Cyber Warfare Threat Prompts Pakistan To Fast-Track Security Measures

سائبر سیکیورٹی خطرات کے پیش نظر 90 روزہ پلان منظور، وفاق کا سیکیورٹی اقدامات تیز کرنے کا فیصلہ

Cyber Warfare Threat Prompts Pakistan To Fast-Track Security Measures

The federal government has approved a 90-day Cyber Security Strategic Action Plan amid what the National Committee for Information and Communications Security (NCICS) described as a heightened cyber threat environment, with provinces being directed to accelerate the establishment of Computer Emergency Response Teams (CERTs) and implementation of the Pakistan Information Security Framework (PISF) 2026. According to senior official sources, the decision was taken at the second meeting of NCICS, held at the Cabinet Division under the chairmanship of the secretary, Ministry of Information Technology and Telecommunications, and NCICS chairman.

The need for practical and immediate measures was stressed in view of the growing cyber threat environment. The committee was informed that PISF 2026 had already been approved and that its implementation at both the federal and provincial levels must be ensured. The National Computer Emergency Response Team (nCERT), which heads the Cyber Security Working Committee, presented a comprehensive Cyber Security Strategic Action Plan focused primarily on measures to be undertaken within 90 days.

The plan covers governance, compliance, resource alignment, incident response and crisis management, cyber security assessment and supply chain security. The meeting was also informed that nCERT had prepared a National Cyber Security Handbook primarily for government officials. The chairman of the Pakistan Telecommunication Authority (PTA) stressed that the operationalisation of the Federal CERT required careful planning, particularly in the absence of sectoral and provincial CERTs, so that relevant ministries and departments could be efficiently integrated.

The National Computer Emergency Response Team said that a Managed Security Service Provider (MSSP) approach would be adopted and that provincial and sectoral CERTs would operate under nCERT and directly interact with their respective ministries and departments. Necessary guidelines for the operationalisation of the provincial and sectoral CERTs had already been issued and would continue to be developed. The senior officer representing Sindh asked whether provinces would have to formulate their own rules and pointed out that considerable funds could be required, particularly if additional data centres were established.

He referred to the recent approval by the Sindh government of a data centre for Sindh Intelligence Fusion. The committee was told that specific instructions regarding the establishment of data centres were contained in the Cloud First Policy issued by the Ministry of Information Technology and Telecommunications. He maintained that PISF 2026 provided the necessary framework for federal and provincial entities and, therefore, there was no requirement for provinces to formulate separate rules. The meeting separately examined the cyber security situation of Ministry of Foreign Affairs missions abroad, an area described as particularly sensitive because of its direct linkage with national security.

Related coverage