10th Parliament· 154 sittings on record · 30,475 speeches · latest 10 June 2026

The Hon. Ravi Karunanayake

New Democratic Front· National List· 23 October 2025 ·Oral question: Urgent Question: Digital Infrastructure Outage (Standing Order 27(2))

InfrastructureCorruption & Governance ReformSecurity & Defence
AI summary generated by gpt-5.5

Hon. Ravi Karunanayake raised an urgent question under Standing Order 27(2) to the Minister of Technology regarding the 14 October 2025 collapse of the Lanka Government Cloud and recent cyber incidents affecting State institutions, banks and digital services. He asked for clarification on the cause of the failure, whether any external intrusion or data compromise occurred, the number of similar incidents, financial losses, disaster-recovery arrangements, and assurances on the integrity of citizen and institutional data. He also called for a cyber security audit to be tabled, measures to restore confidence in e-Government systems, and consideration of a legally empowered National Cyber Security Command Authority, along with proposed digital transformation and cyber security legislation.

Verbatim record (translated)

Machine-translated from Sinhala / Tamil / English

¶ 01 Hon. Speaker, I seek permission to ask this Question of urgent national importance from the Minister of Technology under Standing Order 27(2).

¶ 02 In recent months, Sri Lanka’s digital backbone—the infrastructure sustaining governance, commerce and citizen services—has come under severe strain. The sudden collapse of the Lanka Government Cloud (LGC) on 14 October 2025, crippling eight major State institutions including the Registrar of Companies, the Department of Commerce and the Police Clearance System, has exposed alarming fragility. SLCERT termed it an “internal technical issue”, but lack of transparency has deepened public anxiety.

¶ 03 Over the last six to ten months, we faced unprecedented cyber intrusions targeting banks, State agencies and financial intermediaries. Even the Chairman of BOI, Mr. Arjuna Herath, was intercepted. These attacks shake confidence in protecting sensitive data. Yet there has been no comprehensive cyber audit, national digital risk assessment, or unified crisis command. This is not merely a tech failure but one of governance and foresight.

¶ 04 ICTA and SLCERT, entrusted to safeguard the digital ecosystem, appear unsynchronized. Citizens deprived of essential digital services—birth, marriage, death certificates, e-revenue licences—had to revert to manual processes, a regression for a nation aspiring to be a South Asian digital hub. Conflicting signals further erode trust.

¶ 05 What is at stake is data sovereignty. A breach at this scale would devastate national security, financial integrity and international confidence. In an era of cyber warfare, this must be a wake-up call. Digital government infrastructure is a strategic national asset requiring vigilance and oversight equivalent to physical borders.

¶ 06 Accordingly, I ask:

¶ 07 1. What specific technical or administrative failure led to the LGC collapse on 14 Oct 2025, and have preliminary investigations or a forensic audit identified accountability within ICTA or service providers? 2. Was it purely an internal failure as SLCERT stated, or is there evidence of external intrusion or data compromise? 3. How many similar breakdowns or cyber incidents occurred on key government digital platforms over the past 12 months, and what corrective actions followed? 4. What was the total financial and economic loss to the nation, including disruptions to e-Revenue Licences, police clearance, and other revenue streams? 5. What is the Government’s fallback or disaster-recovery mechanism for such failures? Is there a secure, real-time onshore/offshore backup for citizen and institutional data? 6. Can the Government assure that all sensitive data on LGC remain intact and uncompromised, and will a cyber security audit report be tabled? 7. What steps are taken to restore public and international confidence in e-Government systems given increased cyber attacks in the last six to ten months? 8. Will the Government establish a legally-empowered National Cyber Security Command Authority to coordinate and defend all national digital assets? 9. As we accelerate digital governance, what legislative, policy and institutional safeguards are being introduced to prevent such cyberattacks or collapses? When will a comprehensive Digital Transformation Act and Cyber Security Protection Law be presented? 10. Finally, what assurance can be given that such a collapse will not recur and that the Government has the readiness, expertise and resilience to withstand threats of this magnitude?

Provenance

Source
Hansard, Thursday, 23 October 2025 ·No. 22641 ·English daily/uncorrected Hansard
Page · column
not yet extracted — page/column anchors are not in the current dataset; the source PDF is the citable location.
Permalink
/lk/speeches/7900

Cite as: The Hon. Ravi Karunanayake. 10th Parliament, Parliament of Sri Lanka. Hansard, 23 October 2025. No. 22641. Politick, https://staging.politick.io/lk/speeches/7900