Why keeping data in Bangladesh is not enough to ensure security
A properly designed and operated data centre in Bangladesh can be extremely secure, but the assumption that physical location itself provides that security is a matter of concern
Whenever data sovereignty comes up in Bangladesh, the conversation seems to reach the same conclusion: keep the data inside the country. It sounds sensible. If the servers are here, the data is here, and therefore we have control over it.
But we might be asking the question in the wrong order.
The 2016 Bangladesh Bank cyber heist is an uncomfortable example. The attackers did not need to enter Bangladesh Bank or steal its servers. According to the US Department of Justice, they compromised the bank's network, gained access to computer terminals connected to SWIFT, and used that access to send fraudulent payment instructions.
Bangladesh Bank lost $81 million. The infrastructure was physically in Bangladesh, yet that did not prevent attackers elsewhere from gaining access to the systems that mattered.
I am not using this example to argue that local data centres are insecure. A properly designed and operated data centre in Bangladesh can be extremely secure, and there will be systems for which keeping infrastructure under direct national control is entirely sensible. What concerns me is the assumption that physical location itself provides that security.
Put a badly secured application inside the best data centre in Dhaka and it is still a badly secured application. Give administrators excessive access, fail to protect credentials, neglect security updates or expose vulnerable systems to the internet, and the address of the building will provide little comfort when something goes wrong.
This is where our discussion of sovereignty gets muddled. When someone says that data must remain in Bangladesh, I want to know what concern we are actually trying to address. Are we worried about foreign jurisdiction? Are we worried about unauthorised access? Do we need the system to continue operating if an external supplier or international connection becomes unavailable? Or is there a regulatory reason the information itself must physically remain here?
All of those can be legitimate concerns. They are also different concerns, and do not necessarily have the same technical answer.
Physical location matters. So does jurisdiction. So do encryption, identity controls, monitoring, recovery, administrator access and the design of the application itself. The UK's National Cyber Security Centre, for example, treats physical location and legal jurisdiction as considerations alongside data-centre security, encryption and resilience. It also notes that jurisdiction can be more complicated than simply identifying the country where the storage happens to sit.
Cloud computing sometimes gets presented as though it eliminates these problems. It does not. A badly configured cloud environment can expose sensitive information just as effectively as a badly configured local system. There is no technology that removes the need for competent security.
But the opposite assumption, that information becomes inherently less secure once it is stored outside a locally owned data centre, is equally unhelpful. Modern infrastructure can encrypt stored data, tightly control privileged access, record administrative activity and distribute systems so that the failure of one facility does not necessarily destroy the service. None of this makes the cloud automatically secure, but neither should those capabilities be ignored simply because the underlying machines are somewhere else.
Put a badly secured application inside the best data centre in Dhaka and it is still a badly secured application. Give administrators excessive access, fail to protect credentials, neglect security updates or expose vulnerable systems to the internet, and the address of the building will provide little comfort when something goes wrong.
What concerns me more is that we often start debating the infrastructure before properly discussing the information.
Before deciding that a particular system needs sovereign infrastructure, I would first ask what is actually sitting on it.
Some government information is already public. Laws, notices, public statistics, government websites and open datasets obviously need protection from tampering, but confidentiality is not the main concern. If someone changes an official document or falsifies a government dataset, that can still cause serious damage. The risk is different, not absent.
Then there is the much larger middle ground. Government departments hold internal documents and administrative records. Banks hold financial information. Hospitals hold medical records. Tax authorities hold information most people would reasonably expect to remain private.
These deserve much stronger protection, but even here I am not convinced that "sensitive" should automatically mean "sovereign".
A person's tax return is sensitive. Their medical history is sensitive. Their bank balance is sensitive. Losing any of these could cause real harm. But compromising them is still a different kind of national risk from compromising a central bank settlement platform, a military system or infrastructure whose failure could materially disrupt the country.
That distinction matters because otherwise almost everything eventually becomes critical.
At the far end are systems where Bangladesh should be extremely demanding about sovereign control. Some central banking systems, defence and intelligence workloads, and parts of critical national infrastructure may reasonably require domestic residency, strict control over administrators and encryption keys, independent recovery arrangements and the ability to continue operating without depending entirely on an external provider.
There will be disagreements about exactly where those boundaries belong, and there should be. What matters is that we have the boundaries.
Bangladesh Bank's own Guidelines on Cloud Computing already recognise the importance of classification. Financial organisations are required to classify data before moving it to the public cloud and to consider confidentiality, integrity, availability, business justification and the protection of personal information. The guideline also places tighter restrictions on financial and other sensitive customer data being hosted in cross-border public clouds, except in exceptional cases with prior approval.
I think there is an opportunity to build on that thinking rather than reducing the debate to whether cloud should be allowed.
For any important system, three questions reveal a great deal. What happens if someone sees information they were not supposed to see? What happens if someone changes it without us noticing? And what happens if the system is unavailable when we need it?
The answers can be very different.
A public database may contain no secrets, but quietly altering its contents could be extremely damaging. An emergency system may contain relatively little confidential information but may need to remain available during a national crisis. A database containing citizens' financial records may place confidentiality at the top of the list.
Once those risks are understood, the infrastructure conversation becomes much easier.
For some workloads, we may conclude that Bangladesh should retain infrastructure entirely inside the country. For others, commercial cloud may be perfectly appropriate. There will also be systems where a combination makes more sense than either extreme.
This is why I do not see the choice as one between sovereignty and cloud. I would be equally uncomfortable with a government blindly moving critical national systems onto foreign infrastructure simply because the cloud is fashionable.
The level of control should depend on the level of risk.
There is another uncomfortable issue in the sovereignty conversation. A data centre can be physically located in Bangladesh while depending on hardware manufactured abroad, software developed abroad, networking equipment from foreign vendors and security products maintained by companies outside the country. That does not make the data centre a bad investment. It simply shows why technological sovereignty has never been as simple as owning the building.
Real control comes from understanding our dependencies and deciding which ones we can tolerate. It comes from having people capable of operating and securing the systems, knowing who can access them, being able to recover when something fails and retaining options when a supplier no longer meets our needs.
Bangladesh should absolutely be cautious about where its most important information is kept. But we should be just as cautious about assuming that a server becomes secure because it has crossed the border into Bangladesh.
For some data, keeping it here will be the right decision. For some, it will make little difference. What matters is that we can explain why.
Md Mabrur Husan Dihyat is a London-based Cloud Operations Architect at Amazon Web Services (AWS) who advises the UK central government.
Disclaimer: The views and opinions expressed in this article are those of the author and do not necessarily reflect the opinions and views of The Business Standard.
