National cybersecurity rating system set for launch
Bangladesh is set to launch a National Rating System (NRS) that will, for the first time, give every government and private institution a standardised score based on how well it manages IT, information and cybersecurity.
Built on a four-pillar framework called the National ICT and Cybersecurity Maturity Rating, the system is expected to provide the country’s first evidence-based benchmark for measuring institutional cyber readiness. It comes as Bangladesh’s rapidly expanding digital landscape continues to face cyber breaches, fraud and financial theft.
The system will be unveiled today at the ICT Division, according to documents obtained by The Daily Star.
The first pillar, IT and Information Security Governance, carries a weight of 20 percent and will assess leadership, policies, organisational structure and administrative accountability.
The second pillar, Infrastructure and Operations, accounts for 30 percent of the score. It will evaluate IT infrastructure, data centres, networks, servers, backup and disaster recovery systems, and change management.
The system comes as Bangladesh’s rapidly expanding digital landscape continues to face cyber breaches, fraud and financial theft
The third pillar, Cybersecurity and Data Protection, also carries 30 percent. It covers security controls, data protection, risk management, incident response, vulnerability management and audit compliance.
The remaining 20 percent comes from Digital Service and User Maturity, which assesses the quality of digital services, user-centricity, IT service management, software governance and continuous improvement.
Each of the 131 indicators under the four pillars will be scored on a five-point maturity scale, ranging from 0 (not implemented) to 4 (fully implemented or optimised). The intermediate levels are initial/ad hoc, partially implemented and largely implemented.
The weighted scores will then be combined into a total score out of 100 and converted into a letter grade from A (excellent) to E (poor).
Officials said the indicators were developed in line with internationally recognised standards and frameworks, allowing an institution’s overall ICT and cybersecurity readiness to be assessed through a single integrated system.
Bangladesh has long lacked a unified system to assess how well operators of critical information infrastructure, government agencies and private institutions are prepared to deal with cyber-attacks, data theft, ransomware and service disruptions, an ICT Division official said.
He added that institutions currently differ widely in their policies, technical safeguards, staffing, infrastructure and digital service management, making it difficult to compare their cyber readiness or identify areas that need improvement.
The government expects the rating system to identify institutional weaknesses and risks, help prioritise IT audits and vulnerability assessment and penetration testing (VAPT), and support planning for budgets, staffing and infrastructure.
According to the documents, the system will also create a national maturity baseline by producing an annual ranking of public and private institutions. Officials said this would support evidence-based policymaking and strengthen the country’s cyber resilience and interoperability.
Future phases of the system will include an AI-based automated assessment engine, automated validation of submitted documents, sector-wise benchmarking, comparative analytics dashboards, and automated, risk-based recommendations and improvement roadmaps for individual institutions.
The framework is being introduced as Bangladesh faces growing cyber risks. As of June, the country had 13.60 crore internet users.
Several major cyber incidents have highlighted these risks.
In 2016, hackers stole millions of dollars from Bangladesh Bank in one of the world’s largest cyber-enabled bank thefts.
In 2023, a breach of a government birth and death registration website exposed the personal data, including national ID numbers, of more than 50 million Bangladeshis.
In July 2025, Bangladesh Bank warned banks and financial institutions to strengthen their systems against possible cyber-attacks targeting critical information infrastructure, including the banking, healthcare and public service sectors.
According to the Bangladesh Cyber Threat Landscape 2024 report, published by an ICT Division unit, 188 cybersecurity incidents were reported in 2024.
Comments