Every October, the world observes Cybersecurity Awareness Month — a global reminder that online safety is everyone's responsibility. In Pakistan, the Pakistan Telecommunication Authority (PTA) is leading the charge with its national awareness campaign, "Building a Safe, Secure, and Resilient Cyberspace," backed by the country's most consequential telecom security regulation to date: the Critical Telecom Data and Infrastructure Security Regulations, 2025 (CTDISR-2025).
For Pakistan's businesses and citizens alike, the timing could not be more urgent.

The State of Cyber Threats in Pakistan: 2025–2026 in Numbers
Pakistan's digital landscape is under sustained attack:
- 5.3 million+ on-device cyberattacks were recorded in Pakistan between January and September 2025 alone, alongside 2.5 million blocked web attacks, 166,000 banking malware detections, and 107,000 password-stealer attacks (Kaspersky).
- 157,465 cybercrime complaints were filed with the National Cyber Crime Investigation Agency (NCCIA) in 2025, the highest on record. Financial fraud dominated the caseload, with reported losses of PKR 2.7 billion, of which less than 17% has been recovered.
- In the first five months of 2026, 77,023 complaints were already logged, yet only eight convictions resulted — underscoring how far enforcement lags behind the threat.
- Globally, organizations now face an average of nearly 2,000 attacks per week, an 18% year-over-year increase, while the average cost of a single data breach has reached $4.88 million.
| Indicator | Figure | Period / Source |
| On-device cyberattacks | 5.3M+ | Jan–Sep 2025 (Kaspersky) |
| Blocked web attacks | 2.5M | Jan–Sep 2025 (Kaspersky) |
| Banking malware detections | 166,000 | Jan–Sep 2025 (Kaspersky) |
| Cybercrime complaints (NCCIA) | 157,465 | 2025 (NCCIA) |
| Financial fraud losses | PKR 2.7B (<17% recovered) | 2025 (NCCIA) |
| Complaints vs. convictions | 77,023 vs. 8 | First 5 months of 2026 (NCCIA) |
| Average global cost per data breach | $4.88M | IBM Cost of a Data Breach |

The Bottom Line: Prevention and awareness are not optional. They are the most cost-effective defence Pakistan has.
Real Incidents That Shook Pakistan
Recent years show how diverse and sophisticated attacks on Pakistan have become:
AI-Generated Deepfakes (2023)
Pakistan witnessed a political first when an AI-generated four-minute speech of an incarcerated former prime minister was broadcast at a virtual rally — a watershed moment proving that synthetic media can influence public opinion at scale.
State-Sponsored Espionage (2024–2025)
The SideWinder APT group escalated operations across South Asia in a campaign researchers call Operation SouthNet, deploying 50+ phishing domains, with new ones appearing every 3–5 days, impersonating Pakistani institutions including SUPARCO, the Pakistan Airports Authority, and naval entities. Pakistan accounted for 40% of the campaign's targets. Fake Outlook and Zimbra login portals harvested credentials from government and defence staff. In 2024, authorities also uncovered a fraudulent website posing as the Ministry of IT and Telecom, linked to the same threat actor.
Everyday Financial Fraud (Ongoing)
From hijacked social media accounts used to solicit money from family contacts, to WhatsApp takeovers and fake investment schemes, cyber-enabled financial crime remains the most pervasive threat to ordinary citizens.

CTDISR-2025: Pakistan's New Security Baseline
Gazetted on 31 December 2025, CTDISR-2025 replaces the 2020 framework and sets 84 mandatory regulations across 14 chapters for all PTA licensees. Its key obligations include:
| Obligation | What It Requires |
| Security Leadership | Appointment of a Chief Information Security Officer (CISO) and an Information Security Steering Committee chaired by the CEO |
| Zero Trust | Security architecture where no user or device is trusted by default |
| 24-Hour Breach Reporting | Breaches reported to the PTA's National Telecom CERT within 24 hours |
| Data Localization | Critical data must be hosted within Pakistan |
| Monitoring & Audits | Integration with the National Telecom SOC (nTSOC) and annual PTA-certified third-party audits |
For businesses, this is not just compliance paperwork. It is a blueprint for resilience and a signal to customers that Pakistan's digital economy is maturing.
Related: Data localization and disaster recovery go hand in hand. Explore our data centre and disaster recovery services for infrastructure hosted and protected inside Pakistan.
Gerry's IT: Turning Policy Into Practice
As part of the Gerry's Group, with over five decades of service across Pakistan, Gerry's Information Technology has delivered IT infrastructure, data centre, disaster recovery, and security solutions for more than 20 years. We fully endorse PTA's vision of a secure digital Pakistan, and we practice what we advocate: our own data protection framework operates on the Zero Trust model in alignment with CTDISR-2025, with encryption at rest and in transit, mandatory multi-factor authentication, and a designated CISO.
This Cybersecurity Awareness Month, Gerry's IT is committing to:
- Publish daily awareness content in Urdu and English, covering phishing, smishing, deepfakes, digital scams, and misinformation.
- Host employee briefings and expert webinars to strengthen our internal security culture.
- Amplify PTA's official campaign messages across our website, social channels, and customer portals.
- Share accessible educational material designed to reach citizens and businesses in every corner of Pakistan.
Corporate support is what transforms national policy into everyday practice.
Five Things Every Pakistani Should Do This October
Cybersecurity starts with you. Commit to one small action each day:
- Update your passwords — use unique, strong passwords for every account.
- Enable two-factor authentication (2FA) on email, banking, and social media.
- Verify before you click — check links and sender addresses, especially for "urgent" requests.
- Be sceptical of unexpected money requests — even from familiar accounts; confirm by phone call first.
- Report suspicious content to the platform, and file complaints with the NCCIA through its online portal or one of 15 reporting centres nationwide.
Together, We Build a Safer Cyberspace
The threats are real, growing, and increasingly AI-powered. But Pakistan now has the regulatory framework, the institutional machinery, and — through campaigns like this — the public awareness push to match them. Whether you are a telecom operator navigating CTDISR-2025 compliance, a business protecting customer data, or a citizen guarding your family's digital life: security is a shared responsibility.
Is your organization CTDISR-ready? Talk to Gerry's IT about security audits, Zero Trust implementation, and managed security services tailored to Pakistan's regulatory landscape.
Ready to Check Your CTDISR-2025 Readiness?
Schedule a consultation for a security audit and Zero Trust roadmap built around Pakistan's regulatory requirements.
Talk to a GIT Security Specialist →
Book a CTDISR-2025 Readiness Audit →
Frequently Asked Questions
When is Cybersecurity Awareness Month observed?
Every October worldwide. In 2026, Pakistan's PTA-led national campaign runs from 17–23 October under the theme "Building a Safe, Secure, and Resilient Cyberspace."
What is CTDISR-2025?
The Critical Telecom Data and Infrastructure Security Regulations 2025 — PTA's mandatory security framework for telecom licensees, gazetted 31 December 2025. It covers 84 regulations including Zero Trust adoption, 24-hour breach reporting, data localization, and annual third-party audits.
How big is the cybercrime problem in Pakistan?
NCCIA received over 157,000 complaints in 2025 alone, with reported financial fraud losses of PKR 2.7 billion. Kaspersky recorded over 5.3 million on-device attacks in Pakistan in the first nine months of 2025.
How can my business comply with CTDISR-2025?
Key steps include appointing a CISO, adopting Zero Trust architecture, localizing critical data, integrating with the National Telecom SOC, and passing an annual PTA-certified audit. Gerry's IT provides end-to-end compliance and security services.
Sources
- Kaspersky threat telemetry for Pakistan, Jan–Sep 2025 (via Cybersecurity Asia, Nov 2025)
- NCCIA figures presented to the National Assembly, 2025–2026
- PTA Critical Telecom Data and Infrastructure Security Regulations 2025 (S.R.O. 2504(I)/2025)
- Hunt.io / Trellix, SideWinder "Operation SouthNet" reporting, Oct 2025
- Check Point Research 2026 Security Report; IBM Cost of a Data Breach
- CISA, Cybersecurity Awareness Month (cisa.gov)
Gerry's Information Technology (GIT) — powering Pakistan's enterprises with resilient infrastructure, Zero Trust security, and compliance solutions engineered for what comes next.


