Opinion

Zainab Samantash
August 3, 2026
6 min read
Size
Font
Across the world, cybersecurity is moving from the server room to the regulatory rulebook, becoming a condition of doing business rather than solely an internal technology concern. But that shift exposes a difficulty legislation alone cannot solve: the hard part of securing critical infrastructure is not declaring that it must be secured. It is building the capacity to secure it which cannot be ordered into existence on a three-day timeline.
Pakistan has just supplied a vivid illustration. After coordinated attacks on multiple broadcasters in March, Pakistan Electronic Media Regulatory Authority (PEMRA) directed satellite television licensees to submit a cybersecurity roadmap within three working days; and to complete the substantive measures, like appointing chief information security officers, standing up monitoring systems and commissioning third-party audits, by 4 August, roughly a fortnight later.
Some controls, such as breach reporting, log preservation and resetting exposed credentials, can properly be required within days. A three-day roadmap may therefore be defensible as an emergency information-gathering measure. The error is treating that roadmap, and the fortnight that follows, as if they constitute a durable cybersecurity programme. Governance, specialist personnel, procurement, testing and repeated supervisory review cannot be meaningfully assembled in two weeks.
The deadline still reveals a familiar pattern: Pakistan regulates cyber risk reactively, sector by sector, after a breach rather than before one; and without a common baseline tying those sectors together
This is where Pakistan’s financial sector becomes instructive: it faced similar problems and answered them in the opposite order. Over the past decade, the State Bank of Pakistan (SBP) has built its cyber and technology-risk regime in deliberate stages. Its 2017 technology-governance framework established baseline obligations for banks, development finance institutions and microfinance banks across information security, third-party risk and incident reporting, including a requirement to report serious cyber incidents within forty-eight hours.
Crucially, the framework was expressly risk-based rather than one-size-fits-all, permitted phased implementation and gave institutions more than a year to comply. In October 2025, SBP extended this approach through a dedicated technology-risk-management framework for electronic money institutions, payment system operators and payment service providers. It again calibrated implementation to the institution’s size and technological complexity and gave the sector until 31 March 2026 to comply. The regime is demanding and far from perfect. But it was built incrementally, not compressed into a post-incident deadline.
The sequence is the point. The SBP set its standards against a capability the sector had been given time, guidance and support to build; PEMRA fixed the outcome and the deadline first, and left the capability to appear on its own. Two lessons follow
The first is that capability has to precede the mandate, and obligations should scale to it. The SBP built its expectations against infrastructure that institutions could realisti<a href="https://justfineinfotech.com/fiverr-international-q2-earnings-call-highlights/” title=”Fiverr International Q2 Earnings Call Highlights”>cally stand up, calibrated the burden to the risk, heavier for large and complex institutions, lighter for small ones, and gave everyone a runway. A rule that fixes a deadline before it names an achievable, proportionate method is not regulation so much as an instruction to improvise.
The second, and more serious, is that a mandate without the surrounding architecture manufactures risk rather than reducing it. An impossible deadline does not produce security; it produces a document, a roadmap filed to demonstrate motion while the attacker, who does not read submitted PDFs, carries on. Requiring a named CISO on a compressed timeline is worse still: it places nominal accountability on one person without the budget, authority or institutional support to discharge the role. If the audit finds gaps, that individual already owns them and accountability is handed over without the means to have earned it.
The map is fragmented. The SBP sets the rules for financial institutions. The Pakistan Telecommunication Authority governs telecom networks through its critical-infrastructure security regulations. The Securities and Exchange Commission issues guidance for firms under its remit, beginning with a dedicated framework for insurers in 2020. The newly created Pakistan Virtual Assets Regulatory Authority has also identified cybersecurity as a core requirement of the licensing framework it is developing for virtual-asset businesses. PEMRA has now added broadcasters to the list. A single company operating across these sectors can be accountable to several of them at once, reconciling requirements that were never designed to fit together.
Pakistan keeps promising to knit this together. A National Cyber Security Policy in 2021 envisaged central coordination which never fully arrived. More recently, the government has announced that it is preparing a Cyber Security Act that would establish a national Cyber Security Authority. But as of mid-2026, the legislation has not been enacted and the proposed authority does not yet exist. In the meantime, the national and provincial Computer Emergency Response Teams (CERTs) handle incident response, and the National Threat Intelligence System monitors threats around the clock. But none of them sets binding security standards for the sectors themselves. So each regulator improvises its own, and PEMRA’s three-day order is what that vacuum produces: overlapping expectations, inconsistent baselines, and gaps at the seams, precisely where attackers work.
Beneath all of this is a shift many boardrooms have not absorbed: cybersecurity is becoming a licensing condition. When a regulator converts security expectations into mandatory obligations, persistent non-compliance becomes a regulatory, and potentially licensing, risk. Security used to sit in the cost column, treated primarily as something the technology team owned. It is becoming a licensing and governance question, and that makes it a matter of business strategy.
The finance-to-broadcast comparison has a limit worth naming: a television channel is not a bank. It has a different threat model and holds no customer deposits. But that argues for the lesson, not against it. The value of the financial sector’s experience is not that its rulebook transfers wholesale; it is that it demonstrates the method: build the capability, then require it. The method is sector-agnostic and the three-day deadline ignores it.
None of this argues for delay, it argues for sequencing. PEMRA could require the emergency measures now and set the rest on phased, size-calibrated milestones over the following months: independent audits, monitoring capacity, board oversight, continuity testing. Smaller broadcasters could share or outsource security and monitoring rather than each rebuilding a large network’s infrastructure. And the standard should align with the national CERTs, not stand as a self-contained PEMRA regime.
There is also a distributional cost. A smaller regional channel may not be able to appoint a qualified CISO and procure a sophisticated monitoring stack as quickly as a large media group, and will file a roadmap it cannot yet operationalise. A uniform deadline does not close the gap between the secure and the exposed; it widens the gap between those who can afford genuine resilience and those who can only afford the paperwork that resembles it. And there is a subtler danger: when a standard is one almost no one can fully meet, large numbers of licensees may remain technically in breach. This creates scope for selective or inconsistent enforcement, an uncomfortable amount of discretion to attach to a broadcast licence.
Regulating cyber risk is imperative, and after the March attacks the instinct to act was legitimate. But being seen to act and reducing risk are not the same thing. The roadmaps will be filed, the consultants retained, the news cycle will move on. Pakistan has already shown, in its own financial sector, that cyber regulation can be sequenced, proportionate and supervised; the slower, harder work this deadline skips. The only question that matters is whether a single channel is harder to attack on 5 August than it was on 1 August and nothing in a three-day deadline makes the answer yes.
Share:
Zainab SamantashView all articles →
Comments
No comments yet. Be the first to join the discussion!
Related Articles





Trending Discussions
Loading…
Related:
Digital Automation Training Benin: 5 Winning Skills Employers Demand in 2026
<a href="https://yoursite.com/automation-africa/" title="WhatsApp Marketing Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria”>
WhatsApp Marketing Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria
Want to learn this practically?
Join Justfine Infotech and build real digital skills in AI, automation, web development, digital marketing, office productivity, e-commerce, freelancing and cybersecurity.
Available Programmes:
6 Weeks Certificate • 3 Months Professional Certificate • 6 Months Diploma • Full Professional Diploma
WhatsApp:
+229 01 57 57 99 15
+229 01 66 68 11 60
Source: profit.pakistantoday.com.pk



