Cybersecurity Governance in the Digital Era and IT: Integrating Regulatory Oversight, Risk Management, and Organisational Resilience in Pakistan

Authors

  • Yasir Majeed The University of Lahore
  • Anas Majeed Victoria University Melbourne, Australia
  • Muhammad Tahir Minhas University of Management and Technology (UMT)

DOI:

https://doi.org/10.70670/sra.v4i1.1711

Keywords:

Cybersecurity Governance, Pakistan, Risk Management, Regulatory Oversight, Organisational Resilience, PECA 2016, National Cybersecurity Policy, Digital Transformation, NIST Framework, ISO 27001, IT Governance, PKCERT

Abstract

The increased pace at which the Pakistani economy and infrastructure in the public sector is being digitalised presents a logical multiplicity of cybersecurity threats that require a strong, multi-layered governance structure. The current paper looks at the present situation on cybersecurity governance in Pakistan with an emphasis on the combination of regulatory oversight, enterprise risk management, and organisational resilience. Based on leading international standards like the NIST Cybersecurity Framework 2.0 (NIST, 2024), the ISO / IE 27001:2022, the European Union General Data Protection Regulation (GDPR, 2016), and the NIS2 Directive (European Parliament, 2022) and placing them into the framework of the Pakistan socio-economic and institutional context, the paper will assess the efficacy of the current laws, including the Prevention of Electronic Crimes Act (PECA) 20 The study also explores the organizational level management of the risks in public institutions and the private companies in Pakistan in this research, and the findings revealed the gaps in systems of awareness, technology capacity, incident management, and inter-agency coordination. The paper claims that to address the issue of sustainable cybersecurity governance in Pakistan, a paradigm shift is needed, shifting reactive and compliance-based strategies toward proactive and resilience-oriented strategies enshrined in national digital transformation agendas.

Downloads

Published

20-02-2026

How to Cite

Yasir Majeed, Anas Majeed, & Muhammad Tahir Minhas. (2026). Cybersecurity Governance in the Digital Era and IT: Integrating Regulatory Oversight, Risk Management, and Organisational Resilience in Pakistan. Social Science Review Archives, 4(1), 1806–1829. https://doi.org/10.70670/sra.v4i1.1711