[🇧🇩] Cyber Defense of Bangladesh

[🇧🇩] Cyber Defense of Bangladesh
1
128
More threads by Saif

G Bangladesh Defense

Saif

Senior Member
Joined
Jan 24, 2024
Messages
19,449
Likes
9,006
Nation

Residence

Axis Group

Cyber defense: security imperative

1768613297115.webp


BANGLADESH stands at a turning point where digital transformation and national security intersect more closely than ever before. A rapid progress ion government services, banking, education, health care, industries and defence reflects a bold march towards modernisation. This acceleration into a digital future brings with it a complex set of cyber risks that grow faster than most institutions can handle. Globally, cyber attacks have evolved from isolated incidents into a continuous, borderless threat environment.

Cybersecurity Ventures reports that cyber crime costs increase at an alarming rate of 15 per cent annually and are set to reach $10.5 trillion in 2025 and an estimated $15.6 trillion by 2029. A single data breach now costs nearly $4.44 million on an average while artificial intelligence-powered phishing attacks achieve 50 per cent higher success rates, contributing to more than $17 billion in annual losses.

According to the Stockholm International Peace Research Institute, global military expenditure reached $2.718 trillion in 2024, marking the highest level ever recorded and reflecting a year-on-year increase of 9.4 per cent. Major spenders, including the United States, China, Russia, Germany and India, accounted for about 60 per cent of total global defence expenditure, with a growing share allocated to advanced technologies, cyber capabilities and digital resilience. The figures highlight how nations are increasingly prioritising cyber defence as a core component of national security. The world faces a shortage of nearly four million cyber security professionals, leaving critical systems dangerously exposed.

Bangladesh mirrors this global tension in its own digital landscape. With more than 134 million internet users and more than 60 million social media users, the national attack surface is vast and expands daily. Internet banking transactions crossed Tk 1.12 trillion in a single month, demonstrating both the scale of digital adoption and the magnitude of potential risks. The year 2025 alone witnessed 63 million cyber attacks targeting Bangladesh, with financial institutions facing more than 600 attacks every day. The Bangladesh Bank cyber heist, deep fake attempts targeting government figures, ransomware incidents in the pharmaceutical sector and attempts to illegally sell access to the Titas Gas firewall server on the dark web illustrate how deeply cyber threats have embedded themselves into the digital ecosystem.

A study indicates that cyber crimes doubled in Bangladesh in a year, with 40 per cent of victims suffering financial losses and nearly 48 per cent experiencing serious social consequences, including defamation and harassment. National intelligence assessments further show sharp increases in phishing, social engineering, identity fraud and unauthorized access attempts, affecting not only individuals but also critical infrastructure.

While Bangladesh has introduced important initiatives such as the National Cybersecurity Strategy 2021–2025, the Cyber Safety Ordinance 2025 and institutional strengthening through BGD e-Gov CIRT, the National Cyber Security Agency, BTRC’s Digital Safety Directorate, BCSI and cyber crime units under the Counter Terrorism and Transnational Crime, the Criminal Investigation Department and the Rapid Action Battalion, significant gaps in capacity and capability remain. Many public and private organisations continue to rely heavily on foreign cyber security solutions that are costly, opaque and often poorly aligned with local threat patterns. Universities, despite producing capable engineering graduates, frequently lack specialised teachers, cyber ranges, red-blue team training environments and SOC simulation laboratories necessary for developing real-world defensive expertise. Research efforts remain fragmented and underfunded while collaboration among government bodies, defence institutions, academia and the private sector is still limited.

Against this backdrop, a clear opportunity emerges for Bangladesh to strengthen national cyber-defence through local innovation and skills development. The priority must be building a robust cyber-security work force capable of protecting national infrastructure while reducing dependence on foreign systems. At the same time, Bangladesh must actively support home-grown cyber-security startups and agile innovators who can design solutions tailored to local realities. The global cyber-security market is valued in the hundreds of billions of dollars and there is no structural reason Bangladeshi firms cannot compete within it. Countries such as Singapore, Israel and Malaysia have demonstrated that ecosystem strength, not geographic size, determines success. With the right investments, Bangladesh can position itself as a regional cyber capability hub.

This ambition requires execution through a coordinated national road map focused on education, research, applied training, public-private partnership and sovereign technology development. Such a road map must align closely with national security priorities while ensuring sustained collaboration among key stakeholders.

However, the role of the military, academia and the private sector is central to this effort. Many of the most transformative technologies, including the internet, global positioning system, advanced cryptography and modern communications, originated from defence requirements and later matured through academic research and private-sector innovation. Countries with strong cyber capabilities have institutionalised this tri-sector collaboration. Bangladesh has the foundational elements to pursue a similar model provided these sectors operate with shared intent and long-term vision.

At the same time, regional examples offer important lessons. Pakistan has moved towards centralised cyber governance through the establishment of the National Cyber Crime Investigation Agency, aimed at consolidating cyber crime investigation and strengthening sovereign control over digital security enforcement. Pakistan has also introduced the National Cyber Protection Authority to provide strategic oversight of cyber protection, policy coordination and the safeguarding of critical information infrastructure. Together, these institutions reflect Pakistan’s effort to reduce fragmentation in cyber governance, enhance institutional clarity and assert national ownership over digital security, even as operational and capacity challenges persist.

India, by contrast, has developed a more layered and research-driven ecosystem. Institutions such as CERT-In and the National Critical Information Infrastructure Protection Centre play clearly defined roles in incident response and the protection of critical infrastructure. At the strategic level, India’s Defence Research and Development Organisation has invested for decades in local defence and cyber-related technologies, enabling closer alignment between military requirements, academic research, and industrial innovation. This long-term emphasis on domestic research and development has significantly reduced reliance on external systems and strengthened India’s sovereign cyber and defence capabilities under a coordinated national framework. In today’s interconnected world, no advanced technology is built in isolation. The United States achieved cyber dominance through deep integration between defence institutions, universities and private industry while countries such as Malaysia are now pursuing similar paths. Bangladesh possesses the talent, market demand and institutional base to follow suit if all stakeholders move forward together.

Ultimately, the rise of indigenous cyber innovation is not merely a technological goal, It is a matter of national sovereignty, economic resilience and long-term security. A Bangladesh that builds and controls its own cybersecurity capabilities secures not only its digital infrastructure but also its position in the global digital order. With strategic vision and coordinated action, the country can evolve from a reactive defender into a confident contributor to global cyber security.

Brigadier General Mohammad Shahjahan Majib is dean of the electronic and communication engineering at the Military Institute of Science and Technology; and Shamsad Binte Ehsan is a cyber security specialist at the MIST Cyber Range.​
 

Can Bangladesh defend itself in the great-power cyber war?

Md Mazhar Uddin Bhuiyan

The Global Cybersecurity Outlook 2026 reports that 91% of major organisations have revised their cybersecurity strategies in response to geopolitical instability. It underscores how cyberspace has become a central arena of strategic competition. NATO similarly describes cyberspace as "contested at all times," with adversaries targeting critical infrastructure, public services, and intelligence systems.

Recent incidents reflect this growing trend. The United States accused Chinese groups such as Volt Typhoon and Salt Typhoon of infiltrating key infrastructure networks, while India and Pakistan exchanged cyber operations during their 2025 crisis. Such exchanges persist between Russia and the West as well, alongside reported hacking operatives by Israel in a Tehran CCTV camera to help track Iran's Supreme Leader before the strikes.

German political scientist Thomas Rid famously said that "cyber war will not take place". It means that cyber operations rarely meet the classical test of war. What we actually see, between great powers, is a constant grey-zone contest with four moving parts.

1780451172254.webp

Visual: Star


First, espionage, which means stealing diplomatic cables, defence plans, commercial and scientific secrets. Second, sabotage, which means damaging specific systems, is usually carefully chosen. Third, subversion, which means manipulating information, elections and public opinion. Fourth, pre-positioning, which means quietly burrowing into another country's critical infrastructure so it can be switched off later, in a future crisis. These four dimensions increasingly define the strategic competition among major powers today.

One major change in recent years is the rise of China as a serious offensive cyber power, according to Oxford University Professor Ciaran Martin. The Wall Street Journal has tracked how Chinese hackers have evolved from relatively unsophisticated industrial spies into instruments of military power, with the Typhoon campaigns laying the groundwork for a future conflict in the Pacific over Taiwan. The United States and its allies have responded with sanctions, indictments, and increasingly aggressive defensive operations that rely heavily on private partners such as Microsoft and Cloudflare.

Although the United Nations Convention against Cybercrime was opened for signature in 2025, Bangladesh did not become a signatory. In this uncertain legal and geopolitical environment, Bangladesh finds itself navigating an increasingly complex strategic space between two major regional powers, China and India, the dragon and the elephant.
On the other hand, Russia, despite its mixed performance in Ukraine, continues to run intelligence and information operations against the West. Israel's 2025 operations against Iran showed that cyber tools can support real-world military strikes. India began projecting cyber force across the subcontinent through groups researchers track as SideWinder, Bitter, SloppyLemming and Outrider Tiger.

In such a landscape, the question comes: What is Bangladesh doing?

International law governing cyber warfare remains fragmented and underdeveloped, offering limited protection or strategic recourse to smaller states such as Bangladesh. Although the United Nations Convention against Cybercrime was opened for signature in 2025, Bangladesh did not become a signatory. In this uncertain legal and geopolitical environment, Bangladesh finds itself navigating an increasingly complex strategic space between two major regional powers, China and India, the dragon and the elephant.

According to Mordor Intelligence, Bangladesh's cybersecurity market in 2026 is valued at about USD 250.76 million, expected to increase to USD 503.28 million in 2031. The country has recently gone through one of the sharpest foreign-policy shifts in its history. Beijing recently promised more than US$2 billion in new investments, agreed to build a drone manufacturing plant in Bangladesh, and opened talks to supply J-10CE fighter aircraft.

New Delhi has appeared cautious about this evolving dynamic. In 2025, researchers at Kaspersky identified an espionage campaign known as Mysterious Elephant. The operation, reportedly linked by some analysts to Indian actors, identified Bangladesh as the second most affected jurisdiction after Pakistan. The campaign may have targeted institutions, including the foreign ministry, Bangladeshi diplomatic missions overseas, and several leading policy think tanks.

In March 2026, Arctic Wolf reported on another campaign, SloppyLemming, which was described as possibly India-aligned and reportedly targeted Bangladeshi energy utilities and financial institutions. At the same time, Bangladesh's expanding reliance on Chinese telecommunications infrastructure, digital payment platforms, and surveillance technologies may also draw increased attention from a range of international intelligence actors. But are we ready for any of this? Unfortunately, not really.

Recently, the Cyber Security Act 2023 was replaced by the Cyber Protection Act 2026, which established a National Cyber Security Agency. The new law primarily addresses cybercrime and online speech. The National Cyber Security Agency (NCSA) is set to implement a project titled "Strengthening Capacity of National Cyber Security Agency" from July 2026 to June 2029. The plan includes building key infrastructure, such as a National Security Operations Centre (NSOC), a National Computer Emergency Response Team (NCERT), and Network Operations Centres (NOCs), across 35 Critical Information Infrastructure (CII) institutions. But the agency remains understaffed, underfunded, and lacks expertise in cybersecurity.

Bangladesh should adopt a pragmatic cyber doctrine centred on resilience rather than retaliation. For a smaller state, credibility lies in the ability to withstand disruption, recover quickly, and maintain essential services during crises, not in retaliation.

However, the financial sector is at least making progress. The 2016 Bangladesh Bank heist exposed the country's cyber vulnerabilities in dramatic fashion. In response to growing digital threats, the Bangladesh Bank issued its Cyber Security Framework 2026 on 29 March 2026. All banks, finance companies, and payment operators must comply with the framework by 31 December 2026. It mandates the appointment of a Chief Information Security Officer at every institution and requires incidents to be reported to both Bangladesh Bank and the BGD e-GOV CIRT within 72 hours. However, the framework primarily covers the banking sector. Power grids, telecom networks, ports, hospitals, the election database, and submarine cables still operate under a patchwork of outdated regulations.

Now, what should Bangladesh do? I recommend five things, in order of urgency.

First, Bangladesh should adopt a pragmatic cyber doctrine centred on resilience rather than retaliation. For a smaller state, credibility lies in the ability to withstand disruption, recover quickly, and maintain essential services during crises, not in retaliation.

Second, the government should build working relations with the private tech companies and international partners. Recent experiences in Ukraine, in particular, have shown the importance of coordinated support from technology firms and allied governments.

Third, Bangladesh must regulate critical infrastructure as a whole, not in fragments. Banking is important, but it is only one part of the national cyber picture. Power grids, submarine cables, mobile financial service switches, voter databases, ports, hospitals, and telecom networks should all fall under a single mandatory framework. That framework should include regular audits and real enforcement powers. Often, a partial regime leaves dangerous gaps.

Fourth, just as we balance our diplomacy, we should also balance our cyber partnerships. We should work with American, European, Chinese, Indian and other partners on defensive matters such as threat intelligence, incident response, training, and joint exercises. But it should negotiate from a position of caution. The country should seek help in securing systems, not dependence on foreign surveillance platforms or offensive tools.

1780451250861.webp

Visual: Zarif Faiaz

Fifth, Bangladesh must invest in people. Cyber resilience will depend on the recruitment and retention of talent. That means creating university programmes in cybersecurity and digital forensics, offering scholarships, improving salaries in government cyber units, and building clear public-sector career paths for skilled professionals. Bangladesh should also create a national cyber reserve of trained experts who can be mobilised during emergencies.

In conclusion, Bangladesh does not need to hack back. It needs a strategic cybersecurity policy and the honesty to acknowledge that Bangladesh is a small state in a contest among giants. But that does not mean we are helpless; it means we must be realistic. The question is no longer whether Bangladesh will face cyber warfare; we are already in it. The real question is whether our next national cyber strategy will prepare us for the war we like to imagine or for the one we are already fighting.

Md Mazhar Uddin Bhuiyan is an Oxford-Felix scholar and Master of Public Policy candidate at the University of Oxford.​
 

Latest Posts

Back