Sri Lanka’s next cybersecurity strategy should assume the hacker gets in

For decades, cybersecurity has been built around a simple objective: keep the attacker out.

Build stronger firewalls. Improve passwords. Add multifactor authentication. Monitor networks. Detect intrusions faster.

All are necessary. But the digital economy is reaching a point where they are no longer sufficient.

A recent case in Europe illustrates why. Financial Times reporting revealed that sensitive customer information held by fintech Revolut was obtained by criminals who allegedly compromised an official Italian government communications channel and impersonated law-enforcement authorities.

The striking point is that Revolut says its own systems and databases were not breached.

The attackers did not need to break through the front door. They persuaded someone with legitimate access to open it.

For Sri Lanka, this should be an important warning.

Digital transformation

The country is embarking on an ambitious digital transformation involving digital identity, digital payments, data exchange, online government services and increasing use of artificial intelligence. The more successful that transformation becomes, the more valuable Sri Lanka’s digital infrastructure becomes to criminals.

Sri Lanka CERT’s National Cyber Security Strategy records 21,743 cyber and social-media incidents reported in 2024. Financial scams accounted for 2,241 reported cyber incidents, alongside phishing, ransomware and data breaches.

The conventional response is to spend more on defending databases.

There is another question we should ask: why are we creating so many repositories of valuable, readable data in the first place?

A database containing millions of identity records is valuable because the information inside can be read, copied and reused. The same applies to financial records, medical information, land records, corporate documents and government data.

Encryption protects much of this information while stored or transmitted. But authorised systems and users eventually need access to it.

That creates a fundamental weakness.

Artificial intelligence

An attacker does not always need to defeat the encryption. Sometimes it is easier to compromise the person, application, credential or trusted institution authorised to access the information. Artificial intelligence makes the problem more serious. AI can strengthen cyber defence, but it can also automate reconnaissance, create convincing impersonations and allow attackers to operate at a scale previously requiring significant resources.

Cybersecurity architecture therefore needs to evolve from simply preventing access towards minimising what successful access can reveal.

Imagine a different model.

Instead of storing a complete sensitive document in one location, information can be cryptographically protected and distributed so compromising one repository does not deliver a usable prize.

Instead of sending an entire identity document whenever a fact must be established, cryptographic proofs can confirm the required fact without exposing all the underlying information.

Instead of trusting a request because it arrived through an authorised channel, important transactions can require independently verifiable proof of authority. And instead of security ending once somebody successfully logs in, sensitive actions can become an auditable chain of cryptographically verifiable events.

The principle is straightforward:

Assume someone eventually gets through. Design the data so that getting through is not enough.

This is particularly important for Sri Lanka because much of the country’s digital infrastructure is still being built.

Developed economies carry enormous amounts of legacy technology and decades of accumulated databases. Replacing them is extraordinarily difficult.

Sri Lanka has the opportunity to avoid creating some of those problems in the first place. Emerging digital identity, data-exchange and government-service infrastructure should therefore minimise centralised concentrations of sensitive information; disclose only information required for a transaction; separate verification from possession of the underlying data; make critical actions independently verifiable; and design recovery from compromise into the architecture from the beginning.

This does not mean abandoning conventional cybersecurity. Firewalls, endpoint protection, identity management, monitoring and incident response remain essential.

It means recognising their limitation.

No organisation can credibly promise that an employee will never be deceived, credentials will never be compromised, software will never contain a vulnerability or an attacker will never penetrate a network.

A modern national cybersecurity

A modern national cybersecurity architecture should therefore be judged not only by whether attackers can enter it, but by what an attacker receives if they succeed. That question becomes even more important as Sri Lanka’s core Personal Data Protection Act compliance regime approaches commencement in January 2027. Protecting personal information should not simply mean imposing stronger obligations on organisations after they collect it. Technology can reduce how much sensitive information organisations need to possess and expose in the first place. Sri Lanka does not need to reproduce the digital architecture of countries that digitised 20 years earlier and then spend the next twenty years repairing its weaknesses.

It can build differently.

As Sri Lanka constructs the foundations of its digital economy, cybersecurity should no longer begin with the assumption that every wall will hold forever.

Build the walls. But build the data architecture on the assumption that one day, somewhere, one of them will fail.

Contracts on the rocks: Cabo Verde’s quiet reckoning with the rule of law

Cabo Verde has long stood out among African states for its political stability, but recent developments raise a different question for investors: how predictable is the state as a contractual counterparty? Cabo Verde, an archipelago of about half a million people off the coast of Senegal, has changed government peacefully since multiparty rule began in 1991. It has done so again this year. In parliamentary elections on May 17th the African Party for the Independence of Cabo Verde (PAICV) defeated the Movement for Democracy (MpD), which had governed for a decade. Francisco Carvalho, the PAICV’s leader and until then mayor of Praia, the capital, was sworn in as prime minister on June 19th. The final count gave his party

US-Based Ghanaian Lecturer’s Wife Grabbed Over His Murder

Betty Akamani, a 35-year-old woman, has been charged with the murder of her US-based Ghanaian husband, Dr. Kofi Akamani, a Southern Illinois University professor.

The mother of two was charged on Monday, September 21 with two counts of felony first-degree murder and one count of endangering the life or health of a child.

Betty Akamani is accused of shooting her husband, 48-year-old Dr. Kofi Akamani multiple times while he sat in his car in her driveway at her Murphysboro home.

He later died at a Carbondale hospital.

According to court records and the Jackson County State’s Attorney’s Office, the couple had been separated for two years, and were in the middle of a divorce.

In court on Monday, Betty Akamani was denied release. She will remain in the Jackson County Jail.

She is set to appear in court again on October 6 for a preliminary hearing.

According to the Jackson County Sheriff’s Office (JCSO), deputies were called to a reported shooting around 5 p.m. on Saturday, September 19.

The 48-year-old academic was found with gunshot wounds and was rushed to the Memorial Hospital of Carbondale, where he was pronounced dead.

Police say investigations have commenced but are still in the early stages.

The Jackson County Ambulance Service, the Coroner’s Office, and the State’s Attorney’s Office are assisting with the probe.

The Sheriff’s Office added that no further details would be released for now as investigations continue.

Dr. Akamani began his tertiary education in Ghana at the Kwame Nkrumah University of Science and Technology (KNUST) in Kumasi, where he earned a Bachelor of Science degree in Development Planning, specialising in Urban Planning.

He initially intended to pursue further studies in Urban Planning but was advised that the future of planning lay in sustainable development.

Jeff Harmon, chief communications and marketing officer at SIU, said, ‘It is with a heavy heart that we have learned of the tragic passing of one of our faculty members, Dr. Kofi Akamani. Our deepest condolences go out to his family, friends, colleagues, and students during this difficult time.’

According to a Facebook post by the Southern Illinois University, a vigil is scheduled today at 6 p.m. at the Ag building front lawn. They say a memorial will follow at a later date.

Trincomalee Beach Resort and Spa enters into management deal with Fairway Holdings

Trincomalee Beach Resort and Spa Ltd., owned by Platinum Group of Companies Chairman Kumar Jeyakumaran has announced the signing of a long-term Hotel Management Agreement with Fairway Holdings, under the leadership of its Chairman Virath de Alwis.

The landmark partnership marks a significant milestone in the evolution of one of Trincomalee’s premier beachfront hospitality destinations and reflects a shared vision to position the property among Sri Lanka’s leading coastal resorts.

The strategic collaboration is expected to transform the resort into a world-class destination, offering exceptional guest experiences while strengthening Trincomalee’s position as one of Sri Lanka’s fastest-growing tourism destinations

Kumar Jeyakumaran said: ‘This partnership represents far more than a management agreement. It is a commitment to the future of Trincomalee’s tourism industry By joining hands with Fairway Holdings, we are combining local vision with internationally recognised hospitality expertise to create a destination that will set new benchmarks in service excellence, guest satisfaction, and sustainable tourism. We firmly believe this collaboration will bring significant economic benefits to the Eastern Province while creating employment opportunities and encouraging further investment into the region.’

Under Fairway Holdings’ management, guests can expect: International hospitality standards and service excellence; Enhanced accommodation, dining, and leisure experiences; Improved guest facilities and modern resort amenities; Professional hotel management systems and operational excellence; Stronger international and domestic marketing initiatives; New tourism experiences designed to attract both leisure and business travelers and Sustainable tourism practices that support the local community and environment.

The partnership also reflects the confidence of both organisations in the long-term growth potential of Trincomalee. With increasing tourist arrivals, expanding infrastructure, and growing international interest in Sri Lanka’s East Coast, the investment represents an important step towards making Trincomalee a premier tourism and investment destination in South Asia.

The management agreement is also expected to generate positive value for investors and stakeholders by enhancing the resort’s commercial performance, strengthening its market positioning, increasing occupancy, and improving long-term asset value through professional management and strategic brand Development.

As Fairway Trinco, the resort will become a flagship destination that combines the natural beauty of Trincomalee with the trusted hospitality standards synonymous with the Fairway brand.

Both Platinum Group of Companies and Fairway Holdings extended their sincere appreciation to their shareholders, business partners, government institutions, tourism stakeholders, employees, and the people of Trincomalee for their continued confidence and support throughout this exciting journey.

Together, both organisations look forward to welcoming guests from around the world to experience a new era of hospitality.

President: Cyprus to soon sign Convention supporting global ocean observation

Cyprus will very soon proceed with the signing of the Convention that will support the global ocean observation system, President of the Republic of Cyprus Nikos Christodoulides said on Wednesday, while welcoming the launch of the OceanEye Alliance.

In his intervention, President Christodoulides said that, ‘as an island nation in the Mediterranean Sea, Cyprus understands very well the vital connection between our ocean’s health and our people’s well-being, security, resilience and prosperity.’

He warmly welcomed the launch of the OceanEye Alliance and commended its leadership, stressing that ‘the Alliance represents a very important step towards securing reliable and sustained global ocean observation.’

‘In this context, I’m pleased to inform you that Cyprus will very soon proceed with the signing of the Convention which will support the global ocean observation system,’ the President said.

At the same time, he noted that Cyprus stands ready to contribute through its national scientific, research and technical capacities, as well as through enhanced cooperation and data sharing.

‘The ocean is one, vast, interconnected and essential to life on Earth,’ President Christodoulides said, adding that ‘Cyprus stands ready to lead regionally, collaborate globally and champion a resilient, healthy ocean for all of us.’

You can’t use stolen money for Hajj, Jerusalem and expect God’s acceptance – Sultan

The Sultan of Sokoto, Muhammadu Sa’ad Abubakar, has urged religious leaders in Nigeria to join the fight against corruption, warning that money obtained through corrupt means cannot be used to secure divine blessings.

The Sultan stated this on Wednesday at the 2026 Second Council Meeting of the Nigeria Inter-Religious Council (NIREC), held under the theme, ‘Shared Sacred Flourishing in Nigeria’.

He said religious leaders had a responsibility to condemn corruption and support the Economic and Financial Crimes Commission (EFCC) in its efforts to prosecute individuals involved in financial crimes.

According to him, it was wrong for individuals to steal public or private funds and subsequently use such proceeds to sponsor people to Mecca for Hajj or Jerusalem for religious pilgrimages.

‘God Almighty doesn’t like corruption, he doesn’t love corruption. You cannot steal money and then send people to Jerusalem and Mecca with corrupt money, and then you think God will accept your deeds. No,’ the Sultan said.

He maintained that corrupt proceeds could not become acceptable simply because they were used for religious purposes.

‘God is not corrupt, so he doesn’t like corruption. So you cannot use corrupt money to send people to Jerusalem or to Saudi Arabia for Hajj or for any other thing,’ he added.

The Sultan called on religious leaders to work with EFCC Chairman, Olanipekun Olukoyede, in the fight against corruption, stressing that no individual should be shielded from prosecution because of his or her religious status.

He said pastors, imams, religious leaders, relatives and friends who violated the law should be allowed to face justice.

‘Whoever is involved, even our brothers, our sisters, our fathers, our friends, those involved, should face the law. And law is not a respecter of anybody,’ he said.

The Sultan specifically cautioned against using religious positions as a basis for seeking preferential treatment for individuals facing corruption allegations.

‘When he is facing the law, don’t tell me he is the pastor of a church, he is the chief imam of a mosque. We don’t want to hear that,’ he said.

He urged the EFCC to investigate and prosecute suspects based on the law, irrespective of their religious affiliation or political connections.

‘Let the EFCC Chairman go after that person, whoever it is, and deal with him according to the law,’ the Sultan said.

He further urged the anti-graft agency to remain firm and avoid political interference in the discharge of its responsibilities.

‘And dealing with him according to the law, don’t deviate, don’t listen to politics or political leaders,’ he added.

The Sultan’s remarks came as religious leaders and the EFCC leadership discussed the role of faith institutions in promoting ethical conduct and tackling corruption at the NIREC meeting.

2027 Will Be APC Vs. Nigerians – Makinde

Oyo State Governor and presidential candidate of the Allied Peoples’ Movement (APM), Seyi Makinde, has said the 2027 presidential election will be a contest between the ruling All Progressives Congress (APC) and ordinary Nigerians, rather than between political parties.

Speaking in Katsina on Tuesday during a Northwest town hall meeting organized by his campaign team to present the party’s ‘Reset Nigeria’ agenda, Makinde declared:

‘It would not be APC versus APM, or APM versus APC, or APC versus ADC-it will be APC versus Nigerians.’

Urging citizens to obtain their Permanent Voter Cards (PVCs) and participate actively, Makinde outlined that the ‘Reset Nigeria’ initiative focuses on the economy, education, insecurity, and institutional reforms to build a country that works for all citizens regardless of tribe, religion, or region.

Makinde also used the event to refute claims made by the Minister of the Federal Capital Territory (FCT), Nyesom Wike, that President Bola Ahmed Tinubu granted Oyo State N50 billion to upgrade the Ibadan Airport.

Wike had claimed during a television interview on Monday that the Federal Government provided the funds to support the upgrade of the Ladoke Akintola Airport in Ibadan to international standards.

Describing the assertion as false, Makinde clarified that the project is funded 100 percent by the Oyo State Government.

‘My attention was called to an interview granted by the FCT Minister, Mr. Nyesom Wike, where he said the President gave ?50 billion to Oyo State or to me to upgrade the airport in Ibadan to international standards. I want to say that claim is false,’ Makinde stated.

‘The President didn’t give ?50 billion to me or to Oyo State to upgrade the Ibadan Airport. The project is being undertaken 100 percent with the state’s resources.’

The APM presidential candidate expressed deep concern over the country’s worsening security situation, citing the recent killing of 37 young Nigerians in Niger State.

He also criticized President Tinubu for failing to formally transmit executive power to Vice President Kashim Shettima during extended foreign trips, citing Section 145 of the Nigerian Constitution.

Makinde emphasized that he consistently hands over power to his deputy whenever he travels abroad for more than 21 days, promising to uphold this constitutional requirement if elected.

Also speaking at the event, the party’s vice-presidential candidate and former DSS Director-General, Lawal Musa Daura, identified insecurity and poverty as the twin challenges crippling the Northwest region.

Daura emphasized that the Makinde-led APM ticket offers Nigerians a viable alternative, committing to systematic national restoration. He called on citizens to exercise their civic duty within lawful bounds and support the APM campaign in restoring peace and economic stability across the nation.

The NDPC’s new circular on data protection and responsible data governance: key considerations for Ministries, Departments, Agencies (‘MDAs’)

On August 4, 2026, the Nigeria Data Protection Commission (‘NDPC’) published a press release announcing the Federal Government’s commitment to mandating data compliance across public institutions. The Press release highlighted the issuance of a compliance circular (‘Circular No. 59805/S.I/7) directed to Ministries, Departments, and Agencies (‘MDAs’) by the Federal Government to promote public trust and strengthen data governance across public institutions. The underlying Circular invokes the Federal Government’s directive that all MDAs should ‘capture information rigorously and safeguard it under the Nigeria Data Protection Act 2023’ (‘NDP Act’).

Significance of the Circular

a. It elevates data protection from a simple compliance issue to a priority at the highest levels of government.

b. It mandates that Permanent Secretaries, Accounting Officers, and Chief Executive Officers are personally responsible for institutional compliance.

c. There are commercial implications not just for the MDAs of government but also for private entities, such as data processors, that process personal data on behalf of government institutions.

In light of the above, this insight sets out the Circular’s principal requirements, examines the implications for MDAs, and identifies practical challenges that may arise from the FG’s renewed focus on data protection.

What MDAs Are Required to Do

The Circular directs MDAs to ensure ‘full compliance with the NDP Act, Regulations, Guidelines and Directives issued by the NDPC in relation to the processing of personal data.’ To this end, the Circular imposes the following obligations:

1. Appointment of Data Protection Officers: MDAs must designate qualified officers as Data Protection Officers (DPOs) to oversee data protection compliance and advise management on all matters relating to the lawful processing of personal data.

2. Registration of DPOs with NDPC: MDAs are required to communicate the names and contact details of their designated DPOs to the NDPC for registration and official records. This creates an accountability link between each institution and the regulator.

3. Engagement of licensed Data Protection Compliance Organisations: MDAs may also engage the services of licensed Data Protection Compliance Organisations (‘DPCOs’) to facilitate compliance with the NDP Act and to support statutory compliance audits.

4. Budgetary Allocation for Data Protection: MDAs are required to allocate adequate budget for data protection compliance activities, including capacity building, awareness programmes, deployment of appropriate technical safeguards, and compliance audits.

5. Submission of mandatory audit returns: MDAs must submit all mandatory Data Protection Compliance Audit Returns (CAR) not later than March 31st of each year. and other Statutory returns to the NDPC within timelines prescribed by law.

6. Personal accountability of leadership: The Circular states that Permanent Secretaries, Accounting Officers, and Chief Executive Officers of all MDAs ‘shall be personally responsible for ensuring institutional compliance with the Circular and the provisions of the NDP Act.

Additionally, the NDPC confirmed that the Commission has established a regulatory clinic to provide technical support to MDAs to achieve compliance.

Implications for MDAs and the Private Sector Entities Contracting with MDAs

MDAs will need to undertake a range of activities to ensure compliance with the circular. These include identifying data-processing activities across departments and appointing qualified, experienced DPOs. MDAs will also be required to establish internal data-protection policies and operational procedures, and budget for staff training and awareness programmes. Where internal capacity is limited, MDAs will need to engage licensed DPCOs, prepare and submit data-compliance audit returns, and strengthen internal frameworks to address data-protection risks in third-party arrangements. Overall, for MDAs, this means stronger internal accountability, documentation, oversight and budgeting.

The implications of the Circular may extend well beyond the public sector. This means MDAs must require private contractors, technology vendors, cloud service providers engaged by them, and other private entities that may process data on their behalf to comply with data protection obligations under the NDP Act.

To address these risks, MDAs should incorporate appropriate data protection safeguards into their engagements with such third parties, including entering into data processing agreements, clearly defining the parties’ respective data protection responsibilities, conducting Data Protection Impact Assessments (DPIAs) where required, and implementing appropriate technical and organisational measures to protect personal data. MDAs should also establish mechanisms to monitor third-party compliance and manage data breaches and other data protection incidents throughout the engagement.

These entities should anticipate heightened due diligence requirements in their procurement processes. Data processing agreements would need to reflect the requirements of the NDP Act; there would also be audit requirements and rights of inspection by MDAs or their licensed DPCOs; and higher standards for documentation and record-keeping.

For vendors and service providers already engaged with MDAs, there may be a need to revise or supplement existing data processing agreements to incorporate additional data protection obligations. In particular, where these engagements involve the processing of personal data on behalf of MDAs, the parties may need to update their agreements to clearly set out their respective obligations under the NDP Act. This may include provisions on data security, audit and inspection rights, record-keeping, and the handling of data breaches and other data protection incidents.

Overall, for private-sector entities dealing with MDAs, it means greater scrutiny of their data-protection practices, contractual obligations and ability to safeguard government-held personal data. Businesses with demonstrable data-protection compliance may be better positioned to participate in government procurement processes and secure contracts involving the processing of personal data.

Practical Challenges for MDAs

The Circular requires MDAs to make ‘adequate budgetary provision’ for data protection. For example, recruiting qualified DPOs, ensuring technical safeguards, and engaging licensed DPCOs would require funding that may not have been anticipated in current budgetary cycles.

Second, many MDAs process personal data on systems not designed with data protection principles in mind and may lack support for modern access controls, encryption, or audit trails.

In addition, the Government procurement processes are often lengthy and procedurally rigid. Integrating data protection due diligence into procurement, renegotiating existing contracts, and ensuring vendor compliance may strain already slow processes.

Conclusion

The Circular reflects the Federal Government’s renewed focus on data protection compliance and mandates MDAs to understand and implement its requirements. This will require MDAs to review their existing internal data protection frameworks to identify gaps and ensure the integration of data protection practices into their day-to-day operations to ensure compliance with the NDP Act. For private entities dealing with MDAs, the Circular also signals the need for data protection compliance; therefore, they should ensure that their data protection agreements are sufficiently robust to meet the expectations of MDAs and the requirements of the NDP Act.

Nimma Jo-Madugu, Partner; Amanda Abor and Vivienne Orji, Associates – KENNA LP’s Data Protection Practice Unit

Kenna is licensed by the NDPC as a Data Protection Compliance Organisation (DPCO) to, among other things, provide audit services for the purpose of compliance with the NDP Act. Consequently, we are available to advise the MDAs on their obligations under the NDP Act and other applicable data protection regulations.

House adopts Senate version of BSKE bill

THE House of Representatives has adopted the Senate version of a measure extending the terms of Barangay and Sangguniang Kabataan (SK) officials to five years and postponing the next Barangay and Sangguniang Kabataan Elections (BSKE) from November 2026 to November 2028, paving the way for its submission to President Marcos for approval.

Last week, the House adopted Senate Bill 2387, allowing the measure to bypass the bicameral conference committee process and proceed to presidential action.

Camarines Sur Reps. Miguel Luis Villafuerte and Luigi Vincenzo Villafuerte welcomed the House action.

‘We are optimistic that barangay and SK officials will have more time to implement their development programs in their respective localities, following the approval of the Senate bill adopted by the House,’ said Miguel Luis Villafuerte, a co-author of the measure.

‘The longer terms will give them additional time to plan and carry out projects, particularly those that require longer periods to complete and deliver benefits to their communities,’ he added.

Under the measure, the next BSKE would be held on the second Monday of November 2028, with subsequent elections to be conducted every five years. With their terms extended by two years due to the postponement of the elections, incumbent elective barangay officials shall be regarded as having completed one term in their respective positions.

Deputy Majority Leader Luigi Vincenzo Villafuerte said, meanwhile, that the bill, which seeks to amend Republic Act 12232, also sets limits on the number of consecutive terms that barangay and SK officials may serve.

Barangay officials may serve two consecutive terms in the same position, while SK members may serve one term. It disqualifies incumbent barangay officials who are already serving their third consecutive term from running for the same position in the next barangay elections.

The measure retains the provision that voluntary renunciation of office for any length of time shall not be considered an interruption in the continuity of service for the full term for which the barangay or SK official was elected.

The House passed its version, House Bill 10971, by a vote of 211-13-1, with one abstention, on September 8, while the Senate approved its version, SB 2387, by a 13-5 vote on September 14.

The House’s adoption of the Senate version means the two chambers no longer need to convene a bicameral conference committee to reconcile separate versions of the measure. The adopted version can now proceed to the next stage of the legislative process and be submitted to the president for approval and signing into law.