Bangladesh Bank has introduced a 2026 cybersecurity framework setting baseline security requirements for banks and payment providers across the country's financial sector, covering incident response procedures, third-party vendor risk and ongoing system monitoring. The framework arrives as digital banking and mobile financial services continue expanding rapidly across Bangladesh, a market where mobile money platforms have brought tens of millions of previously unbanked citizens into the formal financial system over the past decade.

The regulator's decision to impose standardised minimums, rather than leaving security investment to individual institutions' discretion, reflects a problem playing out across South Asia's banking sector more broadly: digital payment volumes have been growing faster than many banks' security budgets, leaving smaller and mid-sized institutions in particular under-resourced relative to the attack surface their growing digital services create. A framework that sets a common floor closes at least part of that gap by removing the option for any single institution to treat cybersecurity as optional or aspirational.

For Bangladesh's payment providers, many of which operate on thin margins built around high transaction volumes rather than high per-transaction fees, meeting the new baseline will mean real new compliance costs layered on top of an already competitive market. Bangladesh Bank's bet is that the cost of mandated minimum security standards is smaller than the cost of a major breach at one of the mobile financial platforms that now underpin day-to-day commerce for a large share of the country's population.

AdvertisementIn-Article