brand logo
Cyber Security Bill nears final stage

Cyber Security Bill nears final stage

16 Aug 2026 | By Methmalie Dissanayake



  • Gazette expected within a month

Sri Lanka’s long-awaited Cyber Security Bill has entered its final drafting stages, with a gazette expected within a month, according to Ministry of Digital Economy Secretary Waruna Sri Dhanapala.

Speaking to The Sunday Morning, Dhanapala said that the drafting team had completed 90% of the work, with the remaining focus centred on finalising the operational framework and determining the precise structure of the proposed cyber security regulatory authority. 

He stated that this included critical planning for implementation, as well as staffing required to make the authority functional. The legislative process, he added, was likely to be ready for the next stage of approval in one month.

Sri Lanka Computer Emergency Readiness Team (Sri Lanka CERT) Acting CEO Dr. Kanishka Karunasena confirmed to The Sunday Morning that the bill was currently with the Legal Draftsman for final adjustments. 

“All the comments from our side have been given. Once the remaining minor amendments were integrated, the document would be forwarded to the Attorney General’s Department, he said. 

A primary objective of the new legislation is to provide a statutory foundation for cybersecurity efforts in the country. Dr. Karunasena explained that while Sri Lanka CERT was currently operating, it lacked a formal legal mandate to enforce its directives, with operations largely based on guidelines rather than binding authority.

“Sri Lanka CERT doesn’t have a formal mandate,” he said, adding that once the act was passed, it would grant the institution the legal mandate and powers to work with greater independence, including the authority to conduct mandatory assessments and issue binding instructions. 

The bill also seeks to address what Dr. Karunasena described as a major gap in the country’s digital defences – the absence of a central authority to oversee State agencies. “There is no institution in Sri Lanka to tell Government institutions what specific cybersecurity measures must be taken,” he said. 

The proposed cyber security regulatory authority is intended to fill this void by setting mandatory standards, with the power to mandate Government institutions to follow specific protocols and ensure State agencies comply with national security requirements.

Cabinet approval was granted in April for the establishment of the national cyber security regulatory authority, a move officials say is intended to significantly strengthen the sector compared to its current state.

At present, cybersecurity oversight falls under Sri Lanka CERT, which provides guidelines to safeguard against cyberattacks and responds when entities face such threats, but has no enforcement powers. 

“That organisation cannot enforce cybersecurity implementations across digital platforms. Therefore, there must be a regulatory body to publish enforcement and compliance requirements, and to enforce the application of those measures in all critical infrastructure, both public and private. To establish this regulatory body, we must have a proper legal framework, which is what the Cyber Security Bill aims to achieve,” Deputy Minister of Digital Economy Eranga Weeraratne told The Sunday Morning on a previous occasion.

The push for legislation comes against a backdrop of rapid digitalisation and a rising incidence of cyberattacks. 

According to the Telecommunications Regulatory Commission of Sri Lanka (TRCSL), over 65% of Sri Lankans used social media in 2024 and nearly a third used digital payments. 

The Government’s digital transformation drive aims to accelerate economic growth by expanding digital public infrastructure and increasing the volume of sensitive data exchanged online – with digital systems now embedded across critical national infrastructure including energy, transport, healthcare, and telecommunications, meaning cyber incidents now carry potential population-scale consequences.

The threat is not unique to Sri Lanka. The Asia-Pacific region accounts for over a third of global cyber incidents, and the average cost of a data breach globally exceeds $ 4 million. Locally, the Sri Lanka CERT Coordination Centre has reported a sharp rise in incidents, from 596 in 2019 to 4,347 in 2024, driven primarily by scams, phishing, data breaches, and ransomware. 




More News..