated vulnerability disclosure · EUR-Lex
  3. CERT.LV, Vulnerability Reporting Platform, checked 25 September 2026 · CERT.LV
  4. CERT.LV, Vulnerability Reporting Platform Terms of Use, effective 1 August 2026 · CERT.LV
  5. CERT.LV CVD platform, State Revenue Service programme, checked 25 September 2026 · CERT.LV
  6. CERT.LV CVD platform, Central Election Commission programme, checked 25 September 2026 · CERT.LV
  7. CERT.LV CVD platform, Latvenergo programme, checked 25 September 2026 · CERT.LV
  8. CERT.LV CVD platform, Sadales tīkls programme, checked 25 September 2026 · CERT.LV
  9. CERT.LV CVD platform, LVRTC programme, checked 25 September 2026 · CERT.LV
  10. European Commission, Open science, including active engagement of society and citizen science · research-and-innovation.ec.europa.eu
  11. European Commission, The Role of Citizen Science in the European Green Deal, describing voluntary public participation in research activities including data collection, processing and analysis · projects.research-and-innovation.ec.europa.eu