Shares
In September 2015, a ransomware attack hit several European airports, including London Heathrow, and brought them to a complete standstill. Staff had to handle check-ins and boarding manually, which was a massive headache for an airport that serves over 80 million people a year. Beyond the delays, the stress on people traveling for medical care, work, or family was immeasurable. These kinds of disruptions don't just stay in one place; they ripple outward. For example, a 2025 cyberattack on Jaguar Land Rover stopped production worldwide, and back in 2017, the WannaCry attack on the UK health system affected hundreds of clinics. Doctors couldn't access records and surgeries had to be canceled, which is life-threatening. If a power grid gets hacked, it could mean no lights, no heat in winter, and no phone service. Thousands of these attacks are recorded every few months, and with AI making them more sophisticated, we have to take security seriously to prevent widespread chaos.
For Nepal, we need to focus on protecting five main areas: banking, telecommunications, aviation, energy, and healthcare. Banking and digital payments are the lifeblood of daily life now. If these systems go down, people can't buy basic goods, which can lead to panic and even social unrest. Telecommunications is just as important because it runs everything from schools to hospitals and energy systems. A recent attack on providers in Singapore showed how easily these networks can be disrupted. For many of us, our phones are essential tools for almost everything we do, and without a working network, those tools become useless.
Aviation is also a vital link for Nepal, especially during natural disasters or border blocks when roads are closed. Recent incidents in the Middle East have shown that any trouble in the aviation sector quickly turns into a major crisis. Then there is our energy sector. Since most of our power comes from hydropower, a single breach could paralyze the entire economy. As more people switch to electric cooking to reduce reliance on imported gas, a blackout would be even more devastating for households. Finally, healthcare is perhaps the most critical area. Cyberattacks here directly threaten lives. If a hospital can't access patient records or if a medical device is hacked—which researchers have shown is possible—the consequences can be fatal.
Cyber warfare is a real threat, and it is a matter of when, not if, an incident will happen. Just because we haven't faced a major crisis yet doesn't mean we can ignore the risks.
Even though we currently lack enough experts and clear rules in Nepal, it is not too late to act. Other countries with similar resources have shown it can be done. For example, Rwanda has a national authority to watch over their infrastructure and run regular security drills. Nepal can do the same. This should start at the government level by creating a solid national policy and setting up a Computer Emergency Response Team, known as a CERT. This team would monitor threats and help different sectors recover when things go wrong. While we build our own local expertise, we can look to the global tech industry for help. Companies like Microsoft have helped countries like Ukraine secure their data during times of crisis, and Nepal could reach out for similar support.
We also need laws that require companies to report cyber incidents and follow international security standards. Our existing response teams should be upgraded to work around the clock. At the same time, we should adopt a zero trust approach, which basically means the system never just assumes a user is safe. If an employee logs in from an unusual location and starts moving sensitive files, the system should flag it for review. We should also move away from using SMS for security codes, as they are too easy to hack. Instead, using hardware security keys is a much more reliable way to protect sensitive accounts.
Technology is only part of the solution; we also have to focus on the people using it. This means regular training for all staff and better certifications for IT workers. We could even start bug bounty programs, where people are paid to find and report security flaws. This is a common practice for big companies like Apple and helps fix problems before hackers can find them. Cyber warfare is a real threat, and it is a matter of when, not if, an incident will happen. Just because we haven't faced a major crisis yet doesn't mean we can ignore the risks. Taking small steps now, like improving monitoring and keeping secure backups, will go a long way in keeping our public services running and our people safe. While this article only scratches the surface, we need a serious, long-term plan to keep our essential systems secure. It is paramount to prevent wide-scale disruptions as we have seen in the UK, Singapore or elsewhere.
(Disclaimer: The views and opinions expressed in this article are solely my own and do not reflect the official policy or position of my employer)
(Mr Dhungel is a Security Engineer for Apple Inc. based in Zurich, Switzerland)
Shares
.