pakistan cyber policy

Rapid digitalization and penetration of Information and Communication Technologies (ICTs) in all walks of life have exposed states to new and evolving cybersecurity threats. Protection of data and networks from these has become a sine qua non for states. While all responsible states have developed holistic policies and approaches to counter impending cyber threats, Pakistan struggled to formulate a centralized national policy or strategy for cybersecurity. Guidelines on cybersecurity and governance for various sectors (such as banking and defense) were in place, but a holistic national-level approach to cybersecurity was missing.

On 27 July 2021, the Federal Cabinet approved Pakistan’s first National Cyber Security Policy for data protection and prevention of cybercrimes, a much-anticipated document in the cybersecurity community. The policy was formulated by the Ministry of Information Technology & Telecommunication which endeavored to finally provide a plan of action to establish a concrete legal and structural framework related to cybersecurity.

What are the threats to National Cybersecurity Policy?

While National Cybersecurity Policy was a strategic need for a long it was actually the Pegasus scandal that expedited it. A collaborative investigation by a consortium of media organizations revealed how a hacking software – Pegasus- licensed by an Israeli firm NSO to its client governments for tracking terrorists and criminals was used to target world leaders, human rights activists and journalists, etc. Hundreds of phone numbers from Pakistan were on the list, including one used by PM Imran Khan once. Unsurprisingly, and most worryingly, India- Pakistan’s archrival- happened to be one of NSO’s most loyal clients.

The 2021 policy’s vision is to create a secure, robust, and continually improving nationwide digital ecosystem while ensuring accountable confidentiality, integrity, and availability of digital assets.’ Its key guiding principles include data privacy and security of citizens, providing the required support and system to concerned public and private organizations, the establishment of a national response framework, and last but not least, adoption of best practices to ensure national digital sovereignty.

The policy, in order to improve the national cybersecurity outlook, plans to undertake the ‘strengthening of national cybersecurity capabilities through the development of essential and well-coordinated mechanisms, implementation of security standards and regulations under a policy and legislative framework’.

Because of Pakistan’s meager commitment to cybersecurity, it performed poorly in global ICT rankings (ICT Development Index value of 2.42). Hence, one of the core objectives of the policy also happens to be the improvement of Pakistan’s ICT ranking. Pakistan also ranks 14 out of a total of 18 states in the Asia-Pacific on the Global Cybersecurity Index (GCI) 2020. The country’s overall GCI score is 64.88. The policy would help improve Pakistan’s GCI ranking too.

Another essential element discussed in the policy is the indigenization and development of cybersecurity solutions through R&D programs. This too was an important area that needed attention. Adequate local resources, both in terms of manpower through Centres of Excellence and HRD programs, and technology will rectify our excessive reliance on external sources which further amplify the country’s cyber risks. However, the policymakers did not specify how much resources/budget would be allocated for this crucial purpose.

The approach of risk management is a welcome initiative

Nevertheless, considerably more focus has been put on information security rather than on cybersecurity. This is primarily because the wrong stakeholder is in the lead on this policy. Since cybersecurity is much broader than information security, the subject should fall under the National Security Division (NSD) for a more substantive outlook and scope.

As underscored by the Information Minister, the National Cyber Security Policy constitutes two parts, cyber security as well as cyber offenses. The building up of a mechanism against offensive cyber operations was a long-overdue step. The existing information and data security legislations (often taken synonymous with cyber legislation) did not take into account the growing need to defend and deter cyber aggression.

While the current policy does not provide a response mechanism with demarcated roles and responsibilities, it categorically declares that in case of any aggression, the state of Pakistan will respond. Accordingly, a cyber-attack on Pakistan’s Critical Infrastructure or Critical Information Infrastructure will be regarded as an act of aggression against national sovereignty and the state will defend itself with appropriate response measures. The decision to establish a national-level response team is also fundamental in this regard.

Contextually and content-wise, the policy is an important and much-needed document that covers both offensives as well as defensive needs. Priorities and needed actions are well articulated, but unfortunately, an action plan to achieve those goals and deliverables is missing. Nonetheless, the decision to constitute a Cyber Governance Policy Committee (CGPC) for implementation and oversight is part of the policy.

The Committee will be tasked to come up with a concrete strategy and action plan. Given Pakistan’s poor record of enforcement and selective implementation of policies, all eyes are on CGPC to live up to its mandate and fulfill the responsibility of securing Pakistan’s national cyberspace.

Aneeqa Safdar is researcher at Centre for Aerospace & Security Studies (CASS). This article was first published in Global Space Village (GVS). She can be reached at [email protected]

Image Source:  Radichel, Teri. “Cybersecurity policies that reduce reduce risk”. 2nd Sight Lab. December 11, 2019. 


Share this article

Facebook
Twitter
LinkedIn

Recent Publications

Browse through the list of recent publications.

The US-Israel War on Iran: Objectives, Strategy, and Escalation Management

Zahra Niazi
‘States tend to overestimate themselves or the benefits and swiftness of war, and to underestimate their opponents’ capabilities, intentions, or the costs and duration of war.’ If anything, the 2026 war initiated by the United States and Israel against Iran shall be remembered in the annals of warfare among the most visible manifestations of this dynamic.
The war, immediately preceded by the January mass protests in Iran, did not represent a sudden rupture but rather the continuation of a 47-year-long confrontation and a more intense phase of the June 2025 war.
The US Secretary of War, Pete Hegseth, defined the war’s objectives as being laser-focused: to destroy Iran’s missile capabilities and its security infrastructure, while ensuring that it could never develop nuclear weapons. Beyond these stated objectives, among the priorities on the continuum also lay the objective of regime change, with both President Trump and Prime Minister Netanyahu explicitly calling on the Iranian population to take over the government at the outset of the war.

Read More »

Marka-e-Haq to the Peace Talks: Pakistan’s Middle Power Status

On 7th May 2025, Pakistan’s military forces took the international security community by surprise when it demonstrated operational superiority against its larger belligerent adversary India with its rapid and coordinated response. The Four-Day conflict proved to be a watershed moment for Pakistan, marking its rapid emergence as an important player in the region. In recent years, amidst the ongoing global competition between the United States and China, Islamabad has adopted a position of ’Strategic Balancing,’ where it maintains ties of cooperation with both Beijing and Washington. Deft diplomacy, emphasis on geo-economics, and credible conventional and strategic deterrence have remained the foundational pillars for Pakistan’s ambition as a rising middle power

Read More »

Debunking the S-400 Shield: Lessons from the India-Pakistan Conflict

Air defense has always been a central aspect of warfare. In South Asia, the phenomenon carries immense significance due to compressed reaction times. In this context, one of the most-hyped systems is the Russian-made S-400, touted by New Delhi as a one-stop solution to counter aerial threats from both Pakistan and China.
The 2025 conflict between India and Pakistan marked an important chapter in testing the S-400 technology. The conflict began on May 7, when India attacked what it alleged were terrorist targets in both Pakistani-held Kashmir and Pakistan proper, using drone and missile strikes. The conflict lasted for four days, culminating in a U.S-facilitated ceasefire. However, the brief conflict debunked a lot of the myths regarding the S-400 technology.
First, India claimed that the mobile S-400 would be able to control Pakistan’s airspace. In contrast, Pakistani aircraft continued to operate freely, according to official briefings by the Pakistani military. Although the Pakistan Air Force (PAF) aircraft were in their own airspace, they were still within the air defense range.

Read More »