
Sri Lanka’s financial system is being exposed to a dangerous new reality in which cyber threats are no longer merely technological problems, but symptoms of deeper institutional weaknesses within the State’s financial administration.
The warning was delivered by Central Bank Deputy Governor K.G.P. Sirikumara at the Sri Lanka Economic Association Economic Forum, at a time when Treasury inefficiency, weak governance structures and poor operational coordination continue to leave the country’s financial infrastructure vulnerable to sophisticated cyber scams.
Resilience means more than capital strength
Sirikumara stressed that resilience can no longer be measured solely by capital adequacy, liquidity and profitability. His remarks pointed towards a larger governance challenge, noting that financial stability increasingly depends on how effectively institutions anticipate risks, share intelligence and respond to rapidly evolving threats.
Cybercrime has become one of the fastest growing financial risks globally but Sri Lanka’s public financial management systems continue to suffer from outdated administrative practices, fragmented oversight and slow decision making.
Treasury institutions remain heavily dependent on manual procedures in several areas, while digital transformation has advanced unevenly across government agencies.
Institutional gaps create opportunities for cyber criminals
These weaknesses create opportunities for organised cyber criminals targeting government payment systems, financial databases and public sector transactions.
International cyber security reports have repeatedly shown that financial fraud increasingly exploits institutional inefficiencies rather than sophisticated technology alone.
Sirikumara warned that operational weaknesses amplify external shocks, an observation that carries particular weight given that cyber attacks frequently succeed when governance failures leave institutions unable to detect irregularities quickly or coordinate their responses effectively.
Reforms underway, but gaps remain
The Central Bank has sought to strengthen financial resilience through the Central Bank of Sri Lanka Act No. 16 of 2023, improved banking legislation and new policy coordination mechanisms. These reforms mark important progress, though legislation alone cannot eliminate vulnerabilities created by inefficient implementation.
Former Deputy Governor J.P.R. Karunaratne also warned that operational risks and cyber vulnerabilities remain insufficiently reflected in current financial sector indicators, suggesting that conventional measurements continue to underestimate the emerging digital threats facing the banking system.
Commercial banks have significantly increased their cyber security investment since the economic crisis. Financial experts, however, argue that weaknesses within government financial administration could undermine broader sector resilience if Treasury systems fail to maintain comparable standards.
Administrative shortcomings, not just technological ones
Investigators note that cyber scams increasingly exploit delayed reconciliations, weak verification procedures, fragmented databases and inadequate staff training, all of which are administrative shortcomings rather than purely technological failures.
Successful cyber attacks can erode public confidence in banking institutions, delay government services and disrupt economic recovery.
Sri Lanka’s growing dependence on digital payments makes institutional resilience increasingly important.
Shared responsibility across institutions
Sirikumara emphasised that financial stability is a shared responsibility requiring stronger coordination among regulators, policymakers and financial institutions.
That principle, he suggested, may now need to extend beyond the banking sector to include comprehensive reforms within Treasury operations, procurement systems and digital governance.
Unless administrative inefficiencies are addressed with the same urgency as banking reforms, Sri Lanka’s financial system may remain exposed to cyber criminals capable of exploiting the weakest links in public financial management, regardless of improvements in capital strength or profitability.
(Source- The Leader)
