Pakistan currently has no real-time visibility of cyber threats targeting its critical infrastructure, the National Cyber Crime Investigation Agency (NCCIA) has told the Senate Standing Committee on Information Technology and Telecommunications, citing major gaps in the cybersecurity architecture.
In a report submitted to the Senate Standing Committee, the NCCIA said it lacks direct access to a consolidated national threat-intelligence platform or a unified threat-landscape dashboard capable of monitoring cyber threats across all critical sectors in real time.
The report further added that security monitoring of sector-specific infrastructure is currently handled separately through Security Operations Centres (SOCs) run by individual sectoral regulators and organisations, rather than through a centralised system.
The agency warned that the absence of an integrated national cyber threat information-sharing mechanism limits timely situational awareness, early-warning capabilities and coordinated incident response at the national level.
It called for stronger inter-agency intelligence sharing among the NCCIA, sectoral regulators, Critical Information Infrastructure (CII) operators and SOCs, stating this would significantly improve Pakistan’s cyber resilience and response capabilities.
The NCCIA also clarified the boundaries of its mandate, stating it has no authority or technical infrastructure to encrypt government databases, secure network perimeters, mandate cybersecurity training for civil servants, or install intrusion-detection systems on ministry servers.
It recommended that the government enforce appropriate security standards across all government entities, while the agency’s role would remain limited to investigating criminal breaches that occur despite such protections.
On an ongoing investigation, the NCCIA outlined its next steps, which include reviewing the forensic report on seized digital devices, further examining digital evidence, communications and financial trails, and identifying any additional individuals involved.
Once forensic examination and other investigative requirements are complete, the agency said the case would be finalised and a challan submitted under Section 173 of the Cr.P.C. before the relevant magistrate for further legal proceedings.
The NCCIA described the cyber threat facing Pakistan as “real and significant,” noting it had dismantled one active trafficking network and was investigating possible foreign links. It reiterated that while it can investigate and apprehend criminals after a breach occurs, preventing such breaches remains the responsibility of cybersecurity agencies and data holders themselves.