Friday 9th October 2026
×
Friday 9th October 2026
×
गृहपृष्ठ ∕ Breaking ∕ When Nepal Goes Offline

When Nepal Goes Offline

Building Digital Resilience Against Cyberattacks, Floods and Earthquakes


Ireland, October 9 – Imagine waking after a night of relentless rain to find that the road out of town has vanished. The electricity is down. Mobile calls connect only after repeated attempts, then drop. Families cannot reach relatives. A shopkeeper’s QR payment will not work. A hospital has backup power but a service it relies on is unreachable. Government portals and identity checks begin to fail just when citizens need help most.

This is not a description of one disaster. It is a plausible chain of events in a country that is rapidly moving public services, payments and records online. Nepal now faces a question that deserves the same urgency as digitisation itself: what happens when the country needs its digital systems most but those systems are also caught in the emergency?

The answer is digital resilience: the ability to limit disruption, keep essential services operating, restore them in a planned order and communicate when normal channels fail.

A flood becomes a communications crisis

The recent Bhotekoshi floods offered a warning. Floods and landslides damaged telecommunications infrastructure across Rasuwa, Nuwakot and Dhading. Nepal Telecom reported major damage to 83 mobile towers while Ncell said 27 sites were affected. At Timure, a tower and more than 60 kilometres of optical fibre were washed away.

Yet technical restoration did not always mean dependable service. Residents reported calls requiring repeated attempts, dropping midway or carrying poor audio. Damaged roads made equipment movement difficult. Satellite phones and internet terminals were deployed while generators supported towers where electricity transmission had failed.

A signal icon is not the same as reliable communication for a family searching for someone, an official coordinating shelter or a rescue team in unstable terrain.

The floods also revived concern about a disaster communication plan drafted after the 2015 earthquake but not implemented before the recent emergency. Such plans matter only when alternative links, equipment, contacts and restoration priorities are tested in advance.

An unfinished lesson from 2015

The 2015 earthquake showed how quickly buildings, roads, electricity and communications can fail together. Nepal is now far more digitally dependent. A future earthquake could affect data centres, government offices, telecom networks and recovery staff just as demand for public services surges.

An earthquake does not distinguish between physical infrastructure and digital infrastructure. Modern public services depend on both.

A recovery facility offers little protection if it shares the main site’s hazard zone, electricity supply, fibre route, administrators, identity platform or provider. Two buildings do not create resilience if one event can disable both.

The hidden chain behind a digital service

Nepal’s digital transformation has brought real benefits. Citizens use the Nagarik App and online portals. Passport, tax, revenue and administrative services rely on information systems. Banks, mobile wallets and QR payments support commerce, while hospitals, schools, municipalities and emergency agencies increasingly depend on connected services.

The argument is not against digitisation. It is against building essential services on assumptions that may collapse in an emergency.

A government website may remain online while citizens have no electricity or mobile data. A bank’s servers may be functioning while its customers cannot connect. A hospital may have a generator but lose access to identity, laboratory, supplier or payment systems hosted elsewhere. A municipality may have staff ready to respond but no working communications link to the centre.

These are cascading failures. Each organisation may retain some technical capability while the public service stops working. Nepal must assess the complete chain: electricity, towers, fibre, data centres, identity, payments, suppliers and staff.

More than a cyberattack

Cyberattacks are one route to disruption, not the only one. Ransomware can lock systems, destructive malware can erase data, denial-of-service attacks can overwhelm portals and stolen credentials can hand control to an attacker.

The planning questions should remain simple: which essential service could be lost, what does it depend on, how quickly must it return, which service should recover first, and what usable alternative exists until then?

A backup is not a recovery plan

Many institutions say they have backups. The harder question is whether those backups can be restored when staff, power and connectivity are under pressure.

A useful backup must be current, protected from ransomware and separated from the primary environment. Important data should include offline or immutable copies. Restoration must be tested. Staff need clear procedures, defined recovery times and an agreed restoration order.

Geographic separation must be real. A recovery site that shares the same grid, fibre corridor, floodplain, seismic exposure, administrators or cloud account may fail with the primary site. Distance alone proves little. What matters is whether the two environments share the same points of failure.

Nepal does not need an expensive duplicate of every system. Investment should follow risk. Emergency communications, electricity, telecoms, hospitals, payments, identity and relief platforms need stronger continuity arrangements than services that can remain unavailable for longer. Important suppliers should also support incident reporting and recovery testing.

Digital resilience must include people

Digital continuity is also about inclusion. People may lose phones, documents, electricity or connectivity. Elderly citizens, people with disabilities and remote communities may be unable to use digital-only services. Online verification may fail when treatment, relief or money is urgently needed.

Essential services should retain emergency alternatives, including offline verification, temporary credentials, controlled manual procedures, radio and SMS announcements, local notice points, telephone lines and controlled alternatives when normal digital payments are unavailable.

This is not a return to paper government. It is recognition that making one digital channel the only channel can turn a technical outage into exclusion from essential services.

Standards can help, but Nepal must adapt them

Nepal need not design every requirement from scratch. The NIST Cybersecurity Framework 2.0 structures cyber-risk work around governing, identifying, protecting, detecting, responding and recovering. ISO 22301 provides a framework for planning, operating, reviewing and improving business continuity.

Turning policy into operational coordination

Nepal is not starting from zero. Its National Cyber Security Policy 2023 recognises the country’s digital dependence and the need for reliable, secure systems. The policy envisages a 24-hour National Cyber Security Centre, national and sectoral response arrangements, incident reporting, continuity planning and regular cyber exercises involving critical service providers.

The urgent task is to convert policy into rehearsed capability. A national disruption will cross organisational boundaries, requiring government, disaster authorities, telecom and electricity providers, banks, hospitals, security bodies, suppliers and all three levels of government to act together.

Nepal therefore needs a strengthened national incident-coordination mechanism that operates around the clock, even when offices, networks or power supplies are disrupted. It needs clear reporting routes, named decision-makers, fallback communications, shared situational awareness and predetermined service-restoration priorities. The National Cyber Security Centre should be closely linked with disaster authorities and critical-service institutions, not activated as an isolated technical body after systems fail.

A practical resilience agenda

Nepal should identify digital services whose loss would threaten life, public safety, economic activity or government, then map the infrastructure, suppliers and people behind them. Apparently separate systems may share one data centre, fibre route, identity platform, cloud account or technical team.

Critical operators should maintain tested continuity and recovery arrangements. Recovery facilities should avoid the same flood, seismic, power and connectivity risks as primary sites. Backups require protected copies and demonstrated restoration, while essential public services need limited offline procedures.

Nepal should test compound emergencies rather than tidy, single-cause scenarios. An exercise combining a flood or earthquake with telecom failure, ransomware and false information would reveal whether public authorities and private operators can exchange information, prioritise restoration and issue one trusted message.

The government should also publish a simple public continuity plan. Citizens need to know where verified emergency information will appear, what alternatives exist when a service is unavailable and which channels they can trust.

The test is the worst day

Nepal should continue expanding digital services. But progress must also be measured by whether essential services remain accessible, trustworthy and recoverable during the country’s worst days. Floods, earthquakes and cyberattacks begin differently, yet they often expose the same weaknesses: concentrated infrastructure, shared dependencies, limited alternatives and recovery plans that have never been tested.

The true test of a digital nation is not how smoothly it works on an ordinary morning. It is whether it can still serve its people when the road is gone, the power is out, the network is failing and reliable information matters most.

Suman Tiwari is an Ireland-based cybersecurity professional and writer focusing on cybersecurity, emerging technology and public policy.





Write your comments