The federal government has approved a 90-day Cyber Security Strategic Action Plan and directed provinces to accelerate the establishment of Computer Emergency Response Teams (CERTs) and the rollout of the Pakistan Information Security Framework (PISF) 2026, amid what officials describe as a heightened cyber threat environment.
The decision was taken at the second meeting of the National Committee for Information and Communications Security (NCICS), held at the Cabinet Division and chaired by the secretary of the Ministry of Information Technology and Telecommunications, who also serves as NCICS chairman.
Senior official sources said the meeting stressed the need for practical and immediate measures given the growing scale of cyber threats. The committee was told that PISF 2026 has already been approved and that its implementation must now be ensured at both the federal and provincial levels.
The National Computer Emergency Response Team (nCERT), which heads the Cyber Security Working Committee, presented the 90-day action plan, covering governance, compliance, resource alignment, incident response, crisis management, cyber security assessment and supply chain security. nCERT has also prepared a National Cyber Security Handbook aimed primarily at government officials.
The chairman of the Pakistan Telecommunication Authority (PTA) said operationalising the Federal CERT requires careful planning, particularly since sectoral and provincial CERTs are not yet in place, to ensure ministries and departments are efficiently integrated.
nCERT said a Managed Security Service Provider (MSSP) approach would be adopted, with provincial and sectoral CERTs operating under nCERT while directly engaging their respective ministries and departments. Guidelines for operationalising these CERTs have already been issued and will continue to be developed.
A senior officer representing Sindh asked whether provinces would need to formulate their own rules, noting that significant funding could be required, especially if additional data centres are established. He cited the Sindh government’s recent approval of a data centre for Sindh Intelligence Fusion.
In response, the committee was told that the Ministry of Information Technology and Telecommunications’ Cloud First Policy already contains specific instructions on establishing data centres, and that PISF 2026 provides an adequate framework for both federal and provincial entities, making separate provincial rules unnecessary.
The meeting also reviewed the cyber security situation at Ministry of Foreign Affairs (MoFA) missions abroad, an area officials called particularly sensitive due to its direct link to national security.
The Sub-Committee for Cyber Security Aspects of MoFA Missions briefed the committee on the current cyber security landscape of diplomatic missions and on measures recently taken to strengthen their security posture. The committee subsequently tasked the sub-committee with preparing a comprehensive action plan and guidelines to further secure MoFA missions.