ISLAMABAD: The National Cyber Emergency Response Team of Pakistan (PKCERT) has issued the National Cybersecurity Handbook (2026–27), a practical guide that lays down a baseline operational standard for digital security across federal and provincial governments and public sector organisations.
Published under the Ministry of Information Technology and Telecommunication, the handbook is addressed to employees, officers, officials and technical personnel. It describes cybersecurity not merely as a technical function but as a shared responsibility of every government employee, given that public services are becoming increasingly digital and interconnected.
Legal and policy framework
The document states that it translates the requirements of the Pakistan Information Security Framework (PISF) 2026, the National Cyber Security Policy 2021, the CERT Rules 2023 and other applicable laws, regulations and government directives into everyday guidance. Its resources page also points readers to the Electronic Transactions Ordinance 2002, the National Security Policy 2022 and the Prevention of Electronic Crimes Act (PECA) 2016.
The guidance is organised into eight domains: official email, device security, password security, data security, internet security, removable media, remote access and incident response. Each sets out do’s, don’ts and the risks of non-compliance.
Email, devices and credentials
Employees must conduct official correspondence only through official email accounts. Personal accounts such as Gmail or Yahoo may not be used unless a department expressly authorises it as a special arrangement in exceptional circumstances. Officials are also barred from forwarding official emails to personal inboxes and are told to verify senders, links and requests before acting.
Official work is to be performed on authorised devices. Where a personal device becomes operationally necessary, prior departmental approval is required, and sensitive applications such as e-Office must not be accessed on personal devices. The handbook identifies “Shadow IT”, meaning any tool used without approval, as a security blind spot that also erodes audit traceability during incident investigations.
On passwords, the handbook calls for long, unique passphrases, multi-factor authentication on official portals and storage of credentials only in approved encrypted vaults. Sharing credentials or authentication codes is prohibited.
Data, internet and artificial intelligence
All official data must be classified under the department’s approved scheme, aligned with PISF, and the classification may not be downgraded without authorisation. Critical files must be backed up on secure government infrastructure, with the handbook recommending the 3-2-1 principle: three copies, on two types of storage, with one kept in a separate location.
Personnel must connect through official wired or encrypted networks and avoid open public Wi-Fi for official business. The handbook also addresses artificial intelligence. Staff may use only department-approved AI platforms and must not enter classified documents, emails, software source code or citizen personal information into public AI tools. AI-generated content must be reviewed by a human before use.
On social media, the handbook cautions against posting photographs of official documents, security badges or restricted premises, and against expressing personal opinions using official titles.
Removable media and remote work
Only officially sanctioned USB drives and hard disks may be used, and attempts to bypass USB port blocking policies are prohibited. Official files must be encrypted before being copied to removable media, and damaged drives must be handed to the IT team for secure disposal, since deleting a file does not remove its contents.
Remote access to government systems is permitted only through approved VPN solutions. Virtual meetings must be password-protected, and sensitive official meetings may not be recorded or transcribed without prior written authorisation from the chair.
Incident reporting and evidence
For legal practitioners, the incident response section may be the most consequential. Personnel must report suspected incidents immediately and are told not to delay out of fear of administrative repercussions. Affected machines should be isolated from the network but not switched off or restarted, and users must not run antivirus or recovery tools on them, because doing so may destroy evidence.
During PKCERT-led investigations, departments must grant access to infrastructure and logs, maintain chain-of-custody for impacted devices and refrain from altering audit logs, firewall records or memory dumps before forensic collection. Services may not be restored, or network segments reconnected, until PKCERT issues formal security clearance. The handbook notes that under the CERT Rules 2023, organisations must report incidents to PKCERT through approved channels and through organisational, provincial or sectoral CERTs.
Scope and limits
The handbook does not itself prescribe penalties for non-compliance, listing operational risks such as data leakage, account takeover and service disruption instead. Its disclaimer adds that adherence does not guarantee complete immunity from sophisticated threats, and that departmental IT teams must continue to monitor, update and enforce technical controls. It stresses that the guidance serves as the baseline operational standard for digital security across public sector entities.
Supervisors and IT teams are encouraged to use the guidelines as baseline checklists for internal audits and training. Further information is available at www.pkcert.gov.pk or info@pkcert.gov.pk.
