Strengthening Cyber Resilience for MSMEs: Tackling Financial Fraud and Improving Grievance Mechanisms
The Asia Foundation and The Daily Star jointly organised a policy dialogue on 14 July 2026, with support from Google.org. The dialogue brought together representatives from government, financial institutions, telecommunications sector, development partners, academicians, MSME representatives, and media to address growing cyber risks and financial fraud in the digital economy. Participants emphasised practical measures to improve fraud awareness, enhance grievance reporting and redress mechanisms, and foster public-private collaboration. The discussion focused on building a safer digital ecosystem that empowers MSMEs to securely adopt financial services and drive inclusive growth.
Tahsin Ifnoor Sayeed
Director
Impact & Innovation Lab
Spreeha Foundation
The digital attack surface varies significantly across the MSME landscape. Businesses operating primarily on Facebook and via digital payments face greater exposure to cyber fraud because they handle more online transactions and personal information. Meanwhile, pharmacy operators and small retail shops are more vulnerable to WhatsApp-based scams, where fraudsters offer fake discounts in exchange for advance payments, sometimes causing businesses to lose two to three days’ working capital. However, many entrepreneurs have naturally adopted practical safety measures, such as using a separate low-cost phone for business communications to reduce cyber exposure. Therefore, awareness programmes should present cybersecurity as a shared responsibility rather than a compliance requirement. Explaining how simple actions such as avoiding suspicious links, never sharing PINs, and securely storing business records can help protect the entire digital ecosystem.
Tanjim Al Fahim
Chief Executive Officer
Arena Web Security
SMEs often seek cybersecurity assistance only after facing critical issues, such as severe data loss or permanent bans on social media accounts resulting from unrecognised platform policy violations. While 80% of these post-incident cases can be successfully resolved, the remaining 20% of prominent businesses face the risk of permanent closure due to a lack of proactive digital backups. Furthermore, a widespread misconception persists that robust cybersecurity solutions are prohibitively expensive. In reality, basic one-time setups, including free online firewalls and routine bi-weekly backups, can effectively safeguard a business as it scales from small to medium levels. Relying solely on voluntary awareness programs is insufficient given the rising dependency on IT. Integrating basic cybersecurity assessments into official policy levels, similar to standard trade license or bank loan requirements, remains crucial. Providing a clear, low-cost framework will ultimately ensure widespread adoption and secure inclusive economic growth.
Syed Ibrahim Saajid, PMP
Head of Digital Banking
City Bank PLC
Cyber fraudsters adapt to new situations much faster than financial institutions and regulators, often changing tactics within days or weeks. For example, after major events in 2024, scams quickly emerged using fake calls and messages impersonating authorities, while fraudulent traffic violation messages also appeared soon after new digital services were introduced. Therefore, cybersecurity awareness should become part of the education system from school level to create long-term digital resilience. At the same time, stronger protection of public and private sector data is essential because leaked personal information makes fraud far more convincing. In addition, providing financial institutions with secure mobile number verification linked to national identity records during customer onboarding could significantly reduce identity-related fraud. Such a measure alone could potentially reduce around 50% of financial fraud cases while strengthening trust in digital financial services.
Md. Shazzad Hosain, PhD
Professor and Dean
Department of Electrical & Computer Engineering
North South University
Cybersecurity education in Bangladesh is expanding, but dedicated courses and research facilities remain limited across universities. Therefore, stronger collaboration between academia, industry, and government can help build national cyber resilience. Since December 2025, North South University’s cybersecurity centre has trained 120 students and is working to provide basic cyber hygiene training to 300 MSMEs. The next step is to establish a cyber intelligence lab with a security operations centre, digital forensics, fact-checking, and research facilities to support businesses and public institutions. In addition, universities can contribute practical solutions, including AI-enabled threat monitoring dashboards, security tools, and cybersecurity testing services. A recent analysis of a 120 GB ransomware-related data breach showed that a single unsafe click by an employee triggered the attack, highlighting the importance of user awareness alongside regular penetration testing, secure software development, and expert security assessments.
Md. Sadequl Arefeen
Director
Bondstein - Frontier Tech Solutions
As Bangladesh moves towards a cashless economy, strengthening cybersecurity alongside digital growth is becoming increasingly important. Bangladesh’s e-commerce and f-commerce sector now includes around 300,000 active businesses, with an estimated Tk 180–250 crore in daily transactions, making trust and security essential. Therefore, introducing a national trust mark for secure digital platforms could help businesses and consumers identify reliable services. At the same time, MSMEs need affordable cybersecurity solutions, which could be delivered through partnerships between business associations and software companies using low-cost subscription models. In addition, integrating cyber incident response into the existing 999 emergency service could provide immediate support for affected businesses. Finally, software providers should strengthen data protection, security monitoring, and compliance standards so that cyber risks are addressed proactively, creating a safer and more trusted digital ecosystem for MSMEs.
Md. Nomanuzzaman
Director
SAJIDA Foundation
Cybersecurity awareness remains the first line of defence against financial fraud. Under an ongoing initiative, nearly 90,000 MSMEs have received basic cyber hygiene training, and about 95% of the programme has already been completed. However, with over 8 crore Facebook users across the country, current digital literacy efforts are just scratching the surface. Because cyber fraud entry points remain highly basic, awareness programs must expand extensively through collaborative public-private frameworks. At the same time, an integrated grievance response system involving regulators, financial institutions, mobile financial service providers, and law enforcement is essential. Building public trust is equally important, as people are more likely to report incidents when they are confident of receiving timely support. Sharing successful case resolutions and improving response speed can further strengthen confidence and help the country stay ahead of rapidly evolving cyber threats.
Arif Faisal
Editor & CEO
The Prestige Magazine
Financial fraud is becoming increasingly sophisticated, with criminals reportedly using rented national identity details and multiple mobile accounts to move stolen funds through 20–30 channels within minutes, making investigations more difficult. Therefore, stronger identity verification and closer coordination among relevant agencies are essential. At the same time, limited financial and digital literacy makes MSMEs more vulnerable because cyber safety messages often use technical language that is difficult for grassroots entrepreneurs to understand. Awareness campaigns should therefore use simple, practical language that reflects the daily experiences of small businesses. In addition, many victims hesitate to report fraud because they feel embarrassed or fear being judged. Creating a more supportive and user-friendly reporting process can encourage greater reporting and faster response. Since cybercrime continues to evolve globally, sustained collaboration, prevention, and continuous awareness efforts remain essential for building long-term cyber resilience.
Fasbeer Eskander
Co-Founder & Publisher
The Front Page
To improve cybersecurity, implementing temporary verification codes for identity checks, similar to international practices, can greatly enhance data privacy. Currently, administrative requirements mandate distinct phone numbers for multiple businesses, creating chaotic exposure. Consequently, maintaining a strict separation between public business contacts and personal numbers is essential to minimise fraud. Furthermore, applying “device hardening” such as firewalls and usage restrictions remains crucial for protecting business operations. Rather than acting post-incident, financial institutions must prioritise preventive awareness during customer onboarding. On a national scale, establishing a collaborative cybersecurity authority to certify academic programs and build community-based cyber awareness networks could support MSMEs through comprehensive digital literacy, especially in rural areas where personal and business risks often overlap. Finally, enforcing breach reporting and publishing regular media updates on diverse cyber threats will drive collective accountability and effectively reduce systemic vulnerabilities.
Md Taifur Rahman
Deputy Director
Bangladesh Telecommunication Regulatory Commission (BTRC)
Cybercriminals often exploit human emotions through offers that seem too good to be true, making awareness the first line of defence. Therefore, awareness should extend beyond major cities and reach MSMEs across the country, especially in high-risk areas, as a single click can compromise an entire system. Stronger data protection is also essential. While the Personal Data Protection Act 2026 is a positive step, introducing mandatory breach notification would help people respond quickly when personal information is exposed. In addition, organisations handling customer data should be accountable for protecting it and informing users of breaches. Affordable subscription-based cybersecurity solutions can strengthen MSME security, while the planned NID-SIM-MFS verification system, expected to be implemented within six to eight months, could significantly improve identity verification and help reduce digital fraud. Finally, awareness, secure software, responsible data management, and shared accountability across both public and private sectors are all necessary to build a safer digital ecosystem.
Md. Hafizul Islam Babu, PPM
Additional Deputy Commissioner
Cyber and Special Crime (South) Division
Dhaka Metropolitan Police (DMP)
MSMEs face significant digital threats, primarily driven by social engineering tactics rather than direct system hacks. Common vulnerabilities include phishing links, business email compromises, fake payment screenshots, and highly organised fraudulent pages that spend large amounts on aggressive boosting. Furthermore, advanced Remote Access Trojan (RAT) attacks frequently exploit users who download unauthorised free streaming applications to log sensitive financial details. Consequently, establishing an AI-driven, centralised national cyber fraud reporting cell remains a vital priority. This integrated platform will enable law enforcement, financial institutions, and regulators to collaborate seamlessly. Implementing immediate asset-freezing protocols during active investigations will effectively disrupt financial gains and dismantle organised syndicates. Ultimately, pairing these structural solutions with specialised training at the local law enforcement level will overcome reporting delays, enhance cross-border platform data sharing, and cultivate a highly secure digital marketplace.
Farzana Khan
Deputy Managing Director
SME Foundation
As MSMEs transition into the economic mainstream, integrating digital tools for market access and globalisation becomes unavoidable. While traditional cash transactions disappear in global export markets, the necessity of navigating the digital landscape increases. Consequently, addressing rising vulnerabilities—such as phishing links, fraudulent SMS alerts, and social engineering—requires robust cybersecurity protocols rather than avoiding digital adoption altogether. To minimise these vulnerabilities, foundational awareness remains the primary defence across all roles, whether as customers, sellers, or service providers. Essential practices include securing transaction emails, managing dynamic OTP transfers carefully, and avoiding financial dealings on public Wi-Fi networks. Furthermore, collaborating on a comprehensive cybersecurity manual and extending specialised training programs beyond metropolitan hubs will systematically empower local entrepreneurs. Ultimately, cultivating an integrated public-private ecosystem will drive a secure, highly competitive, and inclusive digital marketplace.
Nawshad Mustafa
Director
SME & Special Programmes Department
Bangladesh Bank
Addressing growing digital risks requires integrating financial literacy and cybersecurity concepts directly into national curricula. Collaborative efforts with the textbook board have already successfully introduced dedicated chapters into secondary education materials. Furthermore, permitting mobile financial services to tag accounts to guardian SIMs ensures that younger users build safe, long-term digital transaction habits from an early stage. Basic practices, such as separating personal and business accounts, limiting employee system access, and never sharing OTPs or passwords, can prevent most financial fraud. Currently, an ADB-funded program of ours is delivering 100 hours of specialised training over 20 working days to 3,000 entrepreneurs, aiming to bridge knowledge deficits across remote areas. Finally, enhancing emergency services like 999 remains essential for rapid responses. Allowing banks to cross-verify SIM registrations against NID databases will effectively curb identity fraud, while institutional helplines like 16236 will safeguard expanding MSME operations.
Kazi Faisal Bin Seraj
Country Representative
The Asia Foundation
MSMEs play a critical role in job creation, making their protection in the expanding digital economy vital. To manage emerging threats, a balanced, collective ecosystem approach must integrate automated technology with robust personal cybersecurity habits. Rather than taking extreme measures that stifle growth, the primary focus must remain on risk minimisation. For instance, choking the 95% majority growth to eliminate a minor 5% risk margin sends a highly counterproductive signal to expanding markets. Furthermore, data privacy requires urgent attention, particularly regarding the handling of sensitive participant lists at events to prevent identity theft. Cultivating mass grassroots digital literacy from an early age remains the ultimate preventative solution. Ultimately, finding the right balance between operational convenience and safety will ensure a secure, uninterrupted economic journey.
Tanjim Ferdous
Head of Strategic Partnerships
The Daily Star (Modaretor of the session)
Bangladesh’s digital economy is expanding rapidly, with micro, small and medium enterprises (MSMEs) increasingly adopting digital platforms for business growth. While this transformation has created new opportunities, it has also increased exposure to cyber threats such as financial fraud, phishing, identity theft, and account takeovers. Strengthening cybersecurity and digital trust is therefore essential for sustaining inclusive economic growth. This roundtable aimed to explore the key cyber risks facing MSMEs, examine existing grievance and reporting mechanisms, and identify practical recommendations to improve institutional coordination, raise awareness, and build a safer, more resilient, and trusted digital ecosystem for businesses in Bangladesh.
M Abu Eusuf, Executive Director, Research and Policy Integration for Development (RAPID); Tania Wahab, Managing Partner, Karigar (SME); Izlal Husain, Senior Program Manager, The Asia Foundation also spoke at the event.
Recommendations
- Strengthen nationwide cybersecurity awareness programmes for MSMEs, with special focus on entrepreneurs in rural and underserved areas
- Introduce mandatory data breach notification requirements to ensure timely action and greater accountability for organisations handling personal data
- Develop affordable, shared cybersecurity solutions and practical guidelines to help MSMEs improve digital security without high cost.
- Strengthen coordination among government agencies, financial institutions, telecom operators, and law enforcement to enable faster fraud detection, reporting, and response.
- Integrate cybersecurity and digital financial literacy into school curricula and expand continuous capacity-building programmes for entrepreneurs.
- Accelerate secure identity verification by linking NID, SIM registration, and financial accounts while ensuring strong data protection and privacy safeguards.
Comments