CYBERSECURITY
AS someone in tech, I want to start by saying that the Government’s recent efforts to address cybercrime deserve recognition.
The anger that fuels this reaction is real and justified. Our sisters and mothers are being humiliated by mindless perverts using AI to fabricate compromising images.
Misinformation and impersonation spread through fake social media accounts, and ordinary people lose their savings to scammers who prey on trust.
When you see all that, you want the state to do something, anything, with force. And so the Government is swinging a legislative sledgehammer. But there’s a nuance. Wanting force and needing force are two different things.
Let me be clear. The proposed amendments to the Cybercrime Code Act 2016 that criminalise AI deepfakes, voice cloning, and digital impersonation are not the problem. Creating offences for AI-generated sexual exploitation, fraudulent impersonation, and scams is a legitimate, even overdue, response to real harm.
My objection is more to do with the package deal, which is a necessary, targeted amendment being used as the public face of a much larger apparatus that has been assembled piece by piece over several years, and which is now accelerating in ways most Papua New Guineans have not yet grasped.
Sim card registration yet to be done
Consider what is already happening right now. Under ministerial direction and NEC Decision No. 183/2025, Nicta – (National Information and Communications Technology Authority) has spent the better part of a year building out the draft Sim (Subscriber Identy Module) Card Registration (Amendment and Consolidation) Regulation 2026, which will link every active Sim card in the country to the national SevisPass digital identity through the SevisWallet app and the SevisDEx digital identity exchange.
Every adult over 18 must obtain a SevisPass and link their Sims.
A transition window of January to June 2026 was announced with some fanfare back in December. Unlinked Sims were expected to be deactivated after the transition period.
That deadline has now quietly passed, without any publicly reported nationwide Sim shutdown.
The consultation period had already been extended once before Nicta finally concluded it in March. Four months later, the regulation still hasn’t been gazetted.
Nobody announced an extension. It simply came and went, unremarked. The same gap, again, between the confidence of the announcement and the pace of the actual machinery. And yet the architecture keeps advancing regardless.
A new Digital ID Implementation Authority will run the entire system and provide customer due diligence services to telcos, with fees reviewed jointly by the Department of Information and Communication Technology, Nicta, and the Bank of PNG.
The Government frames this as anti-fraud policy, and the privacy safeguard is real. Telcos will stop storing raw biometrics, replaced by encrypted SevisPass tokens. But the scale of the architecture being built deserves public scrutiny.
For the first time, every active mobile number in the country will be linked to a verified digital identity, refreshed annually, with a dedicated authority managing the exchange of identity data between government, banks, and telecommunications companies.
The app itself tells the same story as the regulation. SevisWallet was unveiled with fanfare at the Digital Transformation Summit on Nov 24, 2025, with the Government promising full public launch by Dec 24.
The app’s official launch wasn’t reported until Jan 20, 2026, a month late, with no public acknowledgment that the original date had slipped. Small delay, sure. But it’s the same pattern as the SIM regulation, just compressed into six weeks instead of six months.

Ambition vs capacity
After a decade of effort, Papua New Guinea’s National ID system has enrolled only around 3.8 million people, roughly a third of the population, and the Government had to bring on extra staff just to clear the backlog.
Only about half the country has any internet access at all. This is the population the state now proposes to fold into an annually re-verified digital identity system, tethered to every Sim card.
The ambition and the capacity are not the same size. This is worrisome.
Now look at the rest of the scaffolding. The National Cyber Security Strategy 2024 establishes a National Cyber Security Centre housing a cyber threat analysis unit, a security operations centre, and a Social Media Management Desk.
The Protection of Private Communications Act 1973 already permits the interception of communications. The Digital Government Act 2022, the National Digital Identity Policy 2025, the Data Governance and Protection Policy 2024, and the National Cyber Security Policy 2021 all interlock to create the policy backbone for what is being built. This is all public knowledge, published in consultation papers, ministerial statements, and strategy documents.
But it is being sold to the public as a simple crackdown on deepfakes and scam callers, while a nationwide digital identity infrastructure, with surveillance capabilities baked into its design, is quietly being bolted together underneath it all. But all of it is designed to protect banks, power grids and government networks. Not the shop clerk whose mobile money is wiped out by a scammer.
No data protection law
Here’s the part that really irks me. There is no dedicated data protection law in this country at all, only a Data Governance and Protection Policy, which is a policy with no independent authority behind it to enforce it.
A policy doesn’t provide the enforceable rights, obligations and remedies that legislation does, and we’re being asked to trust it will hold up the weight of a national surveillance architecture.
I get that aligning with the Budapest Convention on Cybercrime means PNG must have certain investigative powers, and I understand the genuine policy rationale behind Sim registration.
Anonymous Sims do enable crime. There’s no dispute here. But look at what is being assembled. The interception act, the Social Media Management Desk, the annual Sim re-verification requirement, the data-sharing architecture between telcos, banks, and the state.
Safeguard missing
The pieces for a comprehensive surveillance system are all present. But do you see what is completely missing? Safeguard! There is no independent oversight body, and no visible warrant process in the public drafts or consultation papers.
There are just no brakes to this system that the government is building. And if there are, I’d be glad to be corrected because so far, I haven’t heard or read anything about it.
Right now, from what I’m seeing, the law doesn’t clearly distinguish between legitimate criticism and actual misinformation, and there’s no independent body deciding which is which before someone ends up being charged. We already know how prickly our leaders can be about criticism. A law this loosely worded, with no one checking where the line falls, is an easy tool to violate free speech.
Precedent
There’s already precedent for this. In 2022, a journalist was charged with defamation under the Cybercrime Act, the same one now being amended, and PNG’s Supreme Court upheld the law against his challenge two years later.
The Government has also pushed a media policy that would let it license journalists and pull those licenses over coverage it calls misleading, a proposal press freedom groups have called the thin edge of the web of state control.
None of that is proof of anything about the deepfake amendments specifically. But it’s hard not to notice that a government with this track record on criticism is the one building a system that can trace every leak, every screenshot, and every whistleblower back to a real name and a verified Sim.
When information control has already been the instinct once, it’s fair to ask whether some of this urgency is less about scam callers and more about who gets to know what, and how fast.
And then there is capacity. Who is going to staff this National Cyber Security Centre, run the Digital ID Implementation Authority, or examine a seized laptop and give evidence that holds up in court?
A law that gives police the power to seize devices is useless if they don’t know how to preserve what’s on them. Cases will collapse, smart criminals will walk, and the public will lose whatever faith it had that the system works.
Deeper problem
The deeper problem is that this apparatus mistakes a hardware problem for a human one. Most of the cybercrime hurting ordinary Papua New Guineans is unsophisticated. It doesn’t take elite hackers, just a smartphone and a basic understanding of human psychology.
The boy who creates a fake BSP Facebook account and messages your aunt about a prize isn’t a digital mastermind. He’s figured out that people trust a familiar brand and that our elders often can’t tell a real profile from a fake one.
If your grandmother in Kerema doesn’t know that BSP will never ask for her PIN over the phone, no cyber security centre and no encrypted SevisPass token is going to protect her.
What we need is a nationwide awareness campaign on protecting oneself against malevolent cyber actors. We should be running sustained radio and TV programmes in Tok Pisin and Motu that walk people through what a phishing message looks like, and putting posters at bus stops. The public needs to be informed on how to protect themselves first.
And it doesn’t take a mastermind on the other side either. A 16-year-old in Lae who can teach himself to spoof an email header or navigate the dark web from tutorial videos isn’t stupid; he’s resourceful, maybe even brilliant, and this country offers him no computer lab, or coding club, or any kind of legal pathway into that talent.
The underground offers him community, challenge, and cash instead. The sledgehammer approach just converts that kid into a criminal, and prisons here don’t rehabilitate, they harden.
A boy goes in for an online scam and comes out knowing how to run a much bigger operation, because now he has the connections and the chip on his shoulder to match. Multiply that by a few hundred, and we’re not fighting cybercrime, we’re swelling Bomana with tech-savvy inmates the state never tried to reach on the outside.
I wish I could say with confidence that digital literacy, provincial tech hubs, or training a generation of our own cybersecurity professionals were somewhere in the policy documents.
I just haven’t seen it. What I see is a government that wants to look tough and reassure the public that it’s doing something, without doing the slow, quiet work that would actually make a difference.
You want to stop cybercrime? Teach a grandmother to recognise a scam. Give a bored, talented teenager a legal way to make money with his skills. Build a help desk that ordinary people can call when they think they’ve been hacked. Train police officers not just to arrest, but to understand what they’re arresting for.
These things don’t make for dramatic headlines, but they work, because they address the root of the problem, not just the symptoms.
So what I’m saying is, the Government needs to get their hands dirty and do the ground work first. This is unglamorous, but it’s the foundation on which all of this will be built.
Cybercrime will keep happening no matter how many laws we pass or how many Sim cards we link.
We already know the Government can crack down harder. Nobody is doubting its will to action. But does it have the patience to build something that actually lasts?
I don’t mean to be a party crasher but these things have to be brought up and addressed. I hope I am wrong and that the Government already has plans for the points I raised. I only raised them because that information was not released to the public.
• Philemon Kaisa is a software developer and writer based in Port Moresby. His interests span technology, culture, governance, and the social forces that shape PNG society.
Click Here For The Original Source.
