Section 27(2) of the Cybercrime Code Act 2016 is one of three provisions in the Act that escalate an offence because of the target rather than the conduct.
Section 27(2)
Where the offence under subsection (1) is committed against a critical infrastructure, the offender is guilty of a crime.
Penalty: natural person — imprisonment up to 25 years; or a fine up to K100,000; or an ICT prohibition for the term of imprisonment plus two years; or all or any of them. Body corporate — a fine up to K1,000,000.
| s 27(1) | s 27(2) | |
|---|---|---|
| Imprisonment | Up to 15 years | Up to 25 years |
| Fine — natural person | Up to K50,000 | Up to K100,000 |
| Fine — body corporate | Up to K500,000 | Up to K1,000,000 |
| ICT prohibition | Term of imprisonment plus two years | |
| Elements | Identical, except for the target | |
What is critical infrastructure?
Critical infrastructure is defined in section 2, by reference to systems and assets so vital that their incapacity or destruction would have a debilitating impact on national security, the national economy, public health or safety, or any combination of them.
The definition is functional, not a list. Whether a particular system qualifies is decided on evidence about what depends on it and what would follow if it failed.
In Papua New Guinea the systems most obviously within it include the electricity network, telecommunications and submarine cable landing infrastructure, the national payments and banking systems, aviation and port operations, water supply, hospitals, and the systems supporting government administration and defence.
The critical infrastructure pattern in the Act
| Provision | Base offence | Escalation |
|---|---|---|
| s 7(2) | Illegal interception | State or sensitive data |
| s 9 | System interference | Critical infrastructure |
| s 10(2) | Data espionage | State secrets |
| s 27(2) | Cyber attack | Critical infrastructure |
Section 27(2) says only that the subsection (1) offence is “committed against a critical infrastructure”. It does not require the offender to have known, or to have intended, that the target was critical infrastructure.
That matters because malware frequently spreads beyond its intended target. Ransomware released against one organisation has repeatedly reached hospitals, ports and utilities through shared networks and supply chains.
On the words as drafted, an offender whose malware reaches a critical system faces the aggravated penalty. Whether the offender knew what the target was will go to sentence, applying section 19 of the Criminal Code — not to conviction.
For operators of critical systems
- Section 27(2) is not a duty. It creates no obligation on the operator to protect the system; it punishes the attacker. Obligations, if any, come from the operator’s own regulatory framework — the Banks and Financial Institutions Act 2000 for a bank, or the licensing framework administered by the national ICT regulator for a telecommunications operator.
- Preserve evidence first. Restoring from backup destroys the state of the compromised system. Police can seek preservation notices under section 36 and production orders under section 35, but the operator’s own preservation is what makes an investigation possible.
- Expect cross-border investigation. Attacks on national infrastructure are commonly launched from outside the jurisdiction, engaging Part VI.
- Note the corporate exposure. A body corporate that commits the offence faces K1,000,000 — the highest corporate fine in the Act, shared with sections 28, 29 and 30.
For testers of critical systems
Security testing of a critical system is exactly the activity section 27 describes, done with permission. The lawful excuse must be clear, in writing, and current.
Section 16(2) protects the authorised use of tools for testing, and the words “without lawful excuse or justification” in section 27(1) do the same work. But the further words “or in excess of a lawful excuse or justification” mean the protection ends at the boundary of the authority given.
Where the system is critical infrastructure, exceeding scope is not a 15-year exposure but a 25-year one. See the defence for security testing.
Section 27 is not listed in Schedule 2 and cannot be dealt with summarily. See also managing cybercrime risk.
Sources
- Cybercrime Code Act 2016 — ss 2, 8, 10, 11, 16, 27, 35, 36, 46, 47, 48; Schedule 2
- Criminal Code Act (Chapter 262) — s 19
- Banks and Financial Institutions Act 2000
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.