(a) within twenty four hours after a cybersecurity incident is detected, report the incident to – (i) the relevant sectoral CERT; or (ii) the Malawi CERT, if the critical information infrastructure does not belong to any sectoral CERT; (b) cause an audit to be conducted on the critical information infrastructure; and (c) submit a copy of the audit report to the Authority. (2) An owner of critical information infrastructure who fails to comply with subsection (1) is liable to pay to the Authority the administrative penalty specified in the Schedule. Access to critical information infrastructure 22. - (1) A person shall not, without authorization – (a) secure access; or (b) attempt to secure access, to a computer system or a computer network designated as a critical information infrastructure. (2) A person shall not, without lawful justification, block – (a) access to critical information infrastructure; or (c) access to a site that is hosting critical information infrastructure. (3) A person who contravenes subsections (1) and (2) commits an offence and shall, upon conviction, be liable to a fine of K5,000,000 and to imprisonment for five years. (4) Where the offence committed under subsections (1) and (2) – (a) results in a serious bodily injury, or financial loss or damage to the computer system or computer network designated as a critical information infrastructure, the person who committed the offence shall, upon conviction – (i) in the case of an individual, be liable to a fine of K15,000,000 and imprisonment for fifteen years; and 20

Select target paragraph3