š”ļø Sri Lanka Cyber Readiness: Tackling "Dark Data" & Fraud Ahead of 2027 PDPA
The 2nd Data Privacy and Protection Summit 2026 convened over 380 industry leaders to address critical cybersecurity vulnerabilities, dark data, and the role of AI-driven defenses in Sri Lanka's digital economy.
⢠Rising Cyber Threat & Fraud Metrics
⢠Estimated card-not-present fraud losses jumped 149% from 2025 to reach US$ 49 Bn across the Asia Pacific region.
⢠Nearly 60% of data breaches stem from unmanaged, forgotten "dark data" systems.
⢠Global average cost of a data breach reached US$ 4.8 Mn in 2024, with 75% of consumers refusing to transact with breached firms.
⢠High-Risk Sectors & Attack Vectors
⢠70% of cyberattacks target three foundational pillars: ICT/BPM (technology), financial services, and the government sector.
⢠Primary threats targeting local entities: Malware, email phishing, ransomware, and reconnaissance.
⢠Key targets include customer financial data, personally identifiable information (PII), business systems, and intellectual property.
⢠Strategic Imperatives for Sri Lanka
⢠Upcoming enforcement of Sri Lanka's Personal Data Protection Act (PDPA) on 1 January 2027 makes data governance a critical strategic priority.
⢠Adoption of AI-powered security is key to automatically discovering, classifying, and securing unstructured sleeping data across banking and connected payment networks.