2
1.2
REVIEW OF PAKISTAN’S CYBER SECURITY LANDSCAPE
In order to ensure the online safety of the citizens of Pakistan and to
ensure the security of the digital systems, various initiatives are already in place
by different federal & provincial bodies and sectoral regulators under the
enactments such as the Electronic Transaction Ordinance, 2002 (covering only
electronic financial transactions and records), Investigation for Fair Trial Act
(IFTA) – 2013, Pakistan Telecommunication (Re-Organization) Act - 1996 and
Prevention of Electronic Crime Act (PECA) 2016 which cover some but not all
aspects of information and Cyber Security. In addition, the State Bank of
Pakistan (SBP) issues guidelines on Cyber Security for the financial sector, and
the PTA has notified the Telecom Computer Emergency Response Team
(CERT). However, the inter-departmental coordination and holistic approach
to address the Cyber Security challenges and their emerging trends requires a
special focus on a national level.
With regards to setups responsible for Cyber Security in the country, only
the selective Cyber Security Incident Response Teams (CSIRTs) are operational
at the organizational level in the public, private, and defense sectors.
However, there is a need to enhance existing legislative and institutional
frameworks, and strengthen the principal, organization, mandated for national
Cyber Security. The legal framework, structures, and processes related to
Cyber Security need to be constantly monitored, assessed, and improved.
To undertake academic research, National Center for Cyber Security
was established in 2018. The HEC has also formulated new academic degrees
that include BS, MS, and Ph.D. Cyber Security and MS Systems Security
programs. However, the demand and supply gap for digital skills in general
and Cyber Security, in particular, is ever-increasing, which underscores the
importance of upskilling the existing resources.
In the absence of an indigenous national ICT and Cyber Security
industry, Pakistan relies heavily on imported hardware, software, and services.
This reliance, inadequate national security standards, and weak accreditation
National Cyber Security Policy 2021