Exposed by Design
SCADA, ICS, and the Cyber Vulnerability of Pakistan's Power Grid
Murtaza Asim Shehzad · Chief Executive, SSS
DOI 10.13140/RG.2.2.17302.72004
License CC BY 4.0 — free to share and adapt with attribution
Also on ResearchGate
Abstract
On 1 March 2026, Pakistan's national communication satellite PakSat-1R was hijacked. For several minutes its broadcast feed displayed scrolling anti-state messages before engineers regained control. The incident lasted minutes. The question it raises will last much longer: if Pakistan's satellite infrastructure can be penetrated and weaponised for strategic messaging, what does that imply for infrastructure that is simultaneously more critical and less visible — the power grid?
This working paper argues that Pakistan's electricity infrastructure, built on Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS), presents a Tier-1 national security exposure. The vulnerabilities are not hypothetical. They are the same classes of weakness that state-sponsored adversaries have already exploited to collapse power grids in Ukraine, probe infrastructure across Europe and North America, and attempt to trigger industrial disasters in the Middle East. Pakistan's grid is not meaningfully more secure than any of those targets. In several respects, it is less so.
Three findings anchor this assessment. First, Pakistan's grid architecture — aging legacy systems, inadequate IT/OT network separation, foreign vendor dependencies, and near-zero operational technology monitoring — creates an attack surface that Advanced Persistent Threats are designed to exploit. Second, Pakistan operates in a regional threat environment that includes state actors with both the capability and the strategic motivation to conduct sub-threshold infrastructure operations. Third, the institutional response, fragmented across NCCS, NEPRA, NTDC, and multiple DISCOs with no dedicated OT security mandate, is not commensurate with the threat.
The paper closes with a prioritised set of recommendations structured across three time horizons. It is submitted as a working paper, not a finished assessment, and the author explicitly invites challenge, correction, and expert input.
The question is not whether Pakistan can afford to close this gap. It is whether Pakistan can afford not to.
Three findings
01
Attack surface by architecture
Aging legacy SCADA/ICS, inadequate IT/OT separation, foreign vendor dependencies (including the CPEC dimension), near-zero OT monitoring, and unauthenticated industrial protocols (Modbus, DNP3, IEC 60870-5-104, IEC 61850) create a surface Advanced Persistent Threats are designed to exploit. NPCC is the highest-value node: compromise would not be local — it would set conditions for a nationwide cascade.
02
Credible threat actors
Pakistan sits inside, not outside, the infrastructure-cyber threat landscape. Regional state actors have capability and grey-zone incentives; vendor–state structural access is analytically distinct from external APTs; non-state actors are less capable alone but matter under state facilitation. Attribution in cyber remains probabilistic.
03
Institutional gap
National Cybersecurity Policy 2021 articulates intent without OT-specific mandates. NEPRA does not regulate cybersecurity. NCCS is IT-weighted with limited energy-sector authority. No energy-sector ISAC, no dedicated OT SOC, and no mandatory ICS security baseline comparable to NERC CIP or NIS.
Recommendations (summary)
Horizon 1 · 0–6 months
- Treat critical-infrastructure cyber as a National Security Committee standing agenda item
- Emergency security audit of NPCC EMS/SCADA
- Cross-agency critical-infrastructure cyber coordination cell + tabletop exercise
- Formal policy response treating PakSat as a systemic signal
Horizon 2 · 6–18 months
- NEPRA mandate for ICS/SCADA security standards, audits, incident reporting
- Dedicated energy-sector OT security operations centre
- Security governance framework for CPEC energy assets
- National ICS security training pipeline (NUST, UET, GIKI) and energy ES-ISAC
Horizon 3 · 18–36 months
- National cyber deterrence doctrine for critical infrastructure
- Cyber scenarios in national security planning and exercises
- Funded modernisation to phase out critical legacy SCADA/ICS (IEC 62443-aligned)
Author's note
This paper rests on open-source material, academic literature, technical documentation, threat intelligence reports, and policy documents. It was not commissioned and uses no classified sources. Where analysis reaches beyond what open sources strictly support, that is analytical judgement — challenge is welcome. Expert engagement is invited from energy-sector operations, OT security, national cybersecurity policy, and South Asian strategic affairs.
Responses: [email protected]
Cite
Shehzad, M. A. (2026). Exposed by Design: SCADA, ICS, and the Cyber Vulnerability of Pakistan's Power Grid (Working Paper 01). Star Strategic Systems. https://doi.org/10.13140/RG.2.2.17302.72004
Licensed under CC BY 4.0.
© Star Strategic Systems · March 2026 · All publications