The National Cyber Emergency Response Team (NCERT) has issued a cybersecurity advisory highlighting growing risks from foreign cloud technology products widely used across government, business, and education sectors.
The advisory, titled Deployment of Cloud Technology Products in Pakistan, warns that hosting and processing data outside Pakistan exposes sensitive information to foreign laws permitting compelled disclosure and lawful interception.
NCERT specifically identified platforms such as Zoho Corporation, noting their widespread use across education, information technology, finance, and small businesses, raising concerns about unauthorized access vulnerabilities.
The document highlighted risks including exposure of sensitive communications, procurement records, and financial information, emphasizing that foreign-hosted services increase susceptibility to unauthorized monitoring and data exploitation.
NCERT further flagged surveillance concerns, warning foreign cloud platforms may access communication metadata, files, location data, and other sensitive records through privileged administrative controls, enabling unauthorized monitoring capabilities.
The advisory underscored the presence of local implementation partners supporting foreign services in Pakistan, stressing the scale of adoption and urgency for comprehensive risk assessment measures.
Key vulnerabilities identified include lack of data localization, reliance on foreign sub-processors, and systems with broad administrative capabilities, collectively increasing exposure to cybersecurity threats and intelligence risks.
NCERT recommended immediate stakeholder sensitization, urging organizations and regulators to review and gradually discontinue foreign state-linked cloud services where risks are significant and national interests potentially compromised.
The advisory concluded by recommending promotion of Pakistan-based SaaS alternatives with verified local data storage, aiming to strengthen cybersecurity resilience and safeguard national security and regulatory compliance.
