Draft cyber security strategy shifts focus to AI threats

M
Mahmudul Hasan

The government has drafted a new National Cyber Security Strategy for 2026-2030 that shifts its focus to emerging threats from artificial intelligence (AI) and quantum computing.

The draft takes a different approach from the previous five-year strategy as cyber threats become more sophisticated and the country becomes increasingly dependent on digital services.

Prepared by the National Cyber Security Agency with the ICT Division, the draft was unveiled at a programme in Dhaka recently.

It sets out a five-year roadmap to protect critical digital infrastructure, build a 20,000-strong cyber security workforce and update cyber security laws and institutions to keep pace with rapidly changing technologies.

For the first time, the strategy elaborated plans to secure technologies such as AI, cloud computing, the Internet of Things (IoT), 5G and 6G networks, blockchain and post-quantum cryptography.

The draft also cited “harvest now, decrypt later” attacks, in which encrypted data stolen today could one day be decrypted using powerful quantum computers.

The strategy replaces the previous National Cyber Security Strategy for 2021-2025 and is built around six strategic pillars and 11 priorities.

ICT Division officials said it will be revised following consultations with government agencies, industry representatives and academics before being finalised.

GROWING CYBER RISKS

The draft says the country’s digital ecosystem has expanded rapidly, with around 120 million internet users and 190 million mobile subscribers now generating millions of mobile financial transactions every day.

It says this rapid growth has significantly widened the country’s exposure to cyber attacks.

Citing the Bangladesh Cyber Threat Landscape 2024 report, the draft says government platforms recorded the highest number of reported cyber incidents last year, with 63 cases. The financial and education sectors followed with 34 incidents each.

Data breaches and leaks were the most common type of attack, accounting for 59 reported incidents, followed by website defacement and compromised user credentials.

The draft also points to a growing volume of Bangladeshi data being traded on dark web marketplaces. Email addresses made up the largest share of leaked information at 20 percent, followed by full names at 18 percent and phone numbers at 15 percent. Government-issued identity documents, including national identity cards and passports, accounted for another 10 percent.

It also highlights the country’s standing on global cyber security benchmarks. As of January 2025, the draft says the country ranked 64th in the National Cyber Security Index (NCSI) with a score of 66.67.

It was also placed in the “role-modelling” tier of the International Telecommunication Union’s Global Cyber Security Index 2024, although it scored comparatively lower on legal measures.

SIX PILLARS

The strategy is built around six pillars. Those are protecting critical infrastructure, creating a resilient cyber ecosystem, developing the cyber security workforce and industry, strengthening citizen protection and digital trust, securing emerging technologies, and expanding international cooperation and cyber diplomacy.

Under the first pillar, the draft calls for a comprehensive review of the country’s list of critical information infrastructure and the adoption of international cyber security standards, with particular attention to small and medium-sized enterprises.

To strengthen national cyber defences, it proposes making key institutions fully operational, including the National Cyber Security Agency, a National Security Operations Centre, a National Computer Emergency Response Team (CERT) and a Cyber Crisis Management Centre.

It also sets a target of securing at least $10 million in annual funding for the national agency.

The strategy aims to develop 20,000 cybersecurity professionals by 2030 and increase women’s participation in the sector to at least 30 percent.

To improve public protection, it proposes a 24-hour national cybercrime helpline and a citizen-facing National Cyber Security Center.

The draft also identifies several setbacks that could slow implementation. These include a shortage of specialised cyber security professionals, weak collaboration between industry, academia and government on research commercialisation, poor cyber security practices among small and medium-sized businesses that could serve as entry points into larger networks, and continued reliance on outdated protocols such as SMB and Telnet in some systems.

The final pillar focuses on strengthening international cooperation through bilateral and multilateral cyber security agreements, joint exercises and cross-border cooperation to combat cyber crime.

TARGETS FOR 2030

The draft sets several national targets for 2030. These include placing the country among the world’s top 20 in both the National Cyber Security Index and the Global Cyber Security Index, completing risk assessments for all critical information infrastructure entities and reaching 50 million people through cyber security awareness programmes.

According to the draft, the National Cyber Security Agency will establish baseline values for all performance indicators within a year of the strategy being approved. It will also publish annual progress reports, while a mid-term review is scheduled for 2028.