


The ICT Division has declared Chattogram Port Authority (CPA) a "Critical Information Infrastructure" (CII), placing the country's main trade gateway under state cyber security protection.
The designation, issued Tuesday under Section 15 of the Cyber Protection (Amendment) Act, 2026, follows a detailed assessment of the port's digital systems. CPA becomes the 36th organization in Bangladesh to receive CII status.
CPA Secretary Refayet Hamim said the port handles most of the country's import-export activity, making its container, shipping, customs, revenue and supply-chain systems vital to national security and the economy. "Any cyberattack could directly hit trade, industry and public life," he said, explaining the reasoning behind the decision.
With CII status, CPA's entire IT infrastructure data centers, communication systems, databases and APIs now falls under stricter cyber security rules. The port must run a 24/7 Security Operations Center and Cyber Incident Response Team, conduct annual audits, share regular reports with national cyber agencies, perform risk and vulnerability tests, keep encrypted offline backups, and maintain tested disaster-recovery plans. Any breach of these rules or unauthorized access will now be treated as a criminal offense.
CPA has already formed a cybersecurity team, mapped its digital assets, updated security policies and begun staff training in line with government directives.
CPA Chairman Rear Admiral SM Moniruzzaman said rising digitalization brings rising cyber risk and the port will follow international standards and strengthen its defenses accordingly. He added that ICT Division, the National Cyber Security Agency and other stakeholders will jointly build a secure, resilient digital port system benefiting importers, exporters, shipping agents and other users through safer more reliable services.