HomeCybercrimeData and system offences

What Is System Interference?

Hindering or interfering with the functioning of an electronic system or device, or with a person’s lawful use or operation of one — intentionally or recklessly. A misdemeanour carrying up to 10 years or K10,000, and K100,000 for a company.

The cybercrime series, no. 14 · Attacks on data and systems · 5 min read

Where section 8 protects data, section 9 of the Cybercrime Code Act 2016 protects the systems that run it.

Section 9(1) — the offence

Section 9(1)

A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, or recklessly

(a) hinders or interferes with the functioning of an electronic system or device; or

(b) hinders or interferes with a person’s lawful use or operation of an electronic system or device,

is guilty of a misdemeanour.

Penalty: (a) in the case of a natural person, a fine not exceeding K10,000 or imprisonment not exceeding 10 years, or both; and (b) in the case of a body corporate, a fine not exceeding K100,000.

A misdemeanour with a 10-year maximum

Section 9(1) is one of only three misdemeanours in the Act — with section 6(1) and section 11 — yet it carries a higher maximum sentence than either. See the article on the distinction.

It is listed in Schedule 2, so it may be tried summarily. The aggravated form in section 9(2) is not.

“Hinder” and “interference”

Section 2

“Hinder” means any act which interferes with the proper functioning of an electronic system or device, including but not limited to cutting or disrupting the electricity supply to that electronic system or device.

“Interference” means tampering with the integrity of information content, electronic data or systems, and includes damaging, deletion, deterioration, alteration, suppression, modification and hindering.

Cutting the power is a cybercrime

The definition of hinder expressly includes cutting or disrupting the electricity supply. Physically switching off, unplugging or interrupting power to a server, a router or a terminal is system interference under section 9 — not merely a property or trespass matter.

That is a deliberate choice. The Act protects the functioning of systems, and it is indifferent to whether the attack is delivered through the network or through the power cable.

“Any act” also means the offence is not limited to technical means. Blocking cooling, cutting a cable, jamming a signal or physically obstructing a device all hinder its proper functioning.

The two limbs

Paragraphs (a) and (b) of section 9(1)
ParagraphProtectsExamples
(a) functioning of the system or deviceThe machine or system itselfA denial of service attack; flooding a network; overloading a server; cutting the power; jamming a wireless signal; disabling a service
(b) a person’s lawful use or operationThe user’s ability to use itLocking a user out; changing credentials; blocking a colleague’s access to a terminal; disrupting someone’s connection
Paragraph (b) catches conduct that leaves the system working

A system can be operating perfectly while one person is prevented from using it. Paragraph (b) makes that an offence in its own right, provided the person’s use was lawful.

Note the overlap with section 8(f) and (g), which protect a person’s lawful use of data and access to it. Section 9(1)(b) protects use of the system or device. In practice both are often engaged.

Data interference or system interference?

Section 8 compared with section 9(1)
s 8 — data interferences 9(1) — system interference
ObjectData — including programsElectronic system or device, or a person’s use of one
ClassificationCrimeMisdemeanour
ImprisonmentUp to 10 yearsUp to 10 years
Fine — individualUp to K20,000Up to K10,000
Fine — companyUp to K100,000
Recklessness sufficesYes
Aggravated formNoneYess 9(2), critical infrastructure
Triable summarilyYes — Schedule 2
A single incident usually engages both

A denial of service attack hinders the system’s functioning (s 9(1)(a)) and obstructs users’ lawful use of data (s 8(f)). Ransomware encrypts data (s 8(d)), denies access to it (s 8(g)), and disrupts the system (s 9(1)(a)) — and if deployed to procure a benefit, is also cyber extortion under section 24(1), and if it involves malicious software, a cyber attack under section 27.

The choice of charge will usually turn on the maximum penalty available and on whether the target was critical infrastructure, which raises section 9 to 25 years and adds K25,000 for each day the infrastructure remains inoperable.

Maintenance, testing and the lawful excuse

Where legitimate work meets the offence

Taking a system down for maintenance hinders its functioning and interferes with users’ lawful use. What makes it lawful is authority.

Three points follow:

Stay within the authorisation. Acting in excess of a lawful excuse is expressly within the offence. An outage beyond an approved window, or affecting systems outside the change, is exposed.

Recklessness is enough. A change made with conscious disregard of an obvious risk of outage may satisfy section 9 even where no harm was intended.

Security testing. A load test or a simulated denial of service run without the owner’s authority hinders functioning. Written authority is essential — and note the related defence for authorised testing in section 16(2), which applies to illegal devices.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.