Pakistan’s Ministry of Information Technology and Telecommunication has issued a new cybersecurity guide for personnel working across government institutions. The National Cyber Emergency Response Team of Pakistan, known as PKCERT, prepared and published the National Cybersecurity Handbook. It applies to employees, officers, officials and technical staff in federal and provincial governments and public sector organisations. The handbook aims to make cybersecurity requirements easier to follow during routine official work. It offers practical instructions to prevent cyber incidents, protect sensitive data and strengthen government systems. Read More: Pakistanis Can Earn Up to $50,000 From OpenAI. Here’s How PKCERT says growing digital connectivity has made individual behaviour an important part of national cybersecurity. A careless click, weak password or unauthorised device can expose official information and disrupt public services. “Cybersecurity is therefore not solely a technical function, but a shared responsibility of every government employee,” the handbook states. The guidelines draw on national laws, regulations and government directives. They also incorporate internationally recognised standards and cybersecurity practices. Eight key cybersecurity areas covered The 34-page handbook organises its instructions into eight practical areas. These cover official email, device security, passwords, data protection, internet use, removable media, remote access and incident response. Employees should use official email accounts for government correspondence. They should also verify senders, links and attachments before responding or sharing information. The guide tells users not to forward official emails to personal accounts. It also warns against entering credentials through unverified links or forms. Government staff should use authorised devices for official work. They must obtain departmental approval before using personal equipment for government tasks. The password guidance calls for strong and unique passphrases. Employees should enable multi-factor authentication and avoid reusing passwords across personal and official accounts. Read More: This Simple Wi Fi Router Feature Can Help Protect Your Children Online PKCERT also warns staff against entering classified documents, citizen data, passwords, source code or administrative credentials into public artificial intelligence tools. Employees should use only AI platforms approved by their departments and review generated material before using it. For official data, the handbook recommends classification, encryption, controlled access and secure disposal. It also promotes regular backups on approved government infrastructure. Employees told to report incidents quickly The handbook requires government personnel to use approved USB drives and external storage devices. Staff should scan removable media before opening files and report missing devices immediately. Remote access to government systems should take place through authorised virtual private networks. Users should end remote sessions after completing their work and never share VPN credentials. Employees must immediately report suspicious emails, ransom notes, unauthorised access attempts, altered files or unusual system behaviour to their IT or cybersecurity teams. If a device shows signs of compromise, users should disconnect it from the network. However, they should not restart it or attempt repairs because those actions could destroy digital evidence. Under the CERT Rules 2023, organisations must report cybersecurity incidents to PKCERT through approved channels and relevant organisational, provincial or sectoral CERTs. The handbook converts requirements from the Pakistan Information Security Framework 2026, National Cyber Security Policy 2021 and CERT Rules 2023 into daily instructions. PKCERT said compliance can significantly reduce cyber risk. However, the government clarified that the handbook cannot provide complete protection against sophisticated threats. IT and cybersecurity teams must continue monitoring systems, updating controls and enforcing security requirements.