Most small business owners in Nepal think of cybersecurity as something only banks and big companies need to worry about. That assumption is exactly why small businesses have become such a frequent target — fewer defenses, the same valuable customer data, and an owner who's usually too busy running the business to think about a firewall. This guide covers what actually matters: the real threats hitting Nepali businesses right now, the actual law you're operating under (not the law that's still sitting in Parliament), and a practical, non-technical set of steps any small business can implement without hiring a dedicated IT security team.
1. The Threats Actually Hitting Nepali Businesses
Before discussing protection, it helps to know what's actually happening, based on patterns the Nepal Police Cyber Bureau and cybersecurity researchers have flagged as most common in 2026.
![]() |
| Cybersecurity Basics Every Nepali Small Business Should Know in 2026 |
๐ณ Payment Gateway Fraud
Online fraud involving mobile payment apps is currently the single most prevalent reported crime type in Nepal — directly relevant to any business accepting digital payments.
๐ฃ Phishing & Vishing
Fake emails and phone calls impersonating banks or known contacts remain extremely common, with voice-based phishing (vishing) disproportionately affecting areas with lower digital literacy.
๐ Data Breaches
Nepal has real precedent here — the 2023 breach of the Ramailo app exposed personal data for thousands of users after a hacker leaked the database on a dark web forum.
๐ฆ Ransomware
Increasingly targets businesses directly — locking critical files and demanding payment, often in cryptocurrency, to restore access.
2. The Legal Framework You're Actually Operating Under
This is where a lot of online content gets Nepal's cybersecurity law wrong, so it's worth being precise. As of mid-2026, here's the actual, current state:
| Law | Status | What It Covers |
|---|---|---|
| Electronic Transactions Act 2063 (2008) | In force | The foundational cyber law — legal recognition of electronic records and digital signatures, and the primary basis for prosecuting cybercrime |
| Individual Privacy Act 2075 (2018) | In force | Establishes obligations around collecting, storing, and sharing personal information, grounded in Article 28's constitutional privacy protection |
| National Cyber Security Policy 2023 | In force (policy, not law) | Strategic framework guiding government cybersecurity priorities — not directly enforceable against businesses |
| IT and Cyber Security Bill 2082 | Draft — not yet law | Would establish a dedicated Cyber Security Agency, mandatory breach notification, and a modernized framework — still pending in Parliament |
3. What the Current Law Actually Requires of You
- If you post or publish content online, you're subject to the ETA's provisions — defamatory, false, or harmful content can carry criminal liability, including for businesses managing their own social media presence.
- If you collect customer data (names, phone numbers, payment details, addresses), the Individual Privacy Act places legal obligations on you around consent, storage, and sharing — collecting or sharing personal information without consent is a legal risk, not just a best-practice violation.
- If your business experiences a breach or hack, mandatory breach notification is not yet legally required — but legal specialists still recommend voluntary disclosure to affected customers, since transparency is viewed favorably and reduces future legal exposure.
- Corporate liability is real: under the ETA, chief executives or responsible officers can be held personally liable for offenses unless they can demonstrate a lack of knowledge or negligence.
4. Five Practical Steps That Cover Most of Your Real Risk
You don't need an enterprise security budget to meaningfully reduce your risk. These five steps address the threats most likely to actually affect a small Nepali business:
- 1Use unique passwords and enable 2FA everywhere. Every business email, banking portal, and social media account should have a distinct password and two-factor authentication turned on — this single habit blocks the majority of account takeover attempts.
- 2Verify payment requests through a second channel. If a "client" or "supplier" emails asking to change payment details, confirm by phone before sending money — this single check defeats most business email compromise scams.
- 3Back up your data somewhere offsite, and actually test the restore. A backup that's never been tested isn't a real backup — make sure you can genuinely recover from it before you need to.
- 4Get clear consent before collecting customer data. A simple, visible statement on your order form or signup page about what data you collect and why satisfies the basic spirit of the Individual Privacy Act and builds customer trust.
- 5Know the Cyber Bureau reporting process before you need it. Knowing in advance how to file a complaint with the Cyber Bureau of Nepal Police saves critical time if your business is ever actually breached.
5. What to Do If Your Business Is Actually Breached
| Step | Action |
|---|---|
| 1. Contain | Disconnect affected systems immediately to stop further data loss or spread |
| 2. Assess | Determine what data and how many people were affected |
| 3. Document | Preserve evidence — screenshots, logs, timestamps — before anything is altered or deleted |
| 4. Notify | Inform affected customers where feasible, even though it's not yet a strict legal requirement |
| 5. Report | File with the Nepal Police Cyber Bureau if criminal activity is suspected — this initiates the formal FIR and investigation process |
| 6. Remediate | Fix the underlying vulnerability before reconnecting affected systems |
6. Sector-Specific Notes Worth Knowing
- If you handle online payments: Nepal Rastra Bank has issued sector-specific cybersecurity directives for financial institutions and payment service providers — if your business processes payments directly rather than through a registered gateway, check whether these obligations extend to you.
- If you operate any kind of online platform with user accounts: the Social Network Directives and related registration requirements may apply depending on your platform's nature and scale — this is a fast-evolving area worth periodic legal review.
- If you're an e-commerce business: the E-Commerce Act 2025 establishes specific obligations relevant to online retail, separate from the general cyber law framework.
Frequently Asked Questions
What is the main cyber law that applies to small businesses in Nepal?
The Electronic Transactions Act 2063 (2008) remains the primary and operative cyber law in Nepal as of 2026. A proposed IT and Cyber Security Bill 2082, which would establish a dedicated cybersecurity regulator and mandatory breach notification rules, remains a draft bill pending in Parliament and is not yet enacted law.
Is a small business in Nepal legally required to report a data breach?
Mandatory breach notification is not currently established as law in Nepal. However, legal specialists recommend businesses voluntarily contain the breach, assess its scope, notify affected individuals where feasible, and report to the Nepal Police Cyber Bureau if criminal activity is suspected, since transparency is viewed favorably and may reduce legal exposure if formal breach notification rules are enacted later.
What is the most common type of cybercrime affecting Nepali businesses?
Online fraud involving mobile payment gateways is currently reported as the most prevalent type of cybercrime affecting individuals and businesses in Nepal, ahead of identity theft through phishing and the hacking of government and private sector websites.
Does Nepal have a dedicated authority for handling data protection complaints?
No, Nepal does not currently have a dedicated data protection authority. Cybercrime complaints, including those involving data breaches, are handled by the Cyber Bureau of Nepal Police under the Electronic Transactions Act, while the Individual Privacy Act 2075 sets data protection obligations without a specialized enforcement body of its own.
Final Thoughts
The gap between Nepal's current cyber law and the actual sophistication of modern threats is real — a 2008 statute is doing a lot of work in a 2026 digital economy. But that gap doesn't mean small businesses are defenseless; it means the basics matter even more than they would in a more heavily regulated market. Unique passwords, two-factor authentication, a verified payment process, and a tested backup will protect your business against the overwhelming majority of incidents that actually happen — regardless of which version of the law is currently in force.
This article is for general informational purposes only and does not constitute legal advice. Nepal's cybersecurity and data protection legal framework is actively evolving, including pending legislation that may change businesses' obligations once enacted. Consult a qualified advocate for guidance specific to your business and current legal requirements.
Discussion