Cybersecurity Must Be a Core Priority in Digital Transformation, Says UNDP
Six billion people online is not a triumph if the systems they depend on can be kneecapped by one weak credential, one exposed service, or one neglected agency network.

A new analysis from the United Nations Development Programme Global Centre in Singapore says cybersecurity has to be treated as a core part of digital transformation, not a decorative control added after the launch party. That matters because governments and enterprises are still expanding digital IDs, payments, healthcare platforms, online learning, and public services faster than they are hardening the infrastructure beneath them.
Digital growth is widening the blast radius
The UNDP analysis frames digitalization as a genuine development engine. Mobile connectivity, telemedicine, online learning, digital public infrastructure, digital IDs, and payment systems are widening access to services and improving government efficiency, especially in rural and underserved areas.
That is the attractive side of the ledger. The less marketable side is dependency.
As systems become more interconnected, the attack surface expands. A breach no longer stays politely inside one database or one ministry. It can move laterally across shared networks, connected platforms, and common data systems. The result is not just stolen records. It is service disruption across sectors that were sold as “modernized” but often built on fragile assumptions.
The UNDP warning is blunt: cybersecurity is becoming a foundation for successful digital transformation. Not an IT line item. Not a compliance appendix. A foundation. If that sounds obvious, it is because the industry has spent years proving how often obvious controls are ignored.
The failure cases are already public
The analysis points to ransomware attacks on government systems in Sri Lanka and Costa Rica that disrupted essential services, including healthcare, taxation, and payroll systems. In some cases, losses reached millions of dollars per day. That is what digital dependency looks like when resilience is underfunded: citizens cannot access services, agencies cannot operate normally, and recovery becomes a national administrative problem.
The human cost is also not theoretical. The UNDP-cited analysis refers to a ransomware attack on a hospital in Düsseldorf that was linked to a patient death after systems were disabled and emergency care was redirected. It also cites attacks on energy infrastructure in Ukraine that disrupted electricity supply to hundreds of thousands of people.
These examples should kill the lazy distinction between “cyber incident” and “real-world impact.” There is no clean boundary anymore. A disabled hospital system is a patient safety issue. A compromised energy network is a public infrastructure issue. A government payroll outage is a social stability issue. The keyboard is just the entry point.
On the individual level, the source describes cybercrime at an industrial scale, with global scam losses estimated in the hundreds of billions to trillions of dollars annually and billions of phishing attempts occurring every day. Many are increasingly powered by artificial intelligence to improve deception and impersonation. That does not make AI the villain. It makes weak identity, weak verification, and weak user protection more expensive.
The practical test: build security before the ribbon-cutting
The UNDP argues that governments should integrate cybersecurity into national digital strategies from the outset. That includes national cybersecurity policies, stronger institutional capacity, and closing resource gaps in staffing, infrastructure, and funding.
For technology leaders, the lesson is narrower and more uncomfortable. Digital transformation programs should be judged not only by adoption, cost savings, and service reach, but by failure behavior. What happens when the identity layer is compromised? When a payment platform goes offline? When a hospital or tax system loses access? When one supplier becomes the pivot point into several agencies?
The current market is full of digital transformation noise. Separate reports and announcements point to continued investment in AI, platform modernization, financial services digitization, and AI data center growth. Fine. Capital is moving. Platforms are being built. Awards are being handed out. None of that changes the security math.
If cybersecurity comes after deployment, it is not strategy. It is cleanup.
The grim takeaway is also the useful one: every new digital public service, AI platform, payment rail, or connected data system should be reviewed as an attack vector before it is celebrated as progress. The organizations that do this early will still be attacked. The ones that do not are simply donating their transformation budgets to incident response.