HomeCybercrimeAttacks and IP

Can a Company Be Guilty of a Cybercrime?

Yes. Almost every offence in the Cybercrime Code Act 2016 states a penalty “in the case of a body corporate”, which puts the question beyond argument. What the Act does not say is when a company is taken to have committed the offence.

The cybercrime series, no. 68 · Cyber attack and intellectual property · 5 min read

The Cybercrime Code Act 2016 plainly contemplates corporate offenders. The mechanism by which a company commits an offence, however, has to be found elsewhere.

Where the Act says so

The standard formula

“Penalty: (a) In the case of a natural person … ; and (b) In the case of a body corporate, a fine not exceeding K…”

This appears in almost every offence provision in Part III. The exceptions are section 6, section 22, and sections 23(1) to (3). See corporate fines for the full table.

How a company commits an offence

The Act supplies no attribution rule

Nothing in the Cybercrime Code Act says when the acts of a director, officer or employee are to be treated as the acts of the company. There is no provision deeming an officer liable, and no due diligence defence.

The gap is filled by section 3(1), which applies the Criminal Code Act (Chapter 262) provisions on criminal practice and procedure, jurisdiction and punishments to this Act — and by the general law.

The identification principle

At common law, a company is criminally liable for an offence requiring a mental element where the person who committed the act was the directing mind and will of the company in the relevant respect — typically the board, a managing director, or a person to whom the relevant function has been delegated.

Applied to the Act, that means asking:

  1. Who did the act? The conduct element — the deployment, the disclosure, the publication.
  2. Were they the company’s directing mind in that respect? A junior employee acting on their own account is usually not.
  3. Was the required mental element present in that person? Intention or recklessness, and the absence of lawful excuse.

A company will therefore most often be exposed where the conduct was authorised, directed or knowingly permitted at a senior level — the decision to run unlicensed software, to send deceptive bulk messages, to publish material, to disclose confidential data.

Other routes to corporate exposure

Routes by which a company may face liability
RouteBasisWhere it bites
Principal offenderIdentification principleConduct authorised or directed at a senior level
Party to the offenceCriminal Code provisions on parties, applied by s 3(1)Aiding, enabling or counselling another’s offence
“Authorise, facilitate or enable”Express words of the offences 23(4), s 28
Provider liabilitys 44An ICT service provider with knowledge and control, or ignoring an order
Operator dutiess 14A gaming or lottery operator permitting a child to participate
Section 44 is the important one for online businesses

An ICT service provider — and Schedule 1 defines that widely — is dealt with by section 44, which sets out the circumstances in which a provider is criminally liable for what passes through its service, and by implication when it is not.

A business that hosts content, carries traffic, or provides access should work from section 44 rather than from the general law, and should read it with Schedule 1.

The individuals remain liable

Corporate liability is not a shield

Where a company is convicted, the individuals who did the acts remain personally liable for the same offence — and it is they, not the company, who face imprisonment and an ICT prohibition.

The penalty structure makes this plain: paragraph (a) provides for a natural person, paragraph (b) for a body corporate. Both may be charged for the same conduct.

Directors should also keep in mind their duties under the Companies Act 1997 — in particular the duties directors owe and the standard of care required of them. Permitting the company to run a system that commits offences engages both.

Reducing the exposure

  1. Written authorisations. Almost every offence turns on acting “without lawful excuse or justification, or in excess of” one. Documented authority for what staff may access, send and publish is the practical defence.
  2. Access control. Limits who can commit an insider disclosure under section 25(2).
  3. Licence records. Answers a charge under section 28.
  4. Moderation. Addresses section 23(4) and section 21 exposure on company pages.
  5. An incident procedure. Preserving evidence, reporting, and responding to production orders and preservation notices is itself a legal obligation once one is served.

See also what a business should do about cybercrime risk.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.