Securing the Pillars of Society
The digital infrastructure supporting Bangladesh's economy — our power grid, telecommunication networks, and banking systems — is highly interconnected. This interconnectivity drives economic growth, but it also elevates national risk. Compromising these vital utilities, officially designated as Critical Information Infrastructure (CII), could result in widespread economic disruption and threaten national security.
Recognizing this risk, the government enacted the Cyber Security Ordinance, 2025, establishing mandatory security guidelines for the country's most vital systems.
The Designated 29: National Priority Entities
The government has officially designated 29 organizations as Critical Information Infrastructure. This list includes:
- Banking and Finance: Bangladesh Bank, Sonali Bank, Agrani Bank, Janata Bank, and major stock exchanges.
- Power and Energy: Power Grid Company of Bangladesh (PGCB), Bangladesh Power Development Board (BPDB), Titas Gas, and the Rooppur Nuclear Power Plant project.
- Telecom and Satellites: BTRC, Bangladesh Telecommunications Company Ltd (BTCL), and Bangabandhu Satellite Company Ltd.
- Essential Services: The National Data Centers and prime government offices.
Operational Mandates for Critical Systems
Under the 2025/2026 national framework, designated CII organizations must enforce rigorous cybersecurity standards:
1. Mandatory Dedicated CERTs
Every designated CII must maintain an internal Computer Emergency Response Team (CERT) or SOC capable of real-time monitoring and reporting incidents directly to BGD e-GOV CIRT.
2. Implementation of 24/7 SIEM/SOC Monitoring
Under the Bangladesh Bank Cybersecurity Framework (Version 1.0, 2025), financial institutions are legally required to run round-the-clock SIEM operations to detect and contain lateral movement and ransomware.
3. VAPT and Hardware Isolation
Operational Technology (OT) networks controlling power grids and satellite communications must be physically or logically isolated (air-gapped) from administrative IT networks. Regular vulnerability assessments (VAPT) must be performed by certified, independent third parties.
The Threat Landscape and the Future
Critical infrastructures face persistent challenges, from state-sponsored APT groups to volumetric DDoS attacks targeting power distribution centers. As the government drafts the Cyber Security Strategy (2026-2030), the focus remains on building collaborative resilience between public utilities and private security vendors.
Contact Oberon Services to protect your critical infrastructure with enterprise-grade SOC and VAPT services.