Sri Lanka’s Parliament faces a significant risk of cyberattack on its digital systems, according to audit findings set out in the institution’s 2025 Annual Performance Report.
The Sri Lanka Computer Emergency Readiness Team (SLCERT) assessed Parliament’s information and cybersecurity during the review period, examining 56 cybersecurity-related areas. Of those, 46 were found to carry a high level of risk.
The report warns that the weaknesses leave open the possibility of malicious cyber activity against the legislature, including unauthorised access to its digital systems, the theft of sensitive information, disruption of institutional operations and the defacement of official websites. Such an incident, it notes, could damage the institution’s reputation.
The audit recommends that immediate attention be given to closing the vulnerabilities identified.
The finding lands amid sustained scrutiny of cybersecurity across Sri Lanka’s public sector. The Committee on Public Finance reported this month that the General Treasury’s email system had been outdated since 2019, a lapse it linked to the USD 2.5 million cyber theft from state accounts. In June, a cyberattack disabled the Sri Lanka Railways website and its train schedule system, taking timetable information offline for passengers.
SLCERT, the national body for cybersecurity incident response, conducts security audits of government information systems and has run awareness programmes for public officials, including members of Parliament. Ada Derana’s report did not say what remedial steps Parliament has taken since the assessment, or over what timeframe the recommended fixes are expected to be completed.