Pakistan Unveils 90-Day Cybersecurity Strategic Action Plan
Pakistan has initiated a 90-day Cyber Security Strategic Action Plan to bolster cybersecurity across federal and provincial levels. This plan offers significant procurement opportunities in cybersecurity services, particularly in establishing Computer Emergency Response Teams (CERTs) and secure data centers.
Key Signals
- Pakistan launches 90-day cybersecurity action plan to implement PISF 2026
- National Computer Emergency Response Team (nCERT) designated as primary coordinator
- Action plan includes establishment and management of Computer Emergency Response Teams (CERTs)
"A Managed Security Service Provider (MSSP) approach would be adopted, with provincial and sectoral CERTs operating under nCERT while directly engaging their respective ministries and departments."
In response to increasing threats from cyber warfare, the Government of Pakistan has officially launched a 90-day Cyber Security Strategic Action Plan aimed at addressing critical cybersecurity deficiencies across various tiers of governance. This action plan emerged from deliberations held by the National Committee for Information and Communications Security (NCICS), highlighting the urgent need for practical and immediate responses to rising cyber threats facing internal and external infrastructures.
The Cyber Security Strategic Action Plan mandates the expedited implementation of the Pakistan Information Security Framework (PISF) 2026, which has recently received approval from the authorities. A key dimension of this initiative centers on the establishment of Computer Emergency Response Teams (CERTs) under a Managed Security Service Provider (MSSP) model. This structure is designed to enhance coordination and operational efficiency, with the National Computer Emergency Response Team (nCERT) overseeing the data protection measures proposed.
The plan is not merely a reactive measure but a proactive approach to fundamentally reshape how Pakistan addresses cybersecurity threats. It posits a comprehensive framework that includes governance, resource alignment, incident response protocols, and supply chain security. Moreover, it aims to enhance cybersecurity at Pakistan's diplomatic missions abroad, recognizing the national security stakes tied to these entities. Such measures are aligned with the Ministry of Information Technology and Telecommunications' Cloud First Policy, which aims to modernize data management practices.
Many organizations, especially those operating in the technology and cybersecurity sectors, should closely monitor this action plan as it unfolds over the next 90 days. It presents immediate procurement opportunities for service providers, MSSPs, and infrastructure developers interested in contributing to the operationalization of the CERTs and secure data centers mandated by PISF 2026. The strategic focus not only helps mitigate cyber threats but also signifies a shift towards establishing a resilient digital infrastructure that can adapt to emerging challenges.
In a recent meeting chaired by the secretary of the Ministry of Information Technology and Telecommunications, the urgency was underscored, particularly regarding the operational challenges expected in rolling out the Federal CERT. Authorities stressed the necessity of inter-agency coordination and the integration of various ministries and departments in the nCERT's operational framework. This integration is crucial for delivering a holistic cybersecurity response that can stand up to a growing array of cyber threats on both national and international fronts.
As organizations position themselves to achieve compliance with the new PISF 2026 requirements, it is critical to assess existing capabilities in governance and incident response strategies. The nCERT aims to offer a clear pathway for these implementations, targeting efficient partnerships between provincial and federal entities. Importantly, engagement strategies involving various ministries—including the Pakistan Telecommunication Authority (PTA) and the Ministry of Foreign Affairs—will enhance collaborative efforts toward achieving national cybersecurity objectives.
As stakeholders digest this important announcement, they should also prepare for discussions regarding the funding necessary to establish new data centers, especially for provincial CERTs. The need for investment in secure infrastructure is evident, as highlighted by representatives from the Sindh government, who noted the recent approval of a data center that may serve as a regional model for similar initiatives across the country. The dynamics of these discussions will require keen attention as they unfold, as the operationalization of CERTs cannot be successful without appropriate funding mechanisms in place.
Agencies
- National Committee for Information and Communications Security
- Ministry of Information Technology and Telecommunications
- National Computer Emergency Response Team
- Pakistan Telecommunication Authority
- Ministry of Foreign Affairs
Sources
- Govt Sets 90-Day Deadline to Fix Its Biggest Cyber Security GapsTechJuice · Sep 14
- Cyber warfare threat prompts Pakistan to fast-track security measuresThe News Pakistan · Sep 13
- Govt approves 90-day cyber security action plan - Profit by Pakistan Todayprofit.pakistantoday.com.pk · Sep 14