
Pakistan has heightened its cybersecurity preparedness ahead of Defence Day amid concerns over possible cyber attacks. The National Cyber Emergency Response Team (National CERT) has issued detailed cybersecurity instructions, directing government institutions, critical information infrastructure organisations, and provincial and sectoral CERTs to remain on high alert from September 5 to 7. The measures focus on continuous monitoring, rapid incident reporting, stronger security controls, backup readiness, and coordinated national cyber response.
With Defence Day approaching, Pakistan is moving to strengthen its digital defences as authorities prepare for the possibility of cyber threats against government systems and other critical infrastructure.
The National Cyber Emergency Response Team (National CERT) has asked key institutions to remain on heightened alert between September 5 and 7. During this period, dedicated cybersecurity control rooms are to be established to ensure that any emerging threat can be identified and addressed without delay.
A central role in the response will be played by the National Security Operations Centre (NSOC), which has been designated as the national cyber coordination centre for Defence Day. The facility will operate round the clock, overseeing the cyber environment and coordinating the flow of threat intelligence and incident-related information among institutions.
Organisations overseeing critical information infrastructure have also been directed to strengthen their readiness. Provincial and sector-specific CERTs will remain vigilant, while designated cybersecurity officials and technical teams must be available throughout the three-day period for immediate coordination and emergency response.
Authorities are placing particular emphasis on monitoring. Institutions have been told to keep a close watch on their networks, websites, online systems and digital services, with any unusual activity or suspected compromise to be communicated immediately through the relevant channels.
Government-facing digital infrastructure is also expected to receive additional protection. Websites, portals, APIs and email systems have been advised to operate with web application firewalls and DDoS protection enabled. Organisations have further been asked to ensure that their web systems are patched and running updated software.
Access to sensitive systems is another area of focus. National CERT has recommended multi-factor authentication and stronger controls for administrative accounts, alongside the removal of unnecessary services and timely operating-system updates to limit exploitable weaknesses.
Institutions have additionally been advised to review the security of their critical servers. Firewalls and intrusion detection and prevention mechanisms should remain active, while sensitive databases should not be exposed directly to the public internet. Regular examination of security logs has also been recommended to identify unusual behaviour at an early stage.
The preparedness plan extends beyond preventing attacks to ensuring services can be restored if systems are compromised. Critical organisations have been asked to keep disaster recovery facilities ready and maintain offline or air-gapped backups of essential data, configurations and systems.
Meanwhile, data centres and security operations centres have been instructed to prepare backup power arrangements and alternative internet connections. The measures are intended to reduce the risk of service disruption and help maintain the availability of essential digital infrastructure during a potential cyber incident.
The coordinated measures reflect a broader effort to ensure that Pakistan’s critical digital systems remain secure and operational during Defence Day, while improving the country’s ability to detect, contain and recover from any cyber attack.
