India and Sri Lanka have held their first formal cyber-security consultations in Colombo, covering threats posed by artificial intelligence and the exchange of threat assessments between the two countries.
The Indian delegation was led by Sanjay Bahl, director general of the Indian Computer Emergency Response Team (CERT-In), and Amit Shukla, joint secretary for cyber diplomacy at India’s Ministry of External Affairs, Tamil Guardian reported, citing a press release from the Indian High Commission in Colombo. Devika Lal, counsellor for economic and commercial affairs at the High Commission, also took part.
What was discussed
The delegation met Deputy Minister of Digital Economy Eranga Weeraratne at the GovTech premises on Monday. The talks covered cyber-security governance frameworks, the challenges posed by AI, the exchange of threat assessments, and CERT-In’s practices on capacity building and incident response.
The Sri Lankan side said discussions also covered strengthening Sri Lanka CERT’s ability to identify and respond to cyber threats, cyber-security training for government institutions and the public, and setting up artificial-intelligence-assisted mechanisms for cyber threat assessment.
The delegation separately met Anil Jayantha Fernando, Minister of Labour and Deputy Minister of Finance and Planning, on cyber-security cooperation for the financial system and the digital economy. Talks with Sri Lanka CERT chairman Thilak Pathirage and chief executive Kanishka Karunasena covered knowledge exchange, capacity building, cyber-crisis management, and national strategies on quantum computing and AI.
Context
The consultations follow the first visit to Sri Lanka by an Indian defence minister in 38 years, in September, when the two countries signed three military agreements.
They also come as Sri Lanka builds out its own cyber-security architecture. This desk has reported the National Cyber Security Operations Centre fast-tracking 25 institutions onto its monitoring platform, the Cyber Security Regulatory Authority bill cleared by Cabinet, and the Central Bank’s recruitment of a red-team specialist. The financial-system strand of Monday’s talks is the one that touches the long-running Treasury cyber-heist investigation, though neither side is reported to have raised that case.
This is a separate matter from the Treasury cyber-heist family — these are bilateral consultations on policy and capability, not an investigation.
Not reported
The filing does not say whether any agreement, memorandum or work plan was signed, when the next round will be held, or whether the consultations will become a standing annual mechanism. It does not say what threat assessments, if any, were actually exchanged, or whether the two sides discussed specific incidents.
Tamil Guardian noted in its report that Sri Lankan security forces have a record of monitoring Tamils’ online activity, including arrests over social media posts under the Prevention of Terrorism Act and the use of the Online Safety Act against Tamil media. The filing does not report any discussion of safeguards, oversight or data protection attached to the cooperation.
At the time of writing this desk could not find a filing on these consultations from any other verified newsroom; Ada Derana is reported to have covered it, but that domain has been unreachable from this desk for more than two weeks and could not be fetched or dated.