{
  "id": 9538802,
  "title": "Pakistan Blocks Restoration of Hacked Govt Networks Without Approval",
  "url": "https://urgent.news/2026/09/24/pakistan-blocks-restoration-of-hacked-govt-networks-without-approval",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T09:54:31.000Z",
  "source": {
    "name": "ProPakistani",
    "slug": "propakistani",
    "url": "https://propakistani.pk/2026/09/24/pakistan-blocks-restoration-of-hacked-govt-networks-without-approval/"
  },
  "original_language": "en",
  "account": "The National Cybersecurity Handbook 2026-27 in Pakistan mandates that government departments cannot restore services or reconnect network segments compromised by cyberattacks until they obtain formal security clearance from the National Cyber Emergency Response Team (PKCERT). This requirement is stipulated in the handbook, which outlines how federal and provincial governments, as well as public-sector organizations, must respond to cybersecurity incidents.\n\nUnder the handbook, all cybersecurity incidents must be reported to PKCERT through approved channels, as well as to regional Computer Emergency Response Teams (CERTs) operating under the CERT Rules 2023. PKCERT teams are tasked with investigating critical cyber incidents, performing digital forensic analysis to ascertain how an attack occurred, evaluating its impact, and containing the threat. Upon conducting an investigation, government departments are obligated to provide investigators with immediate physical and administrative access to all affected systems, infrastructure, system logs, and other pertinent records.\n\nThe handbook also mandates that government organizations preserve digital evidence post-attack. This includes maintaining a strict chain of custody for compromised devices and storage media to ensure the integrity of the evidence throughout the investigation. Officials are barred from altering audit logs, firewall records, or memory dumps, and must prevent unauthorized vendors or personnel lacking the requisite clearance from accessing or interfering with systems placed under quarantine.\n\nCompliance with PKCERT's directives is crucial; government organizations are required to implement emergency measures and remediation instructions outlined by PKCERT investigators. The handbook warns that if systems are restored prematurely or an incomplete forensic investigation is conducted, hidden threats may remain within government networks, service disruptions could persist, and it would become more challenging for authorities to determine how the attack transpired, its origin, and the affected systems or information. Consequently, before restoring services or reconnecting quarantined network segments, government organizations must adhere to PKCERT's clearance requirements, preserving affected systems, cooperating with PKCERT investigations, and fulfilling the necessary containment and remediation measures.",
  "summary": "Government departments will not be allowed to restore services or reconnect network segments affected by cyberattacks until they receive formal … Read More The post Pakistan Blocks Restoration of Hacked Govt Networks Without Approval appeared first on ProPakistani .",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}