Cybersecurity Strategy for Growing Businesses in Sri Lanka
Published · Intravantech Pvt Ltd
Most cybersecurity advice for businesses stops at the basics: strong passwords, antivirus, a firewall, backups. Those controls are necessary, but they are no longer enough. Today's attackers rarely break in through a missing antivirus. They log in, using stolen credentials, hijacked sessions, a compromised supplier or a convincing fake request to the finance team.
This guide is written for business owners, directors and IT leads who have already covered the basics and want to run security the way a mature organisation does: driven by business risk, measured and ready for an incident. It is the approach we use when we assess and protect our clients' environments.
1. Why a checklist is not a strategy
The threats facing Sri Lankan businesses have changed:
- Identity attacks. Attackers steal passwords through phishing, then bypass basic two-step verification by flooding staff with approval prompts or stealing the session token after login.
- Business email compromise. A real mailbox is taken over, and the attacker waits, then sends a payment request inside a genuine email thread.
- Ransomware with data theft. Attackers copy your data before encrypting it, then threaten to publish it even if you restore from backups.
- Supplier and SaaS compromise. Your IT provider, software vendor or a connected cloud app becomes the way in.
- AI-assisted fraud. Phishing messages without spelling mistakes, and cloned voices of managers asking for urgent transfers.
A checklist treats every control as equally important and never tells you whether you are actually safer. A strategy starts with what would hurt the business most, puts resources there first and measures the result.
2. Start with governance
Security fails when nobody owns it. The NIST Cybersecurity Framework 2.0 added "Govern" as its first function for exactly this reason. In practice, governance means:
- Clear ownership. One accountable person for security, with authority and budget, reporting to management at least quarterly.
- A defined risk appetite. Management decides how much downtime, data loss and financial loss is acceptable. For example: "Our booking system can be down for no more than four hours, and we can lose no more than one hour of data." Every technical decision follows from statements like these.
- A small set of real policies. Access control, acceptable use, backup and recovery, incident response, supplier security and data protection, each short enough that people actually read them.
- Regular review. Risks, access and controls are reviewed on a schedule, not only after something goes wrong.
3. Know your attack surface
You cannot defend what you cannot see. Map your environment from the attacker's point of view:
- Internet-facing exposure. Every system reachable from the internet: websites, email, VPNs, remote desktop, firewalls, camera systems, test servers. Exposed remote desktop and unpatched VPN appliances are among the most common ransomware entry points.
- Identities. Every user, admin, service and shared account, including accounts of former staff and suppliers.
- Data flows. Where sensitive data (customer, payment, payroll, health, intellectual property) is created, stored, sent and backed up.
- Shadow IT and SaaS. Cloud apps staff signed up for on their own, and third-party apps connected to your email or file storage.
- Email domain protection. SPF, DKIM and DMARC records on your domain, so attackers cannot easily send email that appears to come from you.
4. Assess risk with real scenarios
Instead of a colour-coded heat map, describe concrete attack scenarios and estimate their business impact:
- "An attacker phishes a finance user, takes over their mailbox and redirects a supplier payment."
- "Ransomware encrypts our file server and accounting system on a Monday morning."
- "A supplier with remote access to our network is breached."
For each scenario, estimate the likely financial loss (downtime, recovery, fraud, penalties, lost customers), then identify which controls would prevent, detect or limit it. Frameworks like MITRE ATT&CK help map how real attackers move, so your controls cover the steps that matter. Expressing risk in money makes security decisions business decisions, and makes budget conversations far easier.
5. Make identity your first line of defence
With cloud services and remote work, identity is now the main perimeter.
- Phishing-resistant authentication. Move admins and high-risk users (finance, management, IT) from SMS codes and push approvals to passkeys or FIDO2 security keys, which cannot be phished.
- Conditional access. Allow sign-ins based on device, location and risk, and block legacy protocols that bypass two-step verification.
- Privileged access management. Separate admin accounts from daily accounts, grant admin rights only when needed and record privileged activity.
- Emergency access. Keep at least one secured "break-glass" admin account for when normal sign-in fails.
- Joiner, mover, leaver process. Access is granted by role, reviewed when people change jobs and removed the day they leave, including supplier accounts.
- Service accounts and API keys. Inventory them, give them minimal rights and rotate their secrets.
6. Apply zero trust in practice
Zero trust means no user, device or network is trusted by default; every access request is verified. For a growing business, that translates into:
- Replace exposed remote access. Put remote desktop and internal apps behind zero-trust network access or a properly secured VPN with strong authentication, never directly on the internet.
- Segment the network. Separate servers, staff devices, payment systems, guest Wi-Fi, cameras and other IoT devices, so one infected device cannot reach everything.
- Check device health. Only managed, updated and encrypted devices can reach sensitive systems.
- Least privilege everywhere. People, applications and suppliers get only the access their role needs.
7. Build ransomware resilience
Assume prevention will eventually fail, and design for recovery:
- 3-2-1-1-0 backups. Three copies of your data, on two types of storage, one off-site, one immutable or offline, and zero errors in restore tests.
- Separate backup credentials. Backups must not be reachable or deletable with the same admin accounts attackers target.
- Defined RTO and RPO. How long each critical system can be down (recovery time objective) and how much data you can afford to lose (recovery point objective), agreed by management.
- Endpoint detection and response (EDR). Modern endpoint protection that detects attacker behaviour, not only known malware, and can isolate a device remotely.
- Recovery drills. Restore a critical system from backup at least twice a year and time it. Untested recovery plans usually take far longer than expected.
8. Detect and respond quickly
The longer an attacker is inside, the greater the damage. Mature organisations measure mean time to detect and mean time to respond, and work to reduce both.
- Log what matters. Sign-ins and identity changes, email activity, endpoint alerts, firewall and VPN events, and cloud admin actions, kept long enough to investigate an incident.
- Centralise and correlate. A SIEM brings these logs together and raises alerts on real attack patterns, such as an impossible-travel login followed by a new mailbox forwarding rule.
- Cover nights and weekends. Attacks are often launched outside office hours. A 24/7 security operations centre (SOC) makes sure alerts are acted on at any time.
- Prepare playbooks. Step-by-step responses for likely incidents: account takeover, ransomware, data leak, payment fraud.
- Decide in advance. Who leads the response, who can authorise taking systems offline, who speaks to customers and media, when legal advice is needed and how evidence is preserved.
- Exercise the plan. Run tabletop exercises with management, not only IT. In Sri Lanka, incidents can be reported to Sri Lanka CERT (cert.gov.lk).
9. Manage third-party and SaaS risk
Your security is only as strong as your suppliers' security.
- Tier your suppliers by the access and data they hold, and assess the high-risk ones properly.
- Put security in contracts: breach notification timelines, data protection obligations, access limits and your right to request evidence of controls.
- Review connected apps in email and cloud storage, and remove those that are unused or over-privileged.
- Offboard suppliers as carefully as staff: remove accounts, VPN access and shared credentials when the engagement ends.
10. Build security into the software you develop
If your business builds or commissions software, security has to be part of development, not added at the end:
- Threat modelling during design for features that handle sensitive data or payments.
- Secure coding standards, code review and automated scanning of code and third-party dependencies.
- Secrets kept out of source code and stored in a proper secrets manager.
- Penetration testing before major releases, and after significant changes.
11. Treat compliance as an outcome, not the goal
A strong security programme makes compliance much easier. The requirements most relevant to Sri Lankan businesses:
- Personal Data Protection Act, No. 9 of 2022. Sets obligations for how organisations collect, use and protect personal data, and is being brought into force in stages. Depending on your activities, you may need to appoint a Data Protection Officer, and you need appropriate security measures for the personal data you process.
- ISO/IEC 27001:2022. The international standard for information security management, increasingly requested by international clients.
- PCI DSS applies if you store, process or transmit payment card data.
- SOC 2 reports are often requested from technology and service providers working with US clients.
- Banks and financial institutions have additional technology risk requirements from the Central Bank of Sri Lanka.
This guide is general information, not legal advice. For your specific obligations, consult a legal adviser.
12. Measure and report to management
A security programme needs a few key risk indicators, reviewed monthly and reported to management quarterly:
- Percentage of admin and high-risk users on phishing-resistant authentication
- Number of privileged accounts, and any not reviewed in the last quarter
- Time to patch critical vulnerabilities on internet-facing systems
- Mean time to detect and respond to security incidents
- Date and result of the last successful recovery test against your RTO
- High-risk suppliers assessed in the last year
- Critical penetration test findings still open past their agreed fix date
If these numbers improve, your risk is going down. If nobody can produce them, measurement is the first gap to close.
A 90-day roadmap
Days 1–30
Visibility and quick wins
- Map internet-facing systems, accounts and critical data.
- Enforce two-step verification everywhere, and phishing-resistant methods for admins.
- Close exposed remote desktop and other risky services.
- Set up SPF, DKIM and DMARC on your email domain.
- Confirm offline or immutable backups exist.
Days 31–60
Control and resilience
- Separate admin accounts and review all privileged access.
- Deploy EDR on all endpoints and servers.
- Segment the network, starting with servers, payment systems and guest Wi-Fi.
- Agree RTO and RPO with management and run a first restore test.
- Write the incident response plan and playbooks.
Days 61–90
Detection and governance
- Centralise logs and set up 24/7 monitoring.
- Run an external penetration test and a tabletop exercise.
- Assess your highest-risk suppliers.
- Start the monthly risk indicator report to management.
How IntraVanTech can help
We work with growing businesses to put this strategy into practice:
- Risk assessments and gap analysis that show where you stand and what to fix first
- Security policy and governance reviews that hold up to client and auditor scrutiny
- Penetration testing of networks, web applications and internet-facing systems
- SOC monitoring with 24/7 threat detection and incident response
- Threat prevention through firewall hardening, network segmentation and secure remote access
- Compliance alignment for PDPA, ISO/IEC 27001 and client security requirements
If you want to know where your business stands against this guide, get in touch for a security assessment. See all our cybersecurity services.
Request a Security Assessment