Two provisions of the Cybercrime Code Act 2016 escalate sharply where critical infrastructure is involved: section 9(2) and section 27(2).
Section 2 — the definition
“Critical infrastructure” refers to the basic facilities, services, and installations needed for the functioning of a community, society or government, including but not limited to —
transportation; communication systems; water supply; electricity supply; banking services; public institutions, including health facilities, post offices and education facilities.
“Including but not limited to” makes the list illustrative. The test is whether the facility, service or installation is needed for the functioning of a community, society or government — and a community may be a small one.
Banking services are named. A bank’s systems are critical infrastructure, so an attack on a commercial bank engages the aggravated provisions.
Education facilities are named. A school’s or university’s systems are critical infrastructure.
Post offices and health facilities are named as public institutions.
Communication systems are named — so an attack on a telecommunications network or an ICT service provider’s systems is aggravated.
Section 9(2) — the aggravated offence
Where the offence is committed against an electronic system or device that is exclusively for the use or operation of critical infrastructure — or, where the system is not exclusively for that use but is otherwise used in connection with the operation of critical infrastructure, and the conduct —
(a) affects the use of critical infrastructure; or
(b) impacts the operation of critical infrastructure,
the offender is guilty of a crime.
Penalty: (a) in the case of a natural person, a fine not exceeding K100,000 or imprisonment not exceeding 25 years, or both; and (b) in the case of a body corporate, a fine not exceeding K1,000,000.00 and K25,000.00 for each subsequent day the critical infrastructure remains inoperable.
The system is exclusively for critical infrastructure. Nothing more need be shown — the character of the system is enough.
The system is used in connection with critical infrastructure, and the conduct affects or impacts it. Here a consequence must be proved: the use or operation of the critical infrastructure was affected or impacted.
The second route matters because most systems are shared. A general corporate network that also supports a hospital’s patient records, or a data centre that hosts both commercial and utility services, is caught where the interference reaches through to the critical function.
Note the low threshold of the consequence: affects or impacts, not “disables” or “prevents”.
The daily penalty
This is the only continuing penalty in the Act, and it applies to a body corporate in addition to the K1,000,000 fine.
The consequences are significant. A company convicted of interfering with critical infrastructure faces a fine that grows with the outage — and one that is measured by how long the infrastructure stays down, not by how long the offender’s own conduct continued.
It also creates a strong incentive to assist restoration. Where a company is responsible for an outage of critical infrastructure, cooperating to bring the service back up directly limits the exposure.
Section 27(2) — cyber attack on critical infrastructure
Where a cyber attack under section 27(1) — inputting or deploying malicious software to alter, harm, disrupt, degrade or destroy a system, data, infrastructure or program — is committed against a critical infrastructure, the offender is guilty of a crime.
Penalty: for a natural person, 25 years, or a fine of K100,000, or an ICT prohibition for the term of imprisonment plus two years, or all or any of them; for a body corporate, K1,000,000.
| s 9(2) — system interference | s 27(2) — cyber attack | |
|---|---|---|
| Conduct | Hindering or interfering with functioning or lawful use | Inputting or deploying malicious software |
| Mental element | Intentional or reckless | Intentional, for the purpose of harm or disruption |
| Basic form | 10 years / K10,000 — a misdemeanour | 15 years / K50,000 — a crime |
| Aggravated form | 25 years / K100,000 for an individual; K1,000,000 for a company | |
| Daily penalty | Yes — K25,000 per day | No |
| ICT prohibition | Not provided | Yes |
Practical points
- For anyone working on shared systems. The second limb of section 9(2) reaches systems used in connection with critical infrastructure. Because banking services, schools and communication systems are within the definition, a great many ordinary commercial systems are connected to critical infrastructure in the relevant sense.
- Recklessness suffices for section 9. The aggravated offence carries the mental element of subsection (1), which includes recklessly. A person who acts with conscious disregard of an obvious risk of disrupting a bank’s or a hospital’s systems faces a 25-year maximum.
- For companies. The combination of a K1,000,000 fine and K25,000 per day makes this the most expensive offence in the Act. See corporate fines and business obligations.
- Neither aggravated form is in Schedule 2, so neither can be dealt with summarily.
Sources
- Cybercrime Code Act 2016 — ss 2, 9, 27, 48; Schedule 2
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.