Pakistan’s Digital Dependency:
Security in Someone Else’s Infrastructure
Fibre and surveillance
$ 0.50 b
Telecom
$ 1.92 b
Military China
$ 5.28 b
Military US
$ 6.54 b
When a government coordinates a military operation, processes intelligence, or manages critical national infrastructure, the technology enabling those functions belongs to someone. For Pakistan, that someone is almost always foreign. Its telecommunications backbone runs on Chinese hardware. Its military platforms operate under American licensing frameworks. Its government data sits on infrastructure subject to foreign legal jurisdiction. And its domestic regulatory architecture, while improving, has grown faster on paper than in practice.
Pakistan’s digital dependency is not unusual for a developing state. What makes it strategically significant is the context in which it exists. Pakistan operates under sustained security pressure, sits at the intersection of two competing great power technological spheres, and is deepening its digital dependencies precisely as regional tensions are rising. The 2025 India-Pakistan crisis confirmed what security analysts had argued for years: the cyber domain is not a secondary theatre of conflict. It is a primary one. Pakistan’s digital vulnerabilities are therefore not a technology policy problem to be managed gradually. They are a security liability that exists right now.
Two Tracks, One Problem
Pakistan’s digital dependency runs along two tracks that pull in opposite directions but produce the same structural vulnerability.
On the Chinese side, Pakistan’s infrastructure buildout under the China-Pakistan Economic Corridor has relied heavily on Huawei and ZTE for fibre optic networks, telecommunications equipment, and most recently a 400-gigabyte optical network spanning 72 sites nationwide. The Digital Silk Road, which Pakistan has formally identified as the next major phase of CPEC, extends this relationship into 5G, cloud computing, and artificial intelligence infrastructure. Pakistan gains connectivity and capability at significant speed and at costs that Western alternatives cannot match. It does so by binding its digital architecture to systems whose proprietary design, software standards, and operational dependencies are controlled in Beijing. China’s National Security Law requires Chinese technology firms to cooperate with state intelligence requirements on demand. Hardware and software built by companies subject to that law carries that obligation with it, regardless of where it is deployed.
On the American side, the dependency takes a different form but the structural consequence is similar. Pakistan operates F-16 aircraft and other military platforms under the International Traffic in Arms Regulations, the US export control framework that governs not only the physical sale of defence equipment but the software, technical data, and maintenance services attached to it. Washington retains legal authority over how that equipment is used, upgraded, and shared. That authority can be exercised at any moment, and has been in the past: Pakistan has experienced technology denials and export restrictions during periods of diplomatic friction with Washington. The US Bureau of Industry and Security issued specific heightened due diligence guidance on exports to Pakistan in 2019, a formal signal of the conditions under which American technology access can be restricted.
Beyond military hardware, Pakistan’s government and commercial data stored on American cloud platforms is subject to the US CLOUD Act, which allows American authorities to compel US technology companies to produce data stored anywhere in the world. Pakistani data on American servers is not governed by Pakistani law in any operationally meaningful sense. It is governed by American law, and can be accessed accordingly.
The Institutional Gap
Pakistan has recognised the problem. In early 2025, Parliament amended the Prevention of Electronic Crimes Act, expanding the legal basis for digital oversight and cyber incident response. A draft Cybersecurity Act has been circulated for review, proposing the establishment of a dedicated National Cybersecurity Authority, though it had not been enacted into law as of late 2025. Inter-agency cyber coordination continues to be managed through existing bodies including the CERT Council. The government’s Cloud-First Policy is pushing digital public services toward cloud-based delivery. The IT minister described the cyber domain as Pakistan’s first line of defence following the 2025 crisis, in which cyber operations were conducted alongside conventional military action for the first time at scale.”
ITU Global Cybersecurity Index 2024
96.69/ 100
Top tier, up from 79th place in the previous edition
Pakistan scored a full 20 out of 20 for legal measures. The index measures commitments such as laws, strategies and institutions, which is where Pakistan has moved fastest.
Strong on paper
Electronic crimes law amended, January 2025
3new bodies
- Social Media Protection and Regulatory Authority
- National Cyber Crime Investigation Agency
- Social Media Protection Tribunal
The National Assembly approved the amendment one day after it was introduced.
Enacted
Cyberattacks on Pakistan during the 2025 crisis
+700%
Attacks on India rose 500% over the same escalation, according to security firm SOCRadar.
Vendor estimate
- Cybersecurity Act
- Draft, not enacted as of late 2025
- National Cybersecurity Authority
- Proposed
- Inter-agency coordination
- CERT Council and existing bodies
These are meaningful steps. They do not, however, address the underlying structural problem. A regulatory authority cannot substitute for indigenous infrastructure. Legislation that creates oversight bodies does not reduce the exposure created by running sensitive state functions on foreign-owned platforms subject to foreign legal jurisdiction. Pakistan’s digital governance is fragmented across multiple agencies including the Ministry of IT and Telecom, the Pakistan Telecommunication Authority, the National IT Board, and the newly established cybersecurity bodies, without unified coordination or enforcement capacity across them.
The gap between policy ambition and institutional delivery is familiar territory in Pakistan. The National Action Plan experience showed what that gap costs in the security domain: measurable gains on paper that proved difficult to consolidate in practice. In the digital domain the same dynamic is visible. Pakistan has written the legislation, established the bodies, and articulated the strategy. What it has not yet built is the indigenous infrastructure those documents say it needs.
What Genuine Sovereignty Requires
Reducing Pakistan’s digital dependency in any meaningful sense requires movement on three fronts simultaneously.
The first
Data localisation
Ensuring that sensitive government and security sector data is stored on infrastructure under Pakistani legal jurisdiction, not subject to foreign court orders or intelligence access requirements.
This requires domestic data centre capacity that currently does not exist at the necessary scale.
The second
Diversification of technology suppliers
Reducing concentration in either the American or Chinese sphere without simply trading one dependency for another.
This is politically complex given Pakistan’s relationships with both Washington and Beijing, but technically achievable through open-source platforms and domestically developed systems in specific high-sensitivity domains.
The third
Retention of technical talent
Pakistan produces software engineers, cryptographers, and network architects of significant capability. It exports most of them.
The brain drain of technical expertise to better-paying markets abroad strips the state of precisely the human capital required to build and maintain indigenous digital infrastructure.
Reversing that dynamic requires conditions, economic and institutional, that Pakistan has not yet managed to create.
Pakistan faces a version of the digital sovereignty dilemma that European governments have spent the last several years confronting, but with less institutional capacity to address it, more acute geopolitical exposure, and competing dependencies pulling in opposite directions at once. Europe’s wealth, legal architecture, and alliance relationships have not insulated it from the problem. Pakistan’s position makes the problem sharper still.
2025
The crisis with India established that Pakistan’s adversaries are willing and able to operate in the cyber domain alongside conventional military action. Pakistan’s response demonstrated capability and resilience. What it also revealed is that the infrastructure underpinning that response remains substantially built on foundations Pakistan does not fully control. Addressing that is not a long-term ambition. It is an immediate requirement.