Cybercrime has emerged as one of the most significant issues of this current era, and most honest evaluations show that we are still losing momentum. Global cybercrime expenses are expected to increase from US $ 11 trillion by 2027 to $ 12.2 trillion by 2031, according to Cybersecurity Ventures. That is more than a figure that economists can argue over. The result of cybercrimes could have a great negative impact on the financial aspect or losses, downfall in businesses, critical infrastructure of a Nation getting disrupted and people becoming victims of identity theft.
The first, and often most overlooked, difficulty, is the extreme advanced techniques of contemporary hackers. The days of a lone hacker in a dark room posing the most threat are long gone. These days, we have to deal with organised cybercrime groups that use the resources and discipline of tiny businesses. Within days of a single vulnerability being exploited, the DarkSide ransomware group was responsible for the 2021 US Colonial Pipeline attack, which disrupted fuel supplies throughout the Eastern seaboard and demanded a ransom payment of roughly $ 4.4 million. The realisation that even countries with extremely strong cyber defence capabilities can be taken by surprise, highlights the enormous challenge that smaller Nations must face in building effective cybersecurity governance structures and frameworks.
Then, there is the difficult question of jurisdiction. Despite the fact that cybercrime has no geographical boundaries, most legal systems are still designed to operate within national borders. This approach ensures accountability, protects people's rights, and respects each country's sovereignty. However, the biggest challenge is that there are no fast and effective legal mechanisms for countries to work together when cybercriminals operate across multiple jurisdictions. As a result, investigating, prosecuting, and holding offenders accountable become much more difficult. It is possible for a phishing scheme that targets bank customers in Sri Lanka to be developed in Eastern Europe, hosted on servers in South-East Asia, and funded via cryptocurrency wallets that are registered in offshore jurisdictions. In recent times, Sri Lanka has been more exposed to cyber-attacks. Incidents such as the sovereign debt repayment of $ 2.5 million to Australia, which was due in September of last year (2025), and which was diverted through electronic mail-based payment instructions from the computer system of Sri Lanka’s Finance Ministry, was identified only in January of this year (2026). In addition to this incident, the criminal hackers were able to manipulate the payment instructions of business emails, to transfer a further $ 625,000 which was a due payment to the US Postal Services to an unknown bank account. This was suspected by the authorities as a coordinated series of business email compromise.
The offenders have long since moved on by the time the detectives figure out who did what and where. Sri Lanka became the first country in South Asia to join the Budapest Convention on Cybercrime in 2015, marking an important step towards strengthening its legal framework for tackling cybercrime and improving international cooperation. However, despite this commitment, responding quickly to cybercrimes that cross national borders remains a challenge due to differences in legal systems and investigative procedures. Cyberattacks can be carried out within seconds, but, investigating them often takes much longer. When attacks involve multiple countries, law enforcement agencies must work across different legal systems and procedures. Limited resources, delays in sharing digital evidence, and slow international cooperation can all make it difficult to identify offenders and bring them to justice.
People are often described as the weakest link in cybersecurity. However, many security incidents are not simply the result of human error. Poor system design, complex security controls, and inadequate organisational practices can make it difficult for users to follow secure behaviours. As a result, organisations should focus not only on changing user behaviour but also on creating systems and processes that make secure actions easier and more intuitive. Firewalls, encryption, and intrusion detection systems are examples of technical defences that are only as effective as their users. Over 95 per cent of cybersecurity incidents are caused by human error due to unawareness on the types of cyber breaches, according to International Business Machines Corporation research.
Deep fake videos
The actual access points that fraudsters take advantage of include a single employee clicking on a phishing email which is very convincing to a person without proper cyber awareness, a system administrator reusing a password, having a weak guessable password, or a business not deploying a crucial software patch. This problem will only get worse as social engineering techniques become more convincing, especially when artificial intelligence makes it possible to create highly customised scam messaging and deep fake videos and sounds.
All of this is made worse by the imbalance of resources. Cybercriminals have no overhead, so, they are able to rapidly modify when one strategy does not work and carry on attacks at a low cost. Defenders, on the other hand, have to guard every potential port of entry, staff security operation centres around the clock, and constantly retrain their employees in a setting where skills become outdated nearly as rapidly as they are learned. There is a well-established lack of cybersecurity experts, particularly in poorer Nations. There were around 63% unfilled cybersecurity roles with necessary skills worldwide in 2025, where, despite increased awareness of the issue, this number has hardly changed during the past years. Businesses and Governments in Nations like Sri Lanka must make significant and immediate investments to develop talent domestically rather than just importing it.
Increased digitalisation
The fast expansion of digital services adds another level of complexity. The Covid-19 pandemic increased digitalisation in ways that organisations were unprepared for. Remote employment, internet banking, tele-medicine, and e-government all increased the attack surface significantly. The internet of things has increased vulnerabilities, where smart gadgets in homes, hospitals, and industries frequently use legacy software and lack fundamental security safeguards. As mobile internet use in Sri Lanka has increased and more people use digital financial services, the number of potential victims and ways for attacks have grown too.
None of this shows that the war is lost. However, it does mean that partial solutions will not be sufficient. Preventing cybercrime in today's world demands a true, long-term consistent commitment concurrently on many different fields. Legislation must be modernised; while the Computer Crimes Act No. 24 of 2007 established Sri Lanka's legal foundation for combating cybercrime, the evolving nature and increasing complexity of cyber threats have highlighted the need for a more comprehensive legal framework. To address these challenges, the Government has proposed a Cyber Security Bill, which aims to strengthen national cybersecurity governance and improve the protection of critical information infrastructure. However, as the legislation is still under consideration, its effectiveness will ultimately depend on its enactment, implementation, and enforcement. Investment in a national cyber incident response mechanism should be taken as seriously as investment in physical security infrastructure. Public awareness campaigns must extend beyond annual news releases to include ongoing digital literacy programs in schools, Government departments, businesses, and communities. Strengthening cross-border collaboration is essential for addressing the increasingly global nature of cybercrime. While effective international cooperation between law enforcement agencies remains critical, the Personal Data Protection Act No. 9 of 2022 provides an important legal foundation by regulating cross-border transfers of personal data and requiring appropriate safeguards to protect individuals' rights. Although the Act supports secure and accountable international data flows, it should be viewed as one component of a broader cybersecurity framework rather than a complete solution to the challenges of cross-border cybercrime investigations.
Adopting a proactive approach
Looking ahead, Sri Lanka must adopt a proactive and resilience-driven approach to cybersecurity rather than relying primarily on reactive responses after incidents occur. This requires stronger collaboration between Government agencies, law enforcement, the private sector, the academia, and international partners to share threat intelligence, strengthen cyber incident response capabilities, and build a skilled cybersecurity workforce. At the same time, organisations should embrace a security-by-design culture by integrating cybersecurity into the planning, development, and operation of digital services instead of treating it as an afterthought. Continuous public awareness initiatives, regular cybersecurity training, and sustained investment in modern security technologies will also be essential. By combining effective governance, skilled professionals, secure technologies, and international cooperation, Sri Lanka can build a more resilient digital ecosystem that is better prepared to prevent, withstand, and recover from future cyber threats.
Cybercrime cannot be tackled by a single law, agency, or technology. It is a moving target that requires flexible, well-resourced, and collaborative responses. The invisible conflict is already beginning. The real challenge is whether we have the political commitment and institutional strength to take these risks seriously, or will have to continue responding to crises only after they occur instead of preparing for them in advance.
The writer is a cyber security consultant
----------------------------
The views and opinions expressed in this column are those of the writer, and do not necessarily reflect those of this publication