Pakistan has stepped up cybersecurity preparations ahead of Defence Day amid concerns over possible cyber attacks. The National Cyber Emergency Response Team has issued detailed instructions to important institutions.
The National CERT has directed key institutions to establish special cybersecurity control rooms from September 5 to 7. Meanwhile, sectoral and provincial CERTs have been asked to remain on alert during this period.
Critical information infrastructure organisations must also prepare for potential cyber threats. Authorities are therefore urging institutions to strengthen monitoring and maintain immediate response capabilities.
NSOC to Coordinate National Cyber Response
The National Security Operations Centre will serve as the national cyber coordination centre during Defence Day. It will remain operational around the clock to monitor the cyber situation.
The centre will also facilitate the exchange of important cybersecurity information among relevant institutions. Therefore, organisations have been directed to maintain close coordination with the NSOC.
Institutions must continuously monitor important networks, systems, websites and digital services. They must also immediately report any major cyber incident, suspicious activity or potential security breach.
Cybersecurity Teams Must Remain Ready
All institutions have been instructed to ensure cybersecurity focal persons and technical teams remain available from September 5 to 7. Technical teams must stay prepared for immediate communication and emergency response.
Additionally, institutions have been advised to share cyber threat intelligence with the NSOC. This coordination will support a joint response to incidents affecting national digital infrastructure.
Authorities have also called for special measures to protect government and other important digital services. These include websites, portals, application programming interfaces and email systems.
Websites and Digital Systems Face Additional Protection
Institutions have been instructed to activate web application firewalls and DDoS protection. They must also ensure that their web systems remain updated.
The National CERT has further directed institutions to use multi-factor authentication. Stronger security controls should also protect administrative accounts.
Meanwhile, organisations have been told to update operating systems and disable unnecessary services. These measures are intended to reduce potential vulnerabilities across important digital systems.
Critical Servers and Databases Need Protection
Firewalls and systems designed to detect and prevent cyber attacks must remain active on important servers. Institutions have also been directed to monitor security logs regularly.
Critical databases should not remain directly accessible through public IP addresses. Therefore, organisations must ensure stronger controls around important data and infrastructure.
Institutions have also been told to keep disaster recovery sites ready for immediate use. Additionally, they must maintain offline or air-gapped backups of important systems and configurations.
Backup Internet and Power Arrangements Required
Data centres and security operations centres must ensure alternative internet connectivity during the alert period. They have also been directed to maintain adequate power backup arrangements.
These preparations form part of the broader cybersecurity measures issued ahead of Defence Day. Meanwhile, institutions are expected to remain vigilant from September 5 to 7.
The instructions focus on continuous monitoring, stronger digital protection and rapid response capabilities. They also seek to ensure that critical national digital infrastructure remains prepared for potential cyber incidents.
