Infrastructure–Governance Asymmetry and Cybersecurity Exposure in Nepal's E-Governance: A South Asian Comparative Study
This study identifies a critical "infrastructure–governance asymmetry" in Nepal's e-governance, where rapid digital infrastructure growth outpaces technical and operational cybersecurity capacity, creating exposure risks that legal frameworks alone cannot mitigate.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine a country building a new highway system. The roads are wide, the bridges are strong, and the traffic is moving faster than ever before. But if the traffic lights are broken, the police are understaffed, and the drivers have no map, the speed of the cars becomes a danger rather than a benefit. This is the core tension explored in a new study of Nepal's digital world. The research looks at how nations use technology to run their governments—what experts call e-governance. It examines two distinct things: the physical and digital tools a country builds, like internet connections and computer servers, and the human and legal systems needed to manage them safely, such as skilled workers, clear rules, and the ability to spot problems before they cause harm. The question driving this work is simple: as countries race to build more digital services, are they building the safety nets fast enough to match that speed?
A researcher at Softwarica College in Kathmandu, Ganesh Bhusal, decided to test this idea by looking closely at Nepal's own digital history. He gathered data from two major international organizations that track these trends globally. One set of numbers measures how well a country delivers services online, while the other measures how committed a country is to keeping its digital systems secure. By comparing these numbers over the last two decades, and by looking at real-world security breaches that happened in Nepal, the study reveals a surprising gap. The country has been incredibly successful at laying the digital groundwork. Between 2020 and 2024, the quality of its telecommunications infrastructure grew by more than sixty percent. However, the ability to govern those systems and involve citizens in the process did not keep up. In fact, the measure of how much citizens can participate in government decisions online actually dropped by forty percent during that same period. The researchers call this mismatch "infrastructure–governance asymmetry." It means the digital highway is being paved faster than the traffic rules and safety crews can be organized.
The study does not stop at just looking at Nepal; it places the country side-by-side with its neighbors in South Asia to see if this is a local problem or a regional pattern. The comparison shows that while India and Bhutan are also building their digital roads quickly, Nepal's gap between building and governing is wider than theirs. A particularly revealing finding comes from looking at how countries score on security. Nepal has very strong laws on paper. Its score for legal measures regarding cybersecurity is among the highest in the region, sitting right next to the top performers. Yet, when it comes to the practical skills needed to use those laws—like having the right technical tools and international cooperation to stop hackers—Nepal's scores are the lowest in the group. This suggests that having a law is not the same as having the capacity to enforce it. The study also found that other countries, like Pakistan and Bangladesh, have very high security commitment scores but relatively low levels of actual digital service development. This warns against assuming that a high score on a security checklist means a country is actually safe; it might just mean they have written good rules without the staff to follow them.
To understand what this gap looks like in real life, the researcher examined six specific security incidents that occurred in Nepal between 2020 and 2026. These events ranged from a major outage that shut down government websites and delayed international flights to hackers stealing millions of citizen records. A critical pattern emerged in how these problems were discovered. In almost every case, the government did not find the breach itself. Instead, the problems were revealed by outside groups, such as security researchers, foreign monitoring services, or the hackers themselves who advertised the stolen data. One notable case involved a government agency that only realized it had been compromised after joining an external service that tracks leaked passwords. This indicates that the internal ability to watch for trouble is weak. The government is relying on outsiders to tell it when its own systems are broken.
The study also looks at a new and rapidly growing trend: the use of artificial intelligence to write computer code for government systems. A state-owned company in Nepal has begun using AI tools to build working software in a matter of hours, a process that used to take weeks. While this speeds up development, it introduces a new risk. The government claims that human teams review and test this AI-generated code, but there is no public evidence showing what that review process looks like or who is responsible for it. The head of the national cybersecurity center has admitted that this rapid adoption creates "blind spots," where agencies build systems without fully understanding the security underneath them. The research does not claim that AI has caused a specific disaster yet, but it highlights a worrying reality: the speed of building software is increasing, while the speed of checking that software for safety is not clearly keeping pace.
Ultimately, the paper argues that the solution is not just to write more laws or build more servers. The data shows that Nepal already has strong laws and is building infrastructure at a record pace. The missing piece is the operational capacity to manage what has been built. The recommendations suggest that the country needs to invest heavily in training its own workforce to detect and fix security problems, rather than relying on outside help to find them. It also calls for a system where the speed of building new digital tools is matched by a verified, documented process for checking their safety. The study concludes that until the ability to govern and secure digital systems grows at the same rate as the systems themselves, the rapid expansion of e-governance will leave the country exposed. The road is being built, but the safety crew is still catching up.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.