TheCyberExpress

Pakistan’s 90-Day Cybersecurity Action Plan Unveiled


Pakistan’s federal government has completed work on a 90-day cybersecurity action plan designed to build a more coordinated national defense against digital threats, bringing together federal and provincial governments, regulators and operators of critical infrastructure under one framework. 

The Cyber Security Working Committee (CSWC) drafted the plan and functions as a subordinate body of the National Committee for Information and Communications Security (NCICS).  

Its scope is broad: setting up a Federal CERT, activating provincial CERTs, drafting a five-year national cybersecurity strategy, building a cyber warfare escalation matrix, safeguarding critical infrastructure, and creating a dedicated career track for cybersecurity and emerging-technology specialists. 

CSWC’s Mandate and Structure for the Cybersecurity Action Plan

The CSWC has been asked to close existing gaps in the country’s cyber defenses by coordinating national CERTs, ministries at both federal and provincial levels, and other stakeholders.  

Its goals include a unified governance model for cybersecurity, better visibility into digital assets and vulnerabilities, stronger baseline controls, protection for Critical Information Infrastructure (CII), coordinated incident response, workforce and academic development, and safer practices for acquiring and retiring public-sector technology.  

The 90-day cybersecurity action plan is organized around six themes: governance, compliance, resource alignment, incident response and crisis management, security assessment, and supply chain security. 

Chaired by the Director General of NCERT, the CSWC also includes the Secretary of NTISB, the Cabinet Division, the Chairman of PTA, a Member of the Ministry of IT and Telecom, and representatives from the Pakistan Digital Authority, PTA, NADRA, NTC, and NITB, along with a director from the former NCERT.  

Co-opted members represent the provinces, Gilgit-Baltistan, Azad Jammu and Kashmir, ISI’s technical wing, the Ministry of Interior’s NCCIA, and outside experts. The committee will run gap assessments based on completed audits, review existing policies against international norms, and recommend technical controls for sectors including health, energy, aviation and transport. 

Federal CERT Tops the Priority List 

Establishing a Federal CERT (FCERT) is the plan’s priority, tasked with detecting, monitoring and analyzing threats across government while issuing advisories to ministries and divisions. NCERT will define its mandate and legal standing, and together with NTISB and the IT Ministry will prepare funding and implementation proposals.  

The plan targets 40 percent operationalization of the Federal CERT within 365 days, against a total project timeline of three years, with rules for engaging 39 ministries and divisions to be developed on an ongoing basis.  

Provincial CERTs form the second part of this priority, with NCERT and CSWC issuing technical and administrative guidance within 90 days for notification through provincial chief secretaries. 

Strategy, Escalation and Infrastructure Protection 

The plan notes that since the National Cyber Security Policy 2021, few sectors have built dedicated strategies — PTA’s 2023-2028 strategy being an exception — while sectors like oil and gas remain without one.  

A CSWC subcommittee will draft a Cyber Warfare Escalation Matrix within 60 days, covering escalation levels and response chains, with public consultation and finalization due in 90 days.

Separately, NCERT will identify critical infrastructure and CII, and produce a declaration framework and protective guidelines within the same 90-day window. 

Workforce and Next Steps 

The final priority involves creating a specialized service structure for professionals working in cybersecurity, AI, and quantum computing, aimed at retaining talent. NCERT will also work with the Higher Education Commission and Pakistan Engineering Council to reform related curricula.  

NCICS will oversee monitoring and progress reporting as regulators and provincial authorities manage implementation locally. 



Source link