South Asia
External attack surface management for Bangladeshi organisations
Bangladesh rewrote its cyber laws in 2026. The Cyber Security Act 2026 requires critical information infrastructure to audit its internal and external infrastructure every year, and lets the national cyber security council publish reports on the security of CII websites. National CIRT advisories in 2026 counted hundreds of exposed end-of-life servers and firewalls in the country. EASMLens helps organisations find their own weak points first.
Serving organisations in Dhaka, Chattogram.
What the rules in Bangladesh expect
Cyber Security Act 2026
The Cyber Security Act 2026 (Act 81 of 2026) re-enacted the 2025 Ordinance and established the National Cyber Security Agency with a national CERT and a national security operations centre. The Act was amended in June 2026, so check the current consolidated text.
Every declared critical information infrastructure must have its own CERT or CIRT and SOC, and must audit its internal and external infrastructure every year and submit the report to the national council (section 16(2)). The council monitors the cyber risk of CII and other organisations every three months, and can publish analytical reports on the cyber security of the websites of ministries, agencies and CII (section 14). Any organisation that suffers a cyber incident must inform the national CERT without delay.
Bangladesh Bank ICT Security Guideline v4.0
Bangladesh Bank’s ICT Security Guideline version 4.0 requires an ICT asset inventory with owners, configuration and end-of-life details, preferably maintained with an automated tool (5.1.2). It asks for periodic vulnerability scans and an independent scan of critical systems each year (6.2), continuous attention to new threats on public-facing web applications (6.2.4), and penetration testing from inside and outside the network at least annually and after significant change, including adding a web server (6.2.6 and 6.2.7).
Personal Data Protection Act 2026
The Personal Data Protection Act 2026 (Act 63 of 2026) requires periodic assessment of processing risks and regular testing of security measures (section 17), and notification to the National Data Management Authority of a breach likely to cause significant harm, in the form and time set by regulations (section 20).
What the national CIRT is seeing
BGD e-GOV CIRT reported in March 2026 that 452 Bangladeshi IP addresses were running end-of-life Microsoft IIS and told organisations to fix internet-facing servers first. In July 2026 it identified 153 exposed FortiGate devices linked to a credential theft campaign. Both findings came from an outside-in view, which is the view EASMLens gives you of your own estate.
What each rule asks for, and what EASMLens shows you
| Rule | What it asks for | What EASMLens shows you |
|---|---|---|
| Cyber Security Act 2026 s 16(2) | Annual audit of internal and external infrastructure for CII | A defensible evidence base for the external part of each audit |
| Cyber Security Act 2026 s 14(4) | Council may publish analyses of CII website security | Your public websites’ TLS, headers, software and exposure before anyone else reports them |
| BB ICT Guideline 5.1.2 | Automated ICT asset inventory with end-of-life details | Internet-facing assets and end-of-life software discovered automatically |
| BB ICT Guideline 6.2.4 | Public-facing web applications kept current against new threats | Known vulnerabilities on every public web application |
Reporting clocks
Any organisation (Cyber Security Act 2026)
Inform the national CERT without delay
Personal data (PDP Act 2026)
In the form and time set by regulations
Banks
Report to Bangladesh Bank CIRT
Questions for the board
- 1If we are declared CII, what is the evidence base for the external part of our annual audit, and does it include cloud and vendor-hosted assets?
- 2The council can publish reports on CII website security. Would we rather find our weak sites first?
- 3After the national advisories on end-of-life IIS servers and exposed FortiGate devices, can management show how many such systems we have today?
How EASMLens supports these obligations
- Discovery and automated checks of internet-facing infrastructure to support annual external audits
- End-of-life software and known vulnerability detection on public servers
- Website security posture across every public site you own
- Email domain security grading for government and business domains
EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.
Frequently asked questions
- Which cyber security law applies in Bangladesh now?
- The Cyber Security Act 2026 (Act 81 of 2026), which re-enacted the 2025 Ordinance and was amended in June 2026. Much online content still cites the 2023 Act or the Ordinance, which have been replaced.
- Is there a fixed breach notification deadline?
- The Personal Data Protection Act 2026 leaves the timing to regulations, which had not been published at the time of writing. The Cyber Security Act 2026 requires incidents to be reported to the national CERT without delay.
- Does EASMLens access our systems?
- It never logs in to or exploits your systems. Its active checks send ordinary network requests to the internet-facing assets in your scope. Unauthorised access to CII is an offence under the Cyber Security Act 2026, so keep your scope to assets you own or are authorised to test.
Related guides
Primary sources
- Cyber Security Act 2026 (bdlaws, Bangla)
- Personal Data Protection Act 2026 (bdlaws, Bangla)
- Bangladesh Bank ICT Security Guideline v4.0
- BGD e-GOV CIRT advisories
Regulatory content reviewed on . General information only, not legal advice.