BD Exports $48.2B +8.7% YoY RMG $40.6B +7.2% BGMEA Members 4,275 Top Destination USA $9.1B Jute $1.2B Leather $950M +12.4% Pharma $180M +18.2% Japan EPA Active Feb 2026 EU EBA Duty-Free HS Codes 7,498 BD Exports $48.2B +8.7% YoY RMG $40.6B +7.2% BGMEA Members 4,275 Top Destination USA $9.1B Jute $1.2B Leather $950M +12.4% Pharma $180M +18.2% Japan EPA Active Feb 2026 EU EBA Duty-Free HS Codes 7,498
English | USD $

Bangladesh Draft Cyber Security Strategy Shifts Focus to AI Threats

National Cyber Security Agency with ICT Division unveils 5-year roadmap; 20,000-strong cyber security workforce target; critical digital infrastructure protection; AI-driven threats focus

By AI News Desk, BangladeshExport August 5, 2026 at 6:02 PM 7 min read
Bangladesh draft cyber security strategy document showing shift to AI threats focus with 5-year roadmap and 20000 workforce target
📷 Image: The Daily Star

Dhaka, August 6, 2026 — Bangladesh has unveiled the draft of its new National Cyber Security Strategy, shifting focus to emerging threats from artificial intelligence (AI), quantum computing and next-generation networks — in a comprehensive five-year roadmap that aims to protect the country's rapidly expanding digital ecosystem, build a 20,000-strong cyber security workforce and elevate Bangladesh into the world's top 20 cyber-security-ready nations by 2030.

🏛️ A New Approach for a New Threat Landscape

The draft takes a different approach from the previous five-year strategy as cyber threats become more sophisticated and the country becomes increasingly dependent on digital services. Prepared by the National Cyber Security Agency with the ICT Division, the draft was unveiled at a programme in Dhaka recently. It sets out a five-year roadmap to protect critical digital infrastructure, build a 20,000-strong cyber security workforce and update cyber security laws and institutions to keep pace with rapidly changing technologies.

🤖 For the First Time: AI, Cloud, 5G/6G, Quantum

For the first time, the strategy elaborated plans to secure technologies such as AI, cloud computing, the Internet of Things (IoT), 5G and 6G networks, blockchain and post-quantum cryptography. The draft also cited "harvest now, decrypt later" attacks, in which encrypted data stolen today could one day be decrypted using powerful quantum computers — a forward-looking recognition that today's encrypted national security communications may be retroactively exposed a decade from now.

The strategy replaces the previous National Cyber Security Strategy for 2021–2025 and is built around six strategic pillars and 11 priorities. ICT Division officials said it will be revised following consultations with government agencies, industry representatives and academics before being finalised — signalling that the current draft is open for stakeholder input before formal cabinet approval.

📊 The Scale of Bangladesh's Digital Exposure

The draft says the country's digital ecosystem has expanded rapidly, with around 120 million internet users and 190 million mobile subscribers now generating millions of mobile financial transactions every day. This rapid growth has significantly widened the country's exposure to cyber attacks — a vulnerability that has grown in parallel with the country's ambitions to become a Digital Bangladesh and, eventually, a Smart Bangladesh by 2041.

Citing the Bangladesh Cyber Threat Landscape 2024 report, the draft says government platforms recorded the highest number of reported cyber incidents last year, with 63 cases. The financial and education sectors followed with 34 incidents each. Data breaches and leaks were the most common type of attack, accounting for 59 reported incidents, followed by website defacement and compromised user credentials.

🕸️ Dark Web Trade in Bangladeshi Data

The draft also points to a growing volume of Bangladeshi data being traded on dark web marketplaces. Email addresses made up the largest share of leaked information at 20 percent, followed by full names at 18 percent and phone numbers at 15 percent. Government-issued identity documents, including national identity cards and passports, accounted for another 10 percent — a particularly concerning category given the potential for identity fraud and synthetic identity construction.

  • 📧 Email addresses leaked: 20% of dark web Bangladeshi data
  • 👤 Full names: 18%
  • 📞 Phone numbers: 15%
  • 🆔 NID/passport documents: 10%
  • 🏢 Government sector incidents (2024): 63 cases (highest)
  • 💰 Financial sector incidents: 34 cases
  • 📚 Education sector incidents: 34 cases
  • 📈 Data breaches/leaks (most common): 59 reported incidents

🌏 Bangladesh's Global Cyber Security Standing

The draft also highlights the country's standing on global cyber security benchmarks. As of January 2025, the draft says the country ranked 64th in the National Cyber Security Index (NCSI) with a score of 66.67. It was also placed in the "role-modelling" tier of the International Telecommunication Union's Global Cyber Security Index 2024, although it scored comparatively lower on legal measures — a gap the new strategy is explicitly designed to close.

🏛️ The Six Strategic Pillars

The strategy is built around six pillars:

  1. 🏢 Protecting critical infrastructure — comprehensive review of the country's list of critical information infrastructure (CII), adoption of international standards, with particular attention to small and medium-sized enterprises (SMEs) that often serve as entry points into larger networks.
  2. 🛡️ Creating a resilient cyber ecosystem — making key institutions fully operational, including the National Cyber Security Agency, a National Security Operations Centre, a National Computer Emergency Response Team (CERT) and a Cyber Crisis Management Centre.
  3. 👥 Developing the cyber security workforce and industry — target of 20,000 cybersecurity professionals by 2030, with at least 30 percent women's participation.
  4. 👨‍⚕️ Strengthening citizen protection and digital trust — 24-hour national cybercrime helpline and a citizen-facing National Cyber Security Center.
  5. 🤖 Securing emerging technologies — AI, cloud, IoT, 5G/6G, blockchain, post-quantum cryptography.
  6. 🌏 Expanding international cooperation and cyber diplomacy — bilateral and multilateral agreements, joint exercises, cross-border cooperation to combat cyber crime.

The draft sets a target of securing at least $10 million in annual funding for the national agency — a baseline that, while modest by international standards, represents a meaningful increase from current operational budgets and should enable the agency to staff up its core functions.

⚠️ Implementation Setbacks Identified

The draft also identifies several setbacks that could slow implementation. These include a shortage of specialised cyber security professionals, weak collaboration between industry, academia and government on research commercialisation, poor cyber security practices among small and medium-sized businesses that could serve as entry points into larger networks, and continued reliance on outdated protocols such as SMB and Telnet in some systems — a legacy issue that leaves critical systems exposed to well-known exploits.

🎯 The 2030 Targets

The draft sets several national targets for 2030:

  • 🏆 Top 20 globally in both NCSI and ITU Global Cyber Security Index
  • 📋 Risk assessments completed for all critical information infrastructure entities
  • 👥 50 million people reached through cyber security awareness programmes
  • 👩‍💻 20,000 cyber security professionals trained, with 30% women
  • 💰 $10 million annual funding secured for national agency

🌏 Implications for Bangladesh's Export Economy

The new cyber security strategy has direct implications for Bangladesh's export economy — particularly the IT and IT-enabled services (IT-ITES) sector, which has been growing at double-digit rates and which depends on international trust in Bangladesh's data protection standards. Stronger cyber security credentials would enable Bangladeshi IT firms to bid for higher-value contracts in the EU and US markets, where GDPR and CCPA compliance are increasingly mandatory. It would also strengthen the position of the country's growing fintech sector — including mobile financial services providers like bKash and Nagad — in attracting foreign investment and partnerships. For the ready-made garment sector, stronger cyber security reduces the risk of supply-chain attacks that could compromise buyer data and intellectual property — a growing concern for Western apparel brands that have been targeted by ransomware groups in recent years.

What Comes Next

According to the draft, the National Cyber Security Agency will establish baseline values for all performance indicators within a year of the strategy being approved. It will also publish annual progress reports, while a mid-term review is scheduled for 2028 — providing two formal checkpoints to assess whether the strategy is on track. The immediate next steps will be the consultation process with stakeholders, the incorporation of feedback into a final draft, and submission to the cabinet for formal approval — a process that is expected to be completed by the end of 2026.

📡 News Courtesy

This news was originally published by The Daily Star. For the full original report, please visit: https://www.thedailystar.net/business/economy/news/draft-cyber-security-strategy-shifts-focus-ai-threats-4241796

📬 Get Bangladesh Trade News in your inbox

Weekly digest of export industry news, policy updates, and market analysis.