
Cyber threats lie under the umbrella of hybrid warfare. On top of a domestic security record that has already failed; the rapidly expanding CPEC and other digital infrastructure (foreign-built, inadequately vetted, and legally unscreened) sits inside a hostile India rivalry where attribution errors risk genuine escalation. The solution is diversified suppliers, own infrastructure, data protection laws, and legal screening.
Key Points
- Hybrid warfare is broader than cyber warfare; it includes disinformation and proxies.
- CPEC’s digital infrastructure is Chinese-built, with no Pakistan source-code access and no security screening law.
- The May 2025 India-Pakistan crisis showed active cyber conflict.
- NADRA leaked 2.7 million citizens’ data over 5 years, proving domestic infrastructure vulnerabilities aren’t hypothetical.
“Cyber warfare” and “hybrid war” are often used interchangeably, but they have distinct meanings. Cyberwar falls under the umbrella of hybrid warfare. Cyber is only one tool in a much wider hybrid toolkit, which includes disinformation, threat funding, and the use of proxies, all of which are blended and adapted as an attacker’s objectives change, as noted by Bernard Siman in an Egmont Institute brief. Because cyber is visible—a breach, a system knocked down—it receives the majority of attention. Because influence operations attack trust in institutions, the media, and the military rather than systems, they are more difficult to identify.
Threat Landscape
Pakistan’s vulnerability comes from a weak digital infrastructure, high strategic stakes, and a hostile regional environment. This can be seen in the ongoing digital hostility with India and in the CPEC infrastructure that is outpacing its security. Pakistan’s digital build-out under CPEC includes the Pakistan-China Optical Fiber Cable, an 820 km link connecting Rawalpindi to China. Around it sits a wider layer of Chinese-built infrastructure—city surveillance run by firms like Huawei and ZTE—where Pakistani engineers cannot access the underlying source code. What makes it a security question is that Pakistan still has no data protection law and no legal mechanism to screen foreign digital infrastructure for security risks.
Table 1: Regional Cybersecurity Comparison & Vulnerability (2025-2026 Context)
| Metric / Event | Pakistan | India | Strategic Impact |
|---|---|---|---|
| Global Cybersecurity Index | Ranked 79th / 183 | Ranked 10th / 183 | Significant capability gap |
| May 2025 Stand-off | Alleged interference with Govt sites | Exposed Tax Authority data | Risk of nuclear escalation |
| Infrastructure Control | No source-code access (CPEC) | Indigenized/vetted systems | Sovereignty & audit risks |
The May 2025 India-Pakistan stand-off demonstrated the destabilizing nature of cyber conflict where attribution is difficult. Even cybersecurity companies have been duped by group names like APT 36 (associated with Pakistan) and Sidewinder (associated with India). A misattributed cyber event close to vital infrastructure poses a serious concern in a nuclear-armed rivalry. Furthermore, Pakistan’s own infrastructure has already had numerous breaches. Data belonging to 2.7 million persons was compromised through NADRA offices between 2019 and 2023, surfacing as far away as Romania and Argentina.
Recommendations
- Pass Data Protection Law: The Personal Data Protection Bill has been in draft since 2018. Passing it is essential to regulate CPEC-linked data flows and establish localization requirements.
- Join Multilateral Mechanisms: Instead of waiting for bilateral trust with India, Pakistan should register a national focal point in the UN’s Global Intergovernmental Points of Contact Directory to verify cyber-events via impartial mechanisms.
- Supplier Diversification: Relying heavily on single suppliers (Huawei, ZTE, CISCO) concentrates risk. Pakistan must develop indigenous expertise to audit or build its own infrastructure.
- Legal Screening Mechanism: Pakistan needs a body similar to the US’s CFIUS to examine foreign investments in critical infrastructure for national security risks before they are launched.
* Tayyaba Naseer is a graduate from Government College University, Lahore. She has completed BS in International Relations, with the thesis focusing on Pakistan’s shift from geo-strategy to geo-economics. Currently, she is an intern at Diamanium Thinkers (A Global Think Tank). She chooses to write about the most significant human emotions and the world we live in. She is passionate about unearthing the hidden conspiracies that shape our world and how each of us is interlinked in this intricate web.
References