Insights · Cloud
Cybersecurity for Nepali SMEs: what recent breaches teach
The short version
Most breaches at Nepali small businesses don't need a clever hacker. They need one reused password, one unpatched plugin or one backup nobody tested. Ten basic controls, most of them free, would have blunted nearly every incident on this page. The hard part is doing them consistently, not buying anything.
Nepal has had a busy few years. On 20 September 2026, a ransomware attack on DataHub, a data centre that hosts the trading systems of 72 brokerage firms, took those systems down, and the Nepal Stock Exchange halted trading the next day at the brokers' request. A month earlier, Nepal's National Cyber Security Centre joined the Have I Been Pwned breach tracker and found at least 135 official government email addresses in leaked data. Those aren't SME stories, but the causes behind them are exactly the ones that hit small firms.
What have Nepal's notable breaches actually looked like?
Look at the public record and a pattern shows up. Very few incidents were exotic. Most came down to access that was too easy to get, systems that weren't patched or separated, or recovery that depended on luck.
- October 2017, NIC Asia Bank: attackers sent fraudulent SWIFT transfers during Tihar, about $4.4 million in total, most of which was later recovered. The Kathmandu Post reported that the SWIFT computers were also used by IT staff for everyday tasks such as personal email.
- March 2020, Foodmandu: a leak of about 50,000 users' names, phone numbers, addresses and emails was posted publicly, according to myRepublica. The company said it fixed the flaw.
- January 2023, the Government Integrated Data Centre: a distributed denial-of-service attack knocked around 1,500 government websites offline and stalled immigration systems at Tribhuvan International Airport for about three and a half hours. Officials said no data was compromised.
- September 2025, the Gen Z protests: fires destroyed the Department of Transport Management's server and archives, while bodies with offsite backups, like the Supreme Court, could restore. The government data centre's disaster-recovery site in Hetauda stayed intact.
- August and September 2026: the 135 leaked government email accounts, then the DataHub ransomware attack that stopped share trading.
None of these reports names a confirmed culprit in a way we'd repeat here, and it doesn't matter for a business owner. What matters is the lesson each one carries: separate critical systems, patch what faces the internet, protect logins, and keep a copy of your data somewhere a fire or a ransomware gang can't reach.
Why is this a bigger risk for Nepali SMEs now?
Because the scams have moved to where customers already are. Nepal Police's Cyber Bureau registered 20,526 cybercrime complaints between mid-July 2025 and mid-July 2026, myRepublica reported in August 2026. Most involved social media, but 744 were about digital payments and bank accounts, including eSewa, Khalti and SMS fraud, and 846 involved organisations. Fake parcel, lottery and job messages were among the patterns police flagged.
The policy side has also caught up. The cabinet endorsed the National Cyber Security Policy 2080 in August 2023, which set up the path for new laws and standards. Nepal Rastra Bank's Cyber Resilience Guidelines, enforced from August 2023, already apply to banks, payment service providers and payment operators. If you're a vendor or a merchant connected to them, expect their security questions to land on your desk. And if customer data leaks, your duties under the Privacy Act kick in, which we covered in Nepal's Privacy Act and your CRM, chatbot and AI tools.
How do attackers actually get in?
Verizon's Data Breach Investigations Report is the largest public dataset on this. Its 2026 edition, published in May, found that exploiting a software vulnerability was the top way in for the first time in the report's 19 years, at 31% of breaches, up from 20% a year earlier. Phishing was 16%. Stolen credentials fell to 13% as a first step, partly because Verizon started tracking pretexting separately, but credential abuse still appeared somewhere in 39% of breaches. Ransomware showed up in 48% of breaches, and third parties were involved in close to half.
How attackers get in: top initial access vectors
Share of breaches by first step, 2025 vs 2026 editions
Source: Verizon 2025 DBIR (Apr 2025) and 2026 DBIR (May 2026), via Verizon and Help Net Security. 2026 credential abuse excludes the newly separated pretexting category; measured the old way it would be about 16%, and it appears anywhere in the chain in 39% of breaches.
| Category | DBIR 2025 | DBIR 2026 |
|---|---|---|
| Vulnerability exploitation | 20% | 31% |
| Phishing | 16% | 16% |
| Credential abuse | 22% | 13% |
Exploited vulnerabilities jumped to the top in 2026, but stolen logins are still involved in far more breaches than the first-step figure suggests.
Read that chart as a to-do list. Patching handles the tallest bar. MFA and a password manager handle the credential problem. Awareness training reduces the phishing share. Vendor hygiene covers the third-party half.
How does a typical SME breach unfold?
Here's the chain we see most often in small firms. A staff member gets a convincing message, perhaps a fake bank or eSewa alert in Nepali, and types their email password into a lookalike page. The attacker logs into the mailbox, reads invoices, and sets a hidden forwarding rule. From there they either send a customer a 'new bank account' for payment, or use the same password on the cloud admin console, turn off backups and run ransomware. Tap each step below to see which control breaks it.
From one phishing SMS to invoice fraud or ransomware
Tap a component to see what the attacker does there and which control stops it.
Tap any component above for its role and the real tech.
Every link has a cheap control. You only need to break one to stop the chain, but defence in depth means you break several.
- Phishing SMS or email (External, Fake bank, eSewa or parcel message): The attacker sends a message that looks like a bank, a wallet or a courier, often in Nepali. Phishing was the first step in 16% of breaches in the 2026 DBIR. Control that breaks it: short, regular awareness training with local examples, plus a rule that nobody acts on payment changes from a message alone.
- Staff member (Client, Laptop or phone): One click and a typed password is all it takes. Controls: a password manager, which refuses to autofill on a lookalike domain, and patched browsers and phones so a malicious page can't install anything.
- Website or CMS (Service, WordPress, plugins, admin panel): The other front door. Exploited vulnerabilities were the top first step in 2026 at 31%. Controls: automatic updates for the CMS and plugins, deleting unused plugins, and MFA on the admin login.
- Stolen password (Auth, Reused or phished credentials): Credential abuse appeared somewhere in 39% of 2026 breaches. Controls: MFA everywhere, unique passwords from a password manager, and checking your domain on Have I Been Pwned.
- Mailbox takeover (API, Google Workspace or Microsoft 365): Inside the mailbox the attacker reads invoices and adds a forwarding rule so replies go to them. Controls: MFA, alerts on new forwarding rules and new-country sign-ins, and removing shared inboxes that many people log into with one password.
- Cloud admin console (Auth, AWS, Azure, hosting panel): If the same password works here, the attacker owns your servers. Controls: least privilege, separate admin accounts with hardware or app-based MFA, and revoking access the day someone leaves.
- Invoice fraud (External, Fake bank-change request): A customer or supplier receives a genuine-looking email from your real address asking them to pay a new account. Controls: call-back verification on any bank detail change, and mailbox alerts so you spot the takeover first.
- Ransomware (Service, Encrypts servers and file shares): Ransomware appeared in 48% of breaches in the 2026 DBIR. Attackers usually delete reachable backups first. Controls: least privilege, patching, and logging with alerts on mass file changes.
- Offline backup copy (Data, 3-2-1: 3 copies, 2 media, 1 offsite): The copy the attacker can't reach, because it is offline, immutable or held under a separate account. During the 2025 unrest, offices with offsite backups restored; one without them lost its archives. Control: tested 3-2-1 backups, with a restore drill every quarter.
- Logs and alerts (Service, Sign-in logs, cloud audit trail): Logs tell you what happened and when it started, which you need for recovery and for Privacy Act notices. Control: keep sign-in and admin logs for at least 90 days and route the important alerts to a phone someone actually watches.
A typical small-business breach, from a phishing message to fraud or ransomware, with the control that breaks each step.
Which 10 controls stop most SME breaches?
You don't need to invent a framework. The UK's Cyber Essentials scheme boils small-business security down to five technical controls: firewalls, secure configuration, user access control, malware protection and security updates. The US CISA's Cyber Essentials and the CIS Controls Implementation Group 1, which is 56 safeguards aimed at small, resource-limited teams, say much the same thing. We've squeezed them into ten items a Nepali SME can actually do, with rough effort and what each one stops.
10 controls, what they cost and what they stop
Sort or filter. Costs are typical list prices or effort, as of September 2026.
| MFA on email and cloud admin | Free in Workspace, M365, AWS | 4 | Logins with stolen or reused passwords | NCSC CE user access; CISA; CIS 6 |
|---|---|---|---|---|
| Password manager | A few USD per user per month | 6 | Password reuse, lookalike-site phishing | CIS 5; CISA |
| Patching, auto-updates on | Free | 3 | Exploited vulnerabilities, the top vector in 2026 | NCSC CE security updates; CIS 7 |
| Tested 3-2-1 backups | Storage plus one offsite copy | 8 | Ransomware, fire, accidental deletion | CISA; CIS 11 |
| Least privilege | Free | 5 | One stolen login becoming a full takeover | NCSC CE user access; CIS 5, 6 |
| Phishing awareness, Nepali examples | Free to low | 2 | Fake bank, eSewa and parcel SMS | CISA; CIS 14 |
| Offboarding and no shared accounts | Free | 2 | Ex-staff and shared-password access | NCSC CE user access; CIS 5 |
| CMS and plugin updates | Free to low | 2 | Website defacement, data leaks via plugins | NCSC CE security updates; CIS 2, 7 |
| Secure configuration and firewall | Free | 4 | Exposed admin panels, default passwords | NCSC CE firewalls, secure config; CIS 4 |
| Logging and alerts | Free tiers to low | 6 | Silent mailbox takeovers, late discovery | CISA; CIS 8 |
Most of the list is free settings plus a few hours. Backups and logging take the most setup time. Frameworks: UK NCSC Cyber Essentials, CISA Cyber Essentials, CIS Controls v8 IG1. Vector data: Verizon 2026 DBIR. Effort hours are NeuralYug estimates for a 10 to 50 person firm on common SaaS, not a published benchmark.
Ten controls a small team can finish in about a month of part-time work.
What does each control look like in practice?
- MFA everywhere, starting with email and the cloud or hosting admin account. Use an authenticator app, not SMS, for admins.
- A business password manager so every login is unique and shared credentials are stored, not pasted into chats.
- Automatic updates on laptops, phones, routers and servers, with a monthly check for anything that failed.
- 3-2-1 backups: three copies, on two kinds of storage, one offsite or immutable. Restore one real file every quarter.
- Least privilege: daily work on normal accounts, admin rights only where needed, and a separate admin login.
- Ten-minute phishing talks using real local examples, like a fake Nepali-language bank or eSewa SMS, and a rule to call back before changing any payment detail.
- Offboarding on the last day: disable accounts, rotate shared passwords, pull devices. Kill generic logins such as 'accounts@' that five people share.
- Website hygiene: update WordPress core and plugins, delete what you don't use, and put MFA on the admin panel.
- Secure configuration: change default passwords and close admin ports and panels that face the internet.
- Logging and alerts on new sign-in locations, new mailbox forwarding rules and admin changes, kept for at least 90 days.
Where should a small team start this month?
Do it in order of cost to the attacker. Week one, MFA on every email and admin account and a quick look at who still has access. Week two, turn on automatic updates and clean up the website plugins. Week three, set up the offsite backup and actually restore something from it. Week four, alerts and a short phishing talk with the team.
Where your servers live matters less than how they're run. We compared local and global hosting in Hosting from Nepal: local data centre vs AWS, Azure, GCP; the DataHub case is a reminder that concentrating many businesses in one provider also concentrates the risk. If your systems need to stay up through an incident, our high-availability re-architecture blueprint shows how redundancy and tested recovery fit together. And security logging doesn't have to blow up your bill; the same tagging and alert habits from FinOps for small teams apply.
How can NeuralYug help?
We set up and run cloud infrastructure for Nepali and international teams, and these ten controls are the baseline we put in place on every project. If you'd like a plain-language check of where your business stands, talk to us or see our cloud and DevOps service.
Sources
Frequently asked
What is the single most useful security step for a small business in Nepal?
Turn on multi-factor authentication for email and for every cloud admin account, using an authenticator app rather than SMS where you can. Stolen or reused passwords show up somewhere in the attack chain in roughly two in five breaches in Verizon's 2026 DBIR, and a second factor stops most of those logins cold. It costs nothing on Google Workspace or Microsoft 365.
How much does basic cybersecurity cost a Nepali SME?
Much less than people expect. MFA, patching, least privilege and offboarding are mostly free settings plus a few hours a month. A business password manager and an offsite backup copy typically add a few dollars per user or per month. The expensive items, like 24/7 monitoring or a security operations centre, are rarely where a 10 to 50 person firm should start.
What should I do in the first hour after a breach?
Isolate affected machines from the network, but don't wipe them. Reset passwords and sign out all sessions for affected accounts, starting with email and admin logins. Call your bank if payments may be at risk. Report to the Nepal Police Cyber Bureau, keep logs and screenshots, and check your duties to notify affected people under the Privacy Act before you restore from a clean backup.
Want this run on your numbers?
We'll do the same analysis on one of your workflows in the two-week Automation Sprint.
Related service · Cloud & DevOps