Evidence-based policy discussion
Analysis

A Treasury Hack, A Coal Deal – and a Hard Lesson We Can’t Ignore

The treasury cyber loss and coal deal expose governance failures. While current leaders must be accountable, past regimes were worse. The real lesson: choosing “better” wasn’t enough—Sri Lanka needs truly top-level competence to run a country.

Dr. Seneth Gajasinghe 24 Apr 2026 3 min read English
A Treasury Hack, A Coal Deal – and a Hard Lesson We Can’t Ignore

The recent loss of USD 2.5 million from a treasury-related cyber incident is not just a technical failure. It is a governance failure. And when placed alongside controversies like the coal procurement issues, a pattern begins to emerge — one that deserves calm, honest reflection rather than blind political loyalty.

First, let’s be clear: cybersecurity breaches of this nature do not happen in isolation. They are usually the result of gaps — in systems, in oversight, in accountability, and most importantly, in competence. Modern public finance systems operate in a high-risk digital environment. Basic safeguards, layered verification, and rapid response mechanisms are not optional luxuries; they are minimum requirements. When such a significant loss occurs, it signals that one or more of these layers failed.

Now consider the coal deal issue. While very different in nature, it similarly raised concerns about decision-making quality, transparency, and whether due diligence was adequately performed. Together, these incidents are not random — they point toward weaknesses in institutional judgment and execution.

It is reasonable, therefore, to hold the current administration accountable. These failures occurred under their watch. Appointments, oversight structures, and system readiness are ultimately their responsibility. When critical sectors like treasury operations and energy procurement show lapses, it reflects directly on governance standards.

However — and this is important — acknowledging these failures does NOT mean previous regimes were better alternatives.

In fact, history reminds us that poor appointments and questionable decisions were often worse in earlier administrations. There have been instances where key financial and administrative roles were filled based on political loyalty rather than competence, where oversight was weaker, and where systemic inefficiencies were normalized. Many of the structural weaknesses we see today are inherited, not newly created.

So what is the real lesson here?

The public made a correct and important shift by demanding more qualified, educated, and professional leadership. That expectation was valid — and necessary.

But these incidents show that we are still not there yet.

Even the current bench, despite being comparatively better in intent or profile, is not sufficiently equipped to handle the complexity and pressure of running a country in today’s environment. Governance today demands more than basic qualifications — it requires deep expertise, proven competence, systems thinking, and the ability to anticipate and manage risk at a very high level.

Running a country is not a symbolic exercise. It is not about titles, narratives, or perceived credibility. It is a high-stakes, technical, and unforgiving responsibility.

The treasury hack is not just about lost money. It is about lost confidence.

The coal issue is not just about procurement. It is about trust in decision-making.

If we reduce these to political arguments, we miss the point. The real takeaway is this:

We were right to demand better. But “better” is still not good enough.

Sri Lanka needs a level of governance that is not just improved from the past, but fundamentally stronger, sharper, and more capable — especially in times of crisis.

The next step for the public is not to retreat to old choices, but to raise the bar even higher.

Because if these incidents teach us anything, it’s this:

Competence is not relative. It is absolute.
And in governance, anything less comes at a cost.

Author
Dr. Seneth Gajasinghe
General Secretary, Idiripela