By: Staff Writer
September 28, Colombo (LNW): Sri Lanka’s rapid shift towards digital Government payments is creating a potentially important transformation in how citizens interact with the State. GovPay, officially launched in February 2025, is increasingly becoming a common gateway for payments to Government institutions. But as the platform expands, its greatest vulnerability may not necessarily lie inside the central payment infrastructure. It could emerge at the points where citizens, Government websites, officials and digital applications connect with it.
The attraction of GovPay is obvious. Instead of developing separate payment gateways for every Government department or Local Government authority, a common platform allows citizens to use internet banking, mobile banking and fintech applications to make payments. The relevant institution receives the funds, while the payer receives an electronic confirmation. Government agencies can also monitor payments through a central portal.
This creates more than convenience. Digital transactions generate records that can potentially strengthen financial accountability and improve revenue monitoring. For Local Government institutions in particular, transaction data could provide information about payment patterns, collection gaps and services generating weaker revenues. That makes GovPay potentially relevant not only to digitalisation but also to public-sector financial management.
The system is operated by LankaPay, which says GovPay follows recognised security frameworks including PCI DSS and ISO 27001, while operating under Central Bank-related requirements. LankaPay is responsible for the platform’s architecture, infrastructure, transaction processing and security. GovTech Sri Lanka, meanwhile, has assumed responsibilities previously associated with ICTA.
Hitherto this centralised architecture produces a paradox: the stronger the platform becomes, the more attractive the surrounding ecosystem becomes to criminals.
Cybersecurity specialist Lakmal Embuldeniya points to Government websites and other citizen-facing systems as potentially weak links. A secure central payment platform cannot fully protect a citizen who reaches it through a compromised Government website. If attackers manipulate a website, alter payment information or create a convincing imitation, the citizen could unknowingly transfer money to a fraudulent destination.
Smaller public institutions may face particular difficulties because their websites and cybersecurity capabilities may not match those of major financial institutions. The threat therefore extends beyond technology to staff awareness and public behaviour.
The emerging challenge is consequently one of building a secure digital ecosystem, rather than merely securing GovPay itself. Public awareness about legitimate payment addresses, verification procedures and fraudulent websites must accompany technical safeguards. Experts have even warned about deceptive URLs using visually similar Unicode characters, making fake addresses difficult for ordinary users to identify.
GovPay can make public payments faster, traceable and potentially more accountable. But its success will ultimately depend on whether Sri Lanka secures every link in the chain—not just the central payment engine.
