Most discussion of the Cybercrime Code Act 2016 treats a business as a victim. The Act also treats it as a potential offender, and the corporate fines are substantial.
Where a business is exposed as offender
| Provision | How an ordinary business gets there | Corporate fine |
|---|---|---|
| s 28 | Unlicensed software across the network | K1,000,000 |
| s 25(2) | An employee discloses confidential material | K500,000 |
| s 23(4) | Unmoderated content on a company page | K50,000 |
| s 26 | Deceptive bulk messaging or falsified headers | K100,000 |
| s 21 | Defamatory statements published by the business | K500,000 – K1,000,000 |
| s 29 | Selling goods with a forged registered trade mark | K1,000,000 |
| s 44 | As an ICT service provider — monitoring, obstruction, or ignoring an order | K1,000,000 |
| s 31 | Advertising something that would be an offence | K500,000 |
See the full table of corporate fines and how a company commits an offence.
Eight measures that answer most of it
The opening words of nearly every provision are “without lawful excuse or justification, or in excess of a lawful excuse or justification”. Documented authority is therefore the central compliance measure, not an administrative formality.
- An access policy, in writing. Who may access which systems and data, and for what purposes. This establishes the lawful excuse for staff, and its boundaries.
- Access on need, and logged. Every person with access to confidential material is a person within section 25(2), with its 25-year maximum.
- A software licence register. The direct answer to section 28, which requires infringement to be knowing and repeated.
- A moderation policy for company pages. Section 23(4) reaches those who authorise, facilitate or enable the posting of vulgar or obscene commentary.
- Marketing discipline. Send from your own systems, do not disguise the sender, keep header information accurate — section 26.
- A written scope for any security testing, current and signed. See the defence for security testing and section 16.
- A legal hold procedure. The ability to stop automated deletion of specified data on the day a preservation notice arrives. Failure is an offence.
- Training and supervision. Where the business is an ICT service provider, section 44(1)(e) makes negligently allowing an employee to offend a crime in itself — the only negligence offence in the Act.
Preparing to be a victim
After an incident, the instinct is to restore service. Restoring from backup destroys the state of the compromised system and with it the evidence.
Build the capability in advance:
- Off-system backups, tested. These are also what limits the damage from ransomware — and why paying is unnecessary.
- Log retention long enough to be useful, with accurate clocks.
- An incident procedure that names who isolates the system, who preserves images, and who calls police and the lawyers.
- Identification of critical systems in advance, so that if police remove equipment, the business can immediately explain what is business-critical and offer imaging as the alternative.
On the day of an incident
- Isolate, do not wipe. Disconnect from the network; leave the system intact.
- Preserve logs and images before remediation.
- Report. Ask about a section 36 preservation notice for any third-party data involved.
- Do not pay a ransom. It funds the offence and guarantees nothing.
- Tell the bank immediately where funds moved.
- Take advice on notification to affected customers — and note that where a confidential court order is in place and the business is an ICT service provider, section 45 prohibits disclosing it.
If the business is an ICT service provider
Check Schedule 1. The seven categories include web hosting providers and, significantly, website masters or administrators — so an individual maintaining the company website is within Part V.
Providers need, in addition: a nominated law enforcement contact, a logged process for notices and orders, controls preventing staff from inspecting user data (section 44(1)(a)), and training on the confidentiality obligation in section 45.
Sources
- Cybercrime Code Act 2016 — ss 9, 16, 21, 23–31, 35, 36, 44, 45; Schedule 1
- Companies Act 1997; Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.