Digitalisation Without Security: Nepal’s Cybersecurity Capacity and the Limits of the National Cyber Security Centre

Nepal is on a digitalization spree.  Guided by the 2019 Digital Nepal Framework, systems for the National identity system, passport, immigration, land administration, transport, and citizen-facing services have increasingly become digital. Nepal has been migrating sensitive state and citizen data to connected systems for several years.  Indeed, going digital offers genuine benefits; it can reduce both time and costs. But digitalisation also brings a host of threats that often differ from those in analogue systems. While analogue systems are vulnerable to loss due to fire, flood or any other physical destruction, digital systems are exposed to risks that are harder to contain. Data can be copied remotely and silently altered, leaked, sold, or exploited; combined with other data sets; encrypted for ransom; or made available to every user at once.  

Nepal has definitely not ignored this matter. The National Cybersecurity Policy, 2023 (2080) and the Data Centre and Cloud Service Directives, 2024 (2081)  recognise the threat and outline a roadmap for strengthening cyber defences. In addition, the proposed draft Personal Data Protection Policy, 2025 (2082) sets out requirements for protecting personal data, including collection, storage, use, transfer, and disposal, as well as the responsibilities of relevant stakeholders. Indeed, these are good steps, but events from the recent past question whether the adoption of the framework itself has been effective.  

Nepal’s standing in the Global Cybersecurity Index 2024 is Tier 3, indicating progress; however, it also shows Nepal continues to face a wide range of cyber threats that challenge the digital security ecosystem. It also highlights a lack of technical capacity, inter-institutional cooperation, and a skilled workforce. In 2026, at least 135 official government email addresses of civil servants, including those of the Office of the Prime Minister, the Ministry of Home Affairs, the Ministry of Finance, and the Ministry of Foreign Affairs, were confirmed compromised in various data breaches.  

In the past few years, government websites have increasingly become easy targets. For instance, in February 2025, a hacker group known as YNR took responsibility for accessing 21 subdomains under the Koshi Provincial Government and then later published the evidence on the Zone-H portal.  Another incident involved a group known as Kaju/Kazu gaining access to the personal data of around 2 million Nepali citizens via the Nepal Police Headquarters website and even claimed that they offered it for sale online for USD 7,000. The government’s main server, the Government Integrated Data Centre, was also targeted in cyberattacks that disrupted around 1,500 government websites. It affected international travel, and the immigration server had to be shut down.  

While Nepal has the policy framework, its institutional architecture remains incomplete. Currently, the National Cyber Security Centre governs and monitors Nepal’s cybersecurity architecture. Its main function is to conduct 24-hour monitoring through the Security Operations Centre (SOC) and to conduct Vulnerability Assessment and Penetration Testing for new systems developed and launched under the Nepal Government. Although it has been two and a half years since its establishment, the centre is still finding its way to form teams and operate.  

SOC monitoring continues 24 hours; nonetheless, it covers only the federal government’s major data centre and systems under the Information Technology and Digital Governance Office and the Financial Comptroller General Office. This raises two concerns: they monitor only potentially disruptive attacks and inform the relevant authority if they detect any. This is only a minor part of cybersecurity and excludes other threats. Secondly, all other government websites and portals, like the Nagarik App, Land Management Office systems, Inland Revenue Office systems, etc. do not fall under their monitoring.  

Most systems in Nepal, whether federal, provincial, or local, are developed independently by hiring a vendor, and some bodies have their own data centres. Without proper network connectivity, it is infrastructurally difficult to bring these systems under a single monitoring mechanism. Hence, limited infrastructure capacity is restricting NCSC from expanding its monitoring horizon. 

The primary barrier to everything NCSC intends to build is also the lack of legal grounds. At present, they are guided only by the National Cyber Security Policy. Officials are waiting for the tabled IT and Cyber Security Bill to be passed so they have a legally binding mechanism to enforce their functions. They have been issuing advisories to government bodies on their systems’ security architecture. However, they have no grounds to impose responsibility on government bodies. They do not have the jurisdiction to question the government bodies on their management, maintenance, and control of the system.  

Nepal has built a policy framework for cybersecurity, but the institutions responsible for implementing it remain constrained by limited capacity, coverage, and legal authority. The NCSC can monitor some systems, conduct security testing and issue advisories, but it cannot require government bodies to comply with its recommendations or bring all government systems under its monitoring. As Nepal continues to move sensitive public services and citizen data online, the gap between digitalisation and the capacity to secure it is becoming harder to ignore. A national cybersecurity institution needs more than a mandate on paper; it needs the legal authority, technical expertise, infrastructure, and resources to enforce and continuously maintain that mandate. Without these, Nepal risks building its digital state faster than it is building the institutions needed to secure it. 

Author

  • Ms. Bastola is a recent graduate of Kathmandu University School of Law (BBM LL.B.). Her interests lie at the intersection of international law, policy, and global economic governance, with a particular focus on geopolitics, international trade, and energy systems. Drawing on experience in legal research, advocacy, and policy engagement, she is interested in how legal frameworks shape economic relations and international cooperation in an evolving global order.