digital safety at the riverside ghat ai generated
Madhesh Nepal Top Stories

Beyond Translation: Making Cybersecurity Advice Accessible in Nepal’s Madhesh By Suman Tiwari

digital safety at the riverside ghat ai generated

Suman Tiwari

A warning that people cannot easily find, understand or act upon is unlikely to provide much protection. As digital fraud becomes a growing concern across Nepal, cybersecurity advice matters not only because it is published, but because people can find, understand and use it.

Banks, telecommunications providers and public-awareness organisations in Nepal are already making efforts to address digital risks. They publish fraud-prevention advice, explain online threats and conduct educational campaigns. These initiatives deserve recognition.

But can people find this advice, understand it and use it when a suspicious message or fraudulent call arrives?

For a multilingual region such as Madhesh, answering that question involves more than translating cybersecurity terminology. It requires examining how warnings are written, where they are distributed, whether they reflect familiar situations and how institutions assess whether their messages are understood.

Guidance Exists, but Its Presentation Varies

A review of publicly available cybersecurity information from selected Nepali banks and telecommunications providers reveals considerable differences in communication formats.

Siddhartha Bank, for example, publishes an English-language article explaining common banking frauds, including phishing, impersonation and attempts to obtain sensitive banking information. Its guidance includes practical precautions and steps customers can take when they suspect fraud.

Nepal Bank Limited also provides online security information, including advice about protecting one-time passwords and recognising suspicious activity. Global IME Bank has published guidance on online banking fraud, addressing suspicious links, account monitoring and stronger authentication.

These examples demonstrate that consumer-facing cybersecurity advice is being produced. They also illustrate why presentation matters.

Some guidance explains familiar situations in straightforward language. Other material introduces technical expressions such as two-factor authentication, malware or encryption. There is nothing wrong with these terms, but they work better when explained through simple, familiar examples.

Telecom providers show another side of the issue.

Ncell publishes a dedicated cybersecurity and privacy advisory covering passwords, suspicious links, software updates and personal-information protection. Nepal Telecom also provides security-relevant information, including instructions concerning OTP confidentiality, identity verification and reporting unauthorised activity. However, some of this information appears within service guides or terms and conditions rather than standalone awareness material.

Both approaches have value. Yet someone searching for advice after receiving a suspicious message may find a short, clearly labelled warning easier to use than a lengthy operational document.

The question is therefore not simply whether information has been published. It is whether people can recognise it as relevant, locate it quickly and act on it confidently.

Accessibility Goes Beyond Language

Translation is an important part of accessibility, but it is not the whole solution.

Even advice written in someone’s preferred language can be difficult to use if it is filled with technical terms or vague instructions.

Consider a common warning: never share your OTP.

That instruction is useful, but a more complete message would explain what an OTP is, why criminals ask for it, how a fraudulent caller might impersonate a bank employee and what the customer should do if the code has already been disclosed.

Similarly, telling people to avoid phishing links is less helpful than showing how a fake delivery notification, banking alert or payment request might appear.

Useful public guidance should answer four practical questions: What is the danger? How can I recognise it? What should I do? Where can I seek help?

These questions matter regardless of whether the message is delivered in Nepali, English, Maithili, Bhojpuri or another language.

Why Madhesh Offers an Important Perspective

Madhesh offers a particularly useful lens because it is linguistically diverse and already has established regional-language media networks.

Maithili and Bhojpuri are used across different communities, alongside Nepali and other languages. Public communication that accounts for this diversity can consider not only written notices but also audio messages, community radio, short videos and locally familiar examples.

There are already examples of educational outreach through regional languages.

GoGo Foundation’s Appan Shikshya programme has used Maithili-language radio broadcasts through FM stations in districts including Dhanusha, Mahottari and Siraha. The United Nations has also documented life-skills educational outreach using Maithili, Bhojpuri and Bajjika.

These programmes are not evidence of cybersecurity instruction. Their significance lies elsewhere: they demonstrate that regional-language educational communication channels exist and have been used for public-interest messaging.

Such experience may offer lessons for institutions considering how to explain digital fraud through familiar communication formats.

A short radio segment explaining a fake banking call, for example, could be complemented by a mobile-friendly video showing the same scenario and a clear reporting instruction.

The objective would not be translation alone, but communication designed around the audience’s everyday experience.

What the Evidence Shows

A review of selected banks, telecom providers and regional-language programmes found cybersecurity guidance in different formats, alongside evidence of regional-language educational broadcasting.

The review also found examples of institutions reporting multilingual outreach. Kamana Sewa Bikas Bank Limited, for instance, reported distributing multilingual OTP-security awareness videos during Global Money Week 2026.

Although the bank announced multilingual awareness videos, the available information did not specify which languages were used, and the videos’ spoken content could not be independently verified.

Similarly, the review did not identify directly verifiable cybersecurity guidance in Maithili or Bhojpuri among the sources examined.

That finding needs context. It does not mean such guidance is unavailable elsewhere. Social-media posts, community broadcasts, printed material and locally distributed campaigns may not be readily discoverable through a limited public-source review.

Nor does the available evidence establish whether particular language choices affect fraud rates, public trust or the effectiveness of awareness campaigns.

These limitations raise a constructive question: how can organisations make their awareness efforts easier to discover, document and evaluate?

From Publishing Advice to Demonstrating Reach

A practical improvement would be for banks, telecom operators and relevant public agencies to maintain clearly identifiable cybersecurity-awareness sections on their websites and official channels.

These could bring together fraud warnings, short explanatory videos, reporting contacts and downloadable guidance, with available language versions prominently identified.

Institutions conducting multilingual campaigns could also publish basic information about the languages used, intended audiences, distribution channels and the types of fraud addressed.

This would make existing efforts easier for the public to find without requiring institutions to disclose sensitive information.

Where feasible, awareness programmes could go further by testing whether members of their intended audience understand the messages.

For example, after viewing a short fraud-prevention video, participants could be asked whether they can recognise the warning signs, identify an unsafe request and explain where they would report an incident.

That kind of feedback may tell institutions more than publication counts or social-media views. The real question is whether people can recognise danger and know where to seek help.

Community radio stations, schools, local organisations and financial institutions could also collaborate on practical messages that reflect familiar scenarios. The emphasis should be on simple explanations, clear protective actions and reliable reporting information.

None of these improvements requires assuming that existing campaigns have failed. They recognise that producing awareness material and demonstrating its usefulness are different tasks.

A Public-Safety Message Must Be Usable

Cybersecurity communication is most valuable when it helps someone make a safer decision at the moment that matters. Nepal’s existing guidance, awareness campaigns and educational initiatives provide a foundation for that work.

The next opportunity is to make those efforts easier to find, easier to understand and easier to evaluate. For Madhesh, that means considering regional languages, familiar media channels and locally relevant examples while recognising the communication already underway.

Across Nepal, the ultimate measure of cybersecurity awareness is not how many warnings are published, but whether people understand those warnings when a suspicious message arrives, a fraudulent caller phones or an unfamiliar link appears on a screen.

suman tiwari
Suman Tiwari
Ireland-based cybersecurity professional and writer

The author is an Ireland-based cybersecurity professional and writer. This commentary draws on a review of publicly available guidance from selected banks, telecommunications providers and regional-language educational initiatives. It does not claim to represent all cybersecurity-awareness material available in Nepal.

Leave a Reply

Your email address will not be published. Required fields are marked *