Sri Lanka CERT and the Asian Development Bank have put the findings of an assessment of the country’s Critical National Information Infrastructure (CNII) to the officials who would have to act on them, at a session held on 15 September at the Ruby Hall, BMICH, Colombo.

The exercise — formally the Identification and Assessment of Critical National Information Infrastructure in Sri Lanka — was carried out under the Advancing Digital Transformation Project with ADB support. It was conducted by TNK2, a cybersecurity research and development company based in Melbourne, Australia, and the session was led by TNK2’s Managing Director, Dr. Jongkil Jay Jeong.

Who was in the room

The audience was drawn from the organisations that own the infrastructure in question: Information Security Officers and Assistant Information Security Officers representing CNII bodies, alongside ADB representatives.

The agenda covered the assessment’s methodology, its key findings, observations on cybersecurity and resilience, and the gaps and challenges identified. A stakeholder feedback segment was built in specifically to validate the findings — meaning the results presented were not yet final, and the institutions being assessed were given a chance to contest or correct them before the report is settled.

Participants also discussed priority areas, recommendations and next steps for strengthening CNII protection.

Why it matters

Sri Lanka has been dealing with the consequences of weak state cyber defences in public. In 2026 the Treasury lost roughly US$2.5 million to a fraud that used fabricated emails impersonating a foreign creditor — a breach of exactly the kind of financial system a CNII register is meant to cover, and one still being argued over in Parliament in September. Sri Lanka CERT has separately spent the year on the awareness end of the problem, including training more than 300 Southern Province police officers in cyber security in August.

The significance of this assessment is more basic than any single breach: identifying which systems count as critical is the step that has to come before they can be protected under a common standard. Until that register exists, “critical infrastructure” has no agreed membership list.

Not reported

The Colombo Gazette account — the only published account of the session — does not say how many organisations were assessed, which sectors they fall under, what the key findings or identified gaps actually were, whether the assessment will be published, what it cost, or when a final report is due. No CERT or ADB official is quoted, and no timeline was given for acting on the recommendations.