header logo
Asia asset finance
Mogo Academy
Latest
Expert raises concerns over Finance Ministry’s cybersecurity measures after BEC attack
Apr 25, 202610:15 AM
Expert raises concerns over Finance Ministry’s cybersecurity measures after BEC attack

Cybersecurity expert Asela Waidyalankara states that technical measures are available to prevent incidents such as hackers gaining access to funds, as seen in the reported cyberattack involving a USD 2.5 million Treasury payment.

 

He explained that the cyberattack method used in the incident is known as Business Email Compromise (BEC), a tactic that has affected many private sector institutions.

 

However, Waidyalankara pointed out that because the Central Bank of Sri Lanka (CBSL) has recommended that the domestic banking system obtain ISO 27001—the international standard for Information Security Management Systems—cyberattacks against banks have been minimized.

 

According to him, if an institution such as the Treasury, which bears greater responsibility for the country’s funds than a bank, had implemented similar control mechanisms, the impact of such incidents could have been minimized.

 

Further elaborating, he stated that BEC cyberattacks typically involve intercepting invoices sent by one organization, altering the details, and redirecting payments to fraudulent accounts.

 

Cybersecurity expert Asela Waidyalankara further stated:

 

“The Business Email Compromise (BEC) method was utilized in this cyberattack. This is a common occurrence in the private sector. For example, when an invoice is sent from one organization to another, hackers may intercept it, alter the account details, and redirect the payment to a different account. The concern here is that this involved a financial transaction within a branch of the country’s Ministry of Finance.”

 

He stated that technical tools are available to mitigate such risks and noted that it must be examined whether these measures were properly utilized, whether email systems were up to date, and whether they had been adequately patched. He further observed that there appear to be structural issues within the institution regarding the management and oversight of cybersecurity.

 

“The Central Bank has mandated that Sri Lankan banks obtain ISO 27001 certification, which requires annual external audits. The absence of such standards in an institution like the Ministry of Finance, where national funds are handled, represents a significant shortcoming. While ISO 27001 does not guarantee immunity from cyberattacks, it provides a framework to minimize such risks,” he said.

 

He further added, “Banks are not routinely compromised because they adhere to stringent cybersecurity standards and processes. Given that the General Treasury handles national wealth on a scale greater than that of a typical bank, implementing comparable controls could have potentially prevented this situation.”
 

 

 

 

RelatedNews
MostRead
Mobitel 5g
VideoStories
Special Dengue Prevention Week in Colombo from June 15 to 21

Special Dengue Prevention Week in Colombo from June 15 to 21

“New corruption cases stalled by CIABOC” Joint Opp. seeks meeting with Chairman to raise concerns

“New corruption cases stalled by CIABOC” Joint Opp. seeks meeting with Chairman to raise concerns

Sri Lanka bans export of mineral resources without value addition

Sri Lanka bans export of mineral resources without value addition

Over 39,000 dengue cases reported islandwide; health officials warn of hospital capacity pressure

Over 39,000 dengue cases reported islandwide; health officials warn of hospital capacity pressure

Court declines request for daily access to detained ex-SIS Director Suresh Sallay

Court declines request for daily access to detained ex-SIS Director Suresh Sallay

Colombo HC dismisses Shashi Weerawansa’s appeal over passport case

Colombo HC dismisses Shashi Weerawansa’s appeal over passport case

Satyagraha staged against Suresh Sallay’s detention temporarily suspended after court decision

Satyagraha staged against Suresh Sallay’s detention temporarily suspended after court decision

Court appoints five-member special medical panel to examine Suresh Sallay’s health condition

Court appoints five-member special medical panel to examine Suresh Sallay’s health condition

Opposition calls for fair investigation into Easter attacks and Suresh Sallay

Opposition calls for fair investigation into Easter attacks and Suresh Sallay

Cabinet Spokesman rejects accusations, says Suresh Sallay treated like any other detainee (English)

Cabinet Spokesman rejects accusations, says Suresh Sallay treated like any other detainee (English)

Minister claims funds transferred to foreign companies via ‘TT’ payment method, posing as importers

Minister claims funds transferred to foreign companies via ‘TT’ payment method, posing as importers

Suresh Sallay continues hunger strike; UNP calls for parliamentary review of treatment (English)

Suresh Sallay continues hunger strike; UNP calls for parliamentary review of treatment (English)

“Executive undermining judicial independence” Sajith says public trust on government is eroding

“Executive undermining judicial independence” Sajith says public trust on government is eroding

“Family & legal intervention made hospitalization possible”Suresh Sallay remains under hospital care

“Family & legal intervention made hospitalization possible”Suresh Sallay remains under hospital care

Satyagraha campaigned launched at Colombo Fort in support of Suresh Sallay who is detrained by CID

Satyagraha campaigned launched at Colombo Fort in support of Suresh Sallay who is detrained by CID

Lassana Flora