Sri Lanka’s Central Bank is recruiting a specialist to behave like a cybercriminal and deliberately attack its own defences. It sounds peculiar until one considers what happens if the real criminals get there first.
Somewhere in the Central Bank of Sri Lanka, somebody is about to be paid to try to break in.
Not through the front door. Not with a balaclava, a getaway car and a large bag marked “money”. The Central Bank is looking for a Red Team Specialist whose job will include simulating sophisticated cyberattacks against its systems, hunting for vulnerabilities and tracking threats before somebody with rather less honourable intentions finds them.
It is a three-year contract and the successful applicant will be expected to conduct intelligence-led attacks and proactive threat-hunting operations. The work extends beyond attempting to penetrate the Central Bank’s own defences to monitoring ransomware groups, phishing operations and fraud campaigns, including activity on the dark web.
For anyone unfamiliar with cybersecurity terminology, a red team is essentially paid to think like the enemy.
Instead of waiting for an attacker to discover that a door has inadvertently been left open, the red team tries every door itself. It probes networks, looks for weaknesses, tests human behaviour and attempts to replicate the techniques that a sophisticated criminal organisation might use in a genuine attack.
The objective is not to demonstrate that a computer can be hacked. Almost anything can eventually be attacked. The objective is to discover weaknesses while the person exploiting them is still working for you.
That is increasingly important because the modern financial system barely resembles the banking system many Sri Lankans grew up with.
Money now moves continuously through mobile applications, online banking systems, payment gateways, card networks and instant electronic transfers. Government itself is pushing citizens towards digital transactions, while banks are steadily reducing dependence upon physical branches and paper.
Convenience has increased enormously. So has the potential attack surface.
A robber entering a bank branch once had a fairly obvious limitation: he could steal only what was physically available. A successful cyberattack can potentially reach systems processing enormous volumes of transactions without the attacker ever setting foot in Sri Lanka.
The criminals have changed too.
Cybercrime is no longer necessarily a teenager experimenting from a bedroom. Sophisticated groups operate ransomware businesses, sell stolen credentials, create industrial-scale phishing campaigns and trade access to compromised computer systems. Artificial intelligence is making impersonation, fraud and social engineering still easier.
Financial institutions are particularly attractive targets because that is where the money is. Central banks carry an additional attraction because of the financial infrastructure and information surrounding them.
Sri Lanka therefore has good reason to take the threat seriously.
The more interesting question is whether the rest of the State is doing the same.
Sri Lanka is simultaneously attempting to digitise taxation, government payments, identification, licensing and numerous other interactions between citizen and State. Every new digital service creates efficiencies, but every database and connection also creates something that has to be protected.
Cybersecurity cannot be added after digitisation like a lock fitted to a door after the house has been built. It has to be part of the architecture from the beginning.
The Central Bank’s decision is therefore worth watching beyond the recruitment of one specialist.
There is a useful humility contained within red-team thinking. Instead of assuming your security works because nobody has successfully attacked you yet, you actively try to prove that it does not.
That is a considerably safer approach.
Because the worst possible time to discover that your cybersecurity system has a hole in it is immediately after somebody has climbed through.


