Government departments will not be allowed to restore services or reconnect network segments affected by cyberattacks until they receive formal security clearance from Pakistan’s National Cyber Emergency Response Team (PKCERT).
The requirement is part of the National Cybersecurity Handbook 2026–27, which sets out how federal and provincial governments and public-sector organizations must respond to cybersecurity incidents.
Cyberattacks Must Be Reported
Under the handbook, cybersecurity incidents must be reported to PKCERT through approved channels, as well as to organizational, provincial or sectoral Computer Emergency Response Teams (CERTs) operating under the CERT Rules 2023.
PKCERT teams will investigate critical cyber incidents and carry out digital forensic analysis to determine how an attack occurred, assess its impact and contain the threat.
Government departments must provide investigators with immediate physical and administrative access to affected systems, infrastructure, system logs, and other relevant records.
Strict Rules for Digital Evidence
The handbook also requires government organizations to preserve digital evidence after a cyberattack.
Officials must maintain a strict chain of custody for compromised devices and storage media to ensure evidence remains intact during the investigation.
They are prohibited from changing audit logs, firewall records, or memory dumps. They must also prevent unauthorized vendors and personnel who have not received the required clearance from accessing or interfering with systems placed under quarantine.
Departments Must Follow PKCERT Instructions
Government organizations are required to implement emergency measures and other remediation instructions issued by PKCERT investigation teams.
The handbook warns that restoring systems too early or conducting an incomplete forensic investigation could allow hidden threats to remain inside government networks.
It could also prolong service disruptions and make it harder for authorities to determine how an attack was carried out, where it originated, and what systems or information were affected.
Clearance Required Before Services Resume
The new requirement effectively places forensic investigation and security clearance ahead of the restoration of government networks affected by serious cyberattacks.
Government organizations will therefore have to preserve affected systems, cooperate with PKCERT investigations, and complete required containment and remediation measures before restoring services or reconnecting quarantined network segments.
The post Pakistan Blocks Restoration of Hacked Govt Networks Without Approval appeared first on ProPakistani.
