HomeCybercrimeData and system offences

What Is Critical Infrastructure Under the Cybercrime Act?

The basic facilities, services and installations needed for a community, society or government to function — including transport, communications, water, electricity, banking, health facilities, post offices and schools. Attacking a system used for it raises the maximum to 25 years, plus K25,000 for every day it stays down.

The cybercrime series, no. 15 · Attacks on data and systems · 5 min read

Two provisions of the Cybercrime Code Act 2016 escalate sharply where critical infrastructure is involved: section 9(2) and section 27(2).

Section 2 — the definition

Section 2

“Critical infrastructure” refers to the basic facilities, services, and installations needed for the functioning of a community, society or government, including but not limited to

transportation; communication systems; water supply; electricity supply; banking services; public institutions, including health facilities, post offices and education facilities.

This is much wider than it first appears

“Including but not limited to” makes the list illustrative. The test is whether the facility, service or installation is needed for the functioning of a community, society or government — and a community may be a small one.

Banking services are named. A bank’s systems are critical infrastructure, so an attack on a commercial bank engages the aggravated provisions.

Education facilities are named. A school’s or university’s systems are critical infrastructure.

Post offices and health facilities are named as public institutions.

Communication systems are named — so an attack on a telecommunications network or an ICT service provider’s systems is aggravated.

Section 9(2) — the aggravated offence

Section 9(2)

Where the offence is committed against an electronic system or device that is exclusively for the use or operation of critical infrastructure — or, where the system is not exclusively for that use but is otherwise used in connection with the operation of critical infrastructure, and the conduct —

(a) affects the use of critical infrastructure; or

(b) impacts the operation of critical infrastructure,

the offender is guilty of a crime.

Penalty: (a) in the case of a natural person, a fine not exceeding K100,000 or imprisonment not exceeding 25 years, or both; and (b) in the case of a body corporate, a fine not exceeding K1,000,000.00 and K25,000.00 for each subsequent day the critical infrastructure remains inoperable.

Two routes into subsection (2)

The system is exclusively for critical infrastructure. Nothing more need be shown — the character of the system is enough.

The system is used in connection with critical infrastructure, and the conduct affects or impacts it. Here a consequence must be proved: the use or operation of the critical infrastructure was affected or impacted.

The second route matters because most systems are shared. A general corporate network that also supports a hospital’s patient records, or a data centre that hosts both commercial and utility services, is caught where the interference reaches through to the critical function.

Note the low threshold of the consequence: affects or impacts, not “disables” or “prevents”.

The daily penalty

K25,000 for each subsequent day the infrastructure remains inoperable

This is the only continuing penalty in the Act, and it applies to a body corporate in addition to the K1,000,000 fine.

The consequences are significant. A company convicted of interfering with critical infrastructure faces a fine that grows with the outage — and one that is measured by how long the infrastructure stays down, not by how long the offender’s own conduct continued.

It also creates a strong incentive to assist restoration. Where a company is responsible for an outage of critical infrastructure, cooperating to bring the service back up directly limits the exposure.

Section 27(2) — cyber attack on critical infrastructure

Section 27(2)

Where a cyber attack under section 27(1) — inputting or deploying malicious software to alter, harm, disrupt, degrade or destroy a system, data, infrastructure or program — is committed against a critical infrastructure, the offender is guilty of a crime.

Penalty: for a natural person, 25 years, or a fine of K100,000, or an ICT prohibition for the term of imprisonment plus two years, or all or any of them; for a body corporate, K1,000,000.

Critical infrastructure aggravation compared
s 9(2) — system interferences 27(2) — cyber attack
ConductHindering or interfering with functioning or lawful useInputting or deploying malicious software
Mental elementIntentional or recklessIntentional, for the purpose of harm or disruption
Basic form10 years / K10,000 — a misdemeanour15 years / K50,000 — a crime
Aggravated form25 years / K100,000 for an individual; K1,000,000 for a company
Daily penaltyYes — K25,000 per dayNo
ICT prohibitionNot providedYes

Practical points

  1. For anyone working on shared systems. The second limb of section 9(2) reaches systems used in connection with critical infrastructure. Because banking services, schools and communication systems are within the definition, a great many ordinary commercial systems are connected to critical infrastructure in the relevant sense.
  2. Recklessness suffices for section 9. The aggravated offence carries the mental element of subsection (1), which includes recklessly. A person who acts with conscious disregard of an obvious risk of disrupting a bank’s or a hospital’s systems faces a 25-year maximum.
  3. For companies. The combination of a K1,000,000 fine and K25,000 per day makes this the most expensive offence in the Act. See corporate fines and business obligations.
  4. Neither aggravated form is in Schedule 2, so neither can be dealt with summarily.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.