HomeCybercrimeIn practice

What Should a Business Do About Cybercrime Risk?

Two things at once: protect itself as a victim, and manage its exposure as a potential offender. Twelve provisions of the Act carry corporate fines of K1,000,000, and one adds K25,000 for each day critical infrastructure stays down.

The cybercrime series, no. 95 · Practical guidance · 5 min read

Most discussion of the Cybercrime Code Act 2016 treats a business as a victim. The Act also treats it as a potential offender, and the corporate fines are substantial.

Where a business is exposed as offender

Common routes to corporate liability
ProvisionHow an ordinary business gets thereCorporate fine
s 28Unlicensed software across the networkK1,000,000
s 25(2)An employee discloses confidential materialK500,000
s 23(4)Unmoderated content on a company pageK50,000
s 26Deceptive bulk messaging or falsified headersK100,000
s 21Defamatory statements published by the businessK500,000 – K1,000,000
s 29Selling goods with a forged registered trade markK1,000,000
s 44As an ICT service provider — monitoring, obstruction, or ignoring an orderK1,000,000
s 31Advertising something that would be an offenceK500,000

See the full table of corporate fines and how a company commits an offence.

Eight measures that answer most of it

Almost every offence turns on lawful excuse

The opening words of nearly every provision are “without lawful excuse or justification, or in excess of a lawful excuse or justification”. Documented authority is therefore the central compliance measure, not an administrative formality.

  1. An access policy, in writing. Who may access which systems and data, and for what purposes. This establishes the lawful excuse for staff, and its boundaries.
  2. Access on need, and logged. Every person with access to confidential material is a person within section 25(2), with its 25-year maximum.
  3. A software licence register. The direct answer to section 28, which requires infringement to be knowing and repeated.
  4. A moderation policy for company pages. Section 23(4) reaches those who authorise, facilitate or enable the posting of vulgar or obscene commentary.
  5. Marketing discipline. Send from your own systems, do not disguise the sender, keep header information accurate — section 26.
  6. A written scope for any security testing, current and signed. See the defence for security testing and section 16.
  7. A legal hold procedure. The ability to stop automated deletion of specified data on the day a preservation notice arrives. Failure is an offence.
  8. Training and supervision. Where the business is an ICT service provider, section 44(1)(e) makes negligently allowing an employee to offend a crime in itself — the only negligence offence in the Act.

Preparing to be a victim

Evidence preservation is an operational capability

After an incident, the instinct is to restore service. Restoring from backup destroys the state of the compromised system and with it the evidence.

Build the capability in advance:

  • Off-system backups, tested. These are also what limits the damage from ransomware — and why paying is unnecessary.
  • Log retention long enough to be useful, with accurate clocks.
  • An incident procedure that names who isolates the system, who preserves images, and who calls police and the lawyers.
  • Identification of critical systems in advance, so that if police remove equipment, the business can immediately explain what is business-critical and offer imaging as the alternative.

On the day of an incident

  1. Isolate, do not wipe. Disconnect from the network; leave the system intact.
  2. Preserve logs and images before remediation.
  3. Report. Ask about a section 36 preservation notice for any third-party data involved.
  4. Do not pay a ransom. It funds the offence and guarantees nothing.
  5. Tell the bank immediately where funds moved.
  6. Take advice on notification to affected customers — and note that where a confidential court order is in place and the business is an ICT service provider, section 45 prohibits disclosing it.

If the business is an ICT service provider

Check Schedule 1. The seven categories include web hosting providers and, significantly, website masters or administrators — so an individual maintaining the company website is within Part V.

Providers need, in addition: a nominated law enforcement contact, a logged process for notices and orders, controls preventing staff from inspecting user data (section 44(1)(a)), and training on the confidentiality obligation in section 45.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.