Pakistan’s Digital Dependency:
Security in Someone Else’s Infrastructure

Fibre and surveillance

$ 0.50 b

Telecom

$ 1.92 b

Military China

$ 5.28 b

Military US

$ 6.54 b

When a government coordinates a military operation, processes intelligence, or manages critical national infrastructure, the technology enabling those functions belongs to someone. For Pakistan, that someone is almost always foreign. Its telecommunications backbone runs on Chinese hardware. Its military platforms operate under American licensing frameworks. Its government data sits on infrastructure subject to foreign legal jurisdiction. And its domestic regulatory architecture, while improving, has grown faster on paper than in practice.

Pakistan’s digital dependency is not unusual for a developing state. What makes it strategically significant is the context in which it exists. Pakistan operates under sustained security pressure, sits at the intersection of two competing great power technological spheres, and is deepening its digital dependencies precisely as regional tensions are rising. The 2025 India-Pakistan crisis confirmed what security analysts had argued for years: the cyber domain is not a secondary theatre of conflict. It is a primary one. Pakistan’s digital vulnerabilities are therefore not a technology policy problem to be managed gradually. They are a security liability that exists right now.

Two Tracks, One Problem

Pakistan’s digital dependency runs along two tracks that pull in opposite directions but produce the same structural vulnerability.

On the Chinese side, Pakistan’s infrastructure buildout under the China-Pakistan Economic Corridor has relied heavily on Huawei and ZTE for fibre optic networks, telecommunications equipment, and most recently a 400-gigabyte optical network spanning 72 sites nationwide. The Digital Silk Road, which Pakistan has formally identified as the next major phase of CPEC, extends this relationship into 5G, cloud computing, and artificial intelligence infrastructure. Pakistan gains connectivity and capability at significant speed and at costs that Western alternatives cannot match. It does so by binding its digital architecture to systems whose proprietary design, software standards, and operational dependencies are controlled in Beijing. China’s National Security Law requires Chinese technology firms to cooperate with state intelligence requirements on demand. Hardware and software built by companies subject to that law carries that obligation with it, regardless of where it is deployed.

The Institutional Gap

Pakistan has recognised the problem. In early 2025, Parliament amended the Prevention of Electronic Crimes Act, expanding the legal basis for digital oversight and cyber incident response. A draft Cybersecurity Act has been circulated for review, proposing the establishment of a dedicated National Cybersecurity Authority, though it had not been enacted into law as of late 2025. Inter-agency cyber coordination continues to be managed through existing bodies including the CERT Council. The government’s Cloud-First Policy is pushing digital public services toward cloud-based delivery. The IT minister described the cyber domain as Pakistan’s first line of defence following the 2025 crisis, in which cyber operations were conducted alongside conventional military action for the first time at scale.”

Pakistan’s response in numbers Figures from 2024 and 2025

ITU Global Cybersecurity Index 2024

96.69/ 100

Top tier, up from 79th place in the previous edition

Pakistan scored a full 20 out of 20 for legal measures. The index measures commitments such as laws, strategies and institutions, which is where Pakistan has moved fastest.

Strong on paper

Electronic crimes law amended, January 2025

3new bodies

  • Social Media Protection and Regulatory Authority
  • National Cyber Crime Investigation Agency
  • Social Media Protection Tribunal

The National Assembly approved the amendment one day after it was introduced.

Enacted

Cyberattacks on Pakistan during the 2025 crisis

+700%

Pakistan
India

Attacks on India rose 500% over the same escalation, according to security firm SOCRadar.

Vendor estimate

Cybersecurity Act
Draft, not enacted as of late 2025
National Cybersecurity Authority
Proposed
Inter-agency coordination
CERT Council and existing bodies

These are meaningful steps. They do not, however, address the underlying structural problem. A regulatory authority cannot substitute for indigenous infrastructure. Legislation that creates oversight bodies does not reduce the exposure created by running sensitive state functions on foreign-owned platforms subject to foreign legal jurisdiction. Pakistan’s digital governance is fragmented across multiple agencies including the Ministry of IT and Telecom, the Pakistan Telecommunication Authority, the National IT Board, and the newly established cybersecurity bodies, without unified coordination or enforcement capacity across them.

The gap between policy ambition and institutional delivery is familiar territory in Pakistan. The National Action Plan experience showed what that gap costs in the security domain: measurable gains on paper that proved difficult to consolidate in practice. In the digital domain the same dynamic is visible. Pakistan has written the legislation, established the bodies, and articulated the strategy. What it has not yet built is the indigenous infrastructure those documents say it needs.

What Genuine Sovereignty Requires

Reducing Pakistan’s digital dependency in any meaningful sense requires movement on three fronts simultaneously.

The first

Data localisation

Ensuring that sensitive government and security sector data is stored on infrastructure under Pakistani legal jurisdiction, not subject to foreign court orders or intelligence access requirements.

This requires domestic data centre capacity that currently does not exist at the necessary scale.

The second

Diversification of technology suppliers

Reducing concentration in either the American or Chinese sphere without simply trading one dependency for another.

This is politically complex given Pakistan’s relationships with both Washington and Beijing, but technically achievable through open-source platforms and domestically developed systems in specific high-sensitivity domains.

The third

Retention of technical talent

Pakistan produces software engineers, cryptographers, and network architects of significant capability. It exports most of them.

The brain drain of technical expertise to better-paying markets abroad strips the state of precisely the human capital required to build and maintain indigenous digital infrastructure.

Reversing that dynamic requires conditions, economic and institutional, that Pakistan has not yet managed to create.

Pakistan faces a version of the digital sovereignty dilemma that European governments have spent the last several years confronting, but with less institutional capacity to address it, more acute geopolitical exposure, and competing dependencies pulling in opposite directions at once. Europe’s wealth, legal architecture, and alliance relationships have not insulated it from the problem. Pakistan’s position makes the problem sharper still.

2025

The crisis with India established that Pakistan’s adversaries are willing and able to operate in the cyber domain alongside conventional military action. Pakistan’s response demonstrated capability and resilience. What it also revealed is that the infrastructure underpinning that response remains substantially built on foundations Pakistan does not fully control. Addressing that is not a long-term ambition. It is an immediate requirement.

Join our mailing list!