Fauzia I Abro is an electronics engineer with a PhD in Information Security Engineering and a Master’s in Information Security and Cryptology. She is an associate professor and the director of the Cyber Security Distance Learning Programme at Royal Holloway, University of London. Abro is recognised by the Women’s Engineering Society (WES) as one of the Top 50 Women in Engineering in the UK and was named the Cybersecurity Woman of the Year 2025.
In a recent interview with Bonik Barta, she spoke about the critical necessity of building domestic “Made in Bangladesh” cyber defense frameworks, the urgent need to integrate cyber literacy into education, and the strategic risks of treating digital security as an afterthought in state infrastructure projects. Interview conducted by Minhazul Abedin.
Your career spans over two decades at the intersection of academia, industry and global AI governance. Given this unique vantage point, how have you seen the fundamental nature of national security evolve now that the primary battleground has shifted from physical borders to digital infrastructure?
Thank you. It’s a really interesting question. With my background working across academia, industry, and my own consultancy and businesses, I believe security requires a layered approach. It hasn’t completely changed, but the threat landscape obviously has, because of AI and technology.
Sometimes I feel technology is our biggest challenge. But again, we can’t rely on technology for complete defence; it cannot solve cybersecurity problems on its own. We need people who can actually solve these issues. That’s because the weakest link in cybersecurity is always the human element. No matter how strong technology or systems are, if people are not trained and do not know how to handle that technology, we don’t have any security.
Like many developing countries, Bangladesh is digitalising its public services. How can the state strike the right balance between expanding its digital platforms and ensuring security from the design phase, rather than treating cybersecurity as an afterthought?
I would say that because Bangladesh is expanding now, it has an opportunity to do it in a different way. Treating security as an afterthought is a flawed approach, yet many countries are doing exactly that — setting up the entire digital infrastructure first and only then thinking about how to implement security. That kind of security is not solid; it’s not going to work, really.
Instead, Bangladesh should adopt a “secure by design” philosophy. Whatever systems are being put in, make sure those systems are designed from the ground up as secure systems. They shouldn’t be treated as just standard IT systems, or just any router or computer. They must be secure by design, meaning the hardware itself is secure.
Security should be very much part of the initial negotiation and the initial selection of equipment. Those components should be secure by design from the very start.
Bangladesh Bank is strengthening the security of its SWIFT payment operations by introducing new anti-money laundering (AML) screening tools. Are such technological upgrades enough, and how should the central bank balance the adoption of global tools with the urgent need for domestic capability and training?
I would say again that security is always layered. We can’t secure our systems unless we approach them as a layered solution, because we cannot rely on a single element. Furthermore, whenever a country is outsourcing or purchasing security for its financial and critical systems, it is never fully secure. That will actually be making the state dependent on other nations and other people.
Bangladesh has a young population with so much energy and passion. I used to teach students from Bangladesh in London, and I could feel that they are full of spirit, resilience and the courage to achieve anything. I would say, instead of investing entirely in external systems, try to build your own.
Building systems nowadays does not mean reinventing the wheel; it is about innovation, customising the products, and simply making a start. Right now, it does not look like anyone is ready to take those risks. I would advise starting small, but trying to build your own domestic security framework — essentially, “Made in Bangladesh.”
Bangladesh has experienced several large-scale personal data leaks, including national identification (NID) data. Once sensitive citizen data has been compromised on a macro scale, what mitigation strategies should the government prioritise to secure the state against long-term national security vulnerabilities?
As an educationist, I would say capability building. This is the main weakness, because despite having such a large young population, digital literacy is at just 10 percent. I think it is very challenging.
Unless the government of Bangladesh invests in its people, in their digital literacy and in their digital education, it is going to be very hard, no matter how expensive or how strong the security systems put in place are. If people are not trained and do not have awareness, systems are always vulnerable.
It is not only about integrating tools, but also teaching people how to use them. That is the basic requirement. The government of Bangladesh has to invest in its people, and I have seen the resilience in the Bangladeshi people. I do not have any doubt that there is any shortage of resilience.
How should the government integrate cybersecurity into the national academic curriculum? At what specific grade or developmental stage should children begin learning about digital threats?
If you ask me, I would say from Year 1. This is because children are interacting with mobile phones and tablets from a very early age. Many of the mobile games they play are actually data-harvesting or surveillance applications, but children do not realise this. When they install a game, the app requests extensive device permissions.
Children are exceptionally vulnerable because they just want to play. Most of these games — especially if downloaded from third-party application stores — contain hidden backdoors. The game is essentially a Trojan horse. It asks for permission to access the camera, the microphone and the speakers. This means that without their knowledge, that phone can become a camera for an outside party 24 hours a day. Even when the camera or the microphone is not actively being used, the device can still monitor you.
It is an incredibly alarming reality. You could be at home with all the walls and curtains closed, yet someone is still monitoring the room.
Turning to enterprise trends, corporate entities are encouraging employees to leverage AI models. Yet many IT leaders hesitate due to fears over data leakage and privacy compromise. How should organisations weigh these critical cybersecurity risks against the broader strategic danger of delaying AI integration altogether?
AI has a lot of power, and it is expected that in just a couple of years, AI will be able to do almost any job better than a human. This means we have a very limited window right now.
This is precisely the time when Bangladesh and the wider economies have to speed up and actively adopt AI. The adoption of AI and the responsible use of AI are an absolute must right now.
It shouldn’t be a case of saying, “Okay, AI can leak data, or it can compromise privacy, so let’s just not use it.” It doesn’t work that way. Because if we are not using AI, and if we are not training our people to use it responsibly, we will simply be left behind.
Using AI responsibly is, of course, a big deal. But scammers are also using AI. Deepfake voice and video scams are also becoming more convincing every day. How concerned should governments and businesses be about this weaponised media, and what practical architectural safeguards would you recommend?
AI has been, and continues to be, a major challenge even for developed economies — it is not just a problem for Bangladesh. The UK, US, and Canada are all still struggling with how to handle this.
Look at AI usage in assessments, for example. I am running a distance learning program that is 100% online, with online exams that are not proctored; we don’t truly know if a student has used AI or not. We don’t have reliable tools to verify it. This is a challenge being faced right now even by the UK, the US, and Australia.
Ultimately, I think this issue has to be handled through proper governance and regulations. Right now, governments are not sufficiently involved; they have largely left citizens to use AI however they see fit. There needs to be clear governance and robust regulatory processes put in place to guide people on how, and to what extent, they can use AI.
Generative AI has hyper-charged the spread of misinformation on social media, which serves as a news source for a large portion of the demographic. How can a resource-constrained government realistically mitigate this automated information warfare?
It is incredibly challenging, and it comes down to awareness. The government cannot fully handle this problem through technical means alone. I cannot simply say, “Okay, just install a firewall or put specific tools and controls in place.” The problem cannot be completely addressed that way.
It requires awareness. The government has to educate its people on what the risks are. While there are benefits to AI, there are also significant risks — and right now, the risks can actually be greater than the immediate benefits.
People need to be trained on how to interact with these systems, and specifically, what kind of data they should or shouldn’t share with AI models and AI agents. Public awareness is the fundamental building block.
At an individual level, there remains a misconception that basic password hygiene equals complete personal security. But in the context of 2026, what steps should people take to make sure they are secure in cyberspace?
There are several very basic things that individuals can do. For example, wherever the facility is available, they should absolutely opt for multi-factor authentication. You should never depend on just a single password. It should ideally involve layers — such as a password or PIN combined with biometrics like a fingerprint. I am sure that in Bangladesh, banking applications utilise this, where someone enters a password or PIN, and then it prompts a secondary verification step. That represents two or three layers of security. Wherever possible, implement multi-factor authentication.
Furthermore, organisations should always patch their software and applications. Without updating or patching them, vulnerabilities are left exposed — and with AI, those vulnerabilities are incredibly easy to exploit.
AI has changed the landscape completely. Just imagine when quantum computing matures — if quantum computing and AI join forces, the current state of encryption will essentially be rendered obsolete.
Cybersecurity often struggles to attract sustained investment. How can policymakers effectively convince businesses and state planners to treat cyber resilience as an indispensable capital investment rather than just a compliance cost?
I believe the government has a major role to play here. They can ensure and enforce this transition through robust regulations. For example, Europe has the General Data Protection Regulation (GDPR). Because the penalties under GDPR are so severe, no organisation risks violating it.
Bangladesh and other countries need to implement similar, proper regulatory frameworks. There must be tangible penalties attached, because if companies do not face financial repercussions for failing to follow these regulations, they won’t comply. It is simply human nature — we rarely take risks seriously unless there is a direct financial cost involved.
If you were advising Bangladesh’s government today, what would be your top cybersecurity priorities over the next five years?
My focus has always been on education. That’s because I have seen firsthand that education has a transformative power. So, if you are asking me, my top priority is cyber education. We must ensure that every single citizen and every student understands cybersecurity.
And it is not only students — even women who are homemakers and may not know how to read or write need to learn about cyber safety, because they are also being targeted. In fact, they are often more vulnerable because they lack exposure to these risks. Therefore, widespread cyber education must be the top priority. Once the general public is aware, they can make informed decisions. Otherwise, no matter what tools are brought in, if people are untrained, they will still click on spam and fall for scams. So, public education and capability development are absolute priorities.
The second priority I would urge is to go for “Made in Bangladesh” solutions. Do not outsource security infrastructure to foreign nations. Relying entirely on external vendors is always a massive strategic risk. We have seen historical precedents in global conflicts where reliance on foreign-controlled communication lines and electronic equipment left a nation’s top leadership completely compromised and targeted. When a country relies entirely on external systems, it is unintentionally exposing its entire security apparatus to outside forces.
My core message to Bangladesh is this: invest heavily in education — specifically cyber education and AI. Artificial intelligence and cybersecurity represent the future. Investing in domestic capacity development is truly the most critical investment a government can make.