LIVE · 25 Sept, 22:49 PKT
2.2k tenders546 orgs18 closing today28 new today
defenceWebGIDS Pakistan defence industry partners with Africa | AAD 2026·The Lufkin Daily NewsSaudi Arabia, Turkey and Pakistan sign joint defence deal in Mecca·The Shillong TimesPakistan strikes Afghanistan over drone attacks·presstv.co.ukPakistan executes precision strikes on 10 Afghan sites following drone incursion·QuwaPakistan Launches Air and Drone Strikes Into Afghanistan·QuwaWhat Azerbaijan’s JF-17 Deal Reveals About Pakistan’s Air Power Export Strategy·Daily ObserverPakistan launched air strikes on Afghan over drone attacks·The Defense PostFlorida Drone Maker Expands Asian Presence With Pakistan Defense Order·The Transylvania TimesPakistani airstrikes target Afghanistan after Islamabad accuses Kabul of drone attacks·Defence Security AsiaPakistan Orders US Drones as Washington–Beijing Arms Rivalry Reaches South Asia·SowetanPakistan launches airstrikes in Afghanistan after drone accusations·chinadailyasia.comPakistan strikes Afghan drone sites, no casualties reported·Bloomberg.comPakistan Strikes Afghanistan, Accuses Kabul of Drone Attacks·daily-sun.comAfghanistan dismisses Pakistan’s claims of drone incursion·defenceWebGIDS Pakistan defence industry partners with Africa | AAD 2026·The Lufkin Daily NewsSaudi Arabia, Turkey and Pakistan sign joint defence deal in Mecca·The Shillong TimesPakistan strikes Afghanistan over drone attacks·presstv.co.ukPakistan executes precision strikes on 10 Afghan sites following drone incursion·QuwaPakistan Launches Air and Drone Strikes Into Afghanistan·QuwaWhat Azerbaijan’s JF-17 Deal Reveals About Pakistan’s Air Power Export Strategy·Daily ObserverPakistan launched air strikes on Afghan over drone attacks·The Defense PostFlorida Drone Maker Expands Asian Presence With Pakistan Defense Order·The Transylvania TimesPakistani airstrikes target Afghanistan after Islamabad accuses Kabul of drone attacks·Defence Security AsiaPakistan Orders US Drones as Washington–Beijing Arms Rivalry Reaches South Asia·SowetanPakistan launches airstrikes in Afghanistan after drone accusations·chinadailyasia.comPakistan strikes Afghan drone sites, no casualties reported·Bloomberg.comPakistan Strikes Afghanistan, Accuses Kabul of Drone Attacks·daily-sun.comAfghanistan dismisses Pakistan’s claims of drone incursion·

Exposed by Design

SCADA, ICS, and the Cyber Vulnerability of Pakistan's Power Grid

Working Paper 01March 2026·14 pages · PDF·CC BY 4.0

Murtaza Asim Shehzad · Chief Executive, SSS

DOI 10.13140/RG.2.2.17302.72004

License CC BY 4.0 — free to share and adapt with attribution

Also on ResearchGate

Abstract

On 1 March 2026, Pakistan's national communication satellite PakSat-1R was hijacked. For several minutes its broadcast feed displayed scrolling anti-state messages before engineers regained control. The incident lasted minutes. The question it raises will last much longer: if Pakistan's satellite infrastructure can be penetrated and weaponised for strategic messaging, what does that imply for infrastructure that is simultaneously more critical and less visible — the power grid?

This working paper argues that Pakistan's electricity infrastructure, built on Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS), presents a Tier-1 national security exposure. The vulnerabilities are not hypothetical. They are the same classes of weakness that state-sponsored adversaries have already exploited to collapse power grids in Ukraine, probe infrastructure across Europe and North America, and attempt to trigger industrial disasters in the Middle East. Pakistan's grid is not meaningfully more secure than any of those targets. In several respects, it is less so.

Three findings anchor this assessment. First, Pakistan's grid architecture — aging legacy systems, inadequate IT/OT network separation, foreign vendor dependencies, and near-zero operational technology monitoring — creates an attack surface that Advanced Persistent Threats are designed to exploit. Second, Pakistan operates in a regional threat environment that includes state actors with both the capability and the strategic motivation to conduct sub-threshold infrastructure operations. Third, the institutional response, fragmented across NCCS, NEPRA, NTDC, and multiple DISCOs with no dedicated OT security mandate, is not commensurate with the threat.

The paper closes with a prioritised set of recommendations structured across three time horizons. It is submitted as a working paper, not a finished assessment, and the author explicitly invites challenge, correction, and expert input.

The question is not whether Pakistan can afford to close this gap. It is whether Pakistan can afford not to.

Three findings

  1. 01

    Attack surface by architecture

    Aging legacy SCADA/ICS, inadequate IT/OT separation, foreign vendor dependencies (including the CPEC dimension), near-zero OT monitoring, and unauthenticated industrial protocols (Modbus, DNP3, IEC 60870-5-104, IEC 61850) create a surface Advanced Persistent Threats are designed to exploit. NPCC is the highest-value node: compromise would not be local — it would set conditions for a nationwide cascade.

  2. 02

    Credible threat actors

    Pakistan sits inside, not outside, the infrastructure-cyber threat landscape. Regional state actors have capability and grey-zone incentives; vendor–state structural access is analytically distinct from external APTs; non-state actors are less capable alone but matter under state facilitation. Attribution in cyber remains probabilistic.

  3. 03

    Institutional gap

    National Cybersecurity Policy 2021 articulates intent without OT-specific mandates. NEPRA does not regulate cybersecurity. NCCS is IT-weighted with limited energy-sector authority. No energy-sector ISAC, no dedicated OT SOC, and no mandatory ICS security baseline comparable to NERC CIP or NIS.

Recommendations (summary)

Horizon 1 · 0–6 months

  • Treat critical-infrastructure cyber as a National Security Committee standing agenda item
  • Emergency security audit of NPCC EMS/SCADA
  • Cross-agency critical-infrastructure cyber coordination cell + tabletop exercise
  • Formal policy response treating PakSat as a systemic signal

Horizon 2 · 6–18 months

  • NEPRA mandate for ICS/SCADA security standards, audits, incident reporting
  • Dedicated energy-sector OT security operations centre
  • Security governance framework for CPEC energy assets
  • National ICS security training pipeline (NUST, UET, GIKI) and energy ES-ISAC

Horizon 3 · 18–36 months

  • National cyber deterrence doctrine for critical infrastructure
  • Cyber scenarios in national security planning and exercises
  • Funded modernisation to phase out critical legacy SCADA/ICS (IEC 62443-aligned)

Author's note

This paper rests on open-source material, academic literature, technical documentation, threat intelligence reports, and policy documents. It was not commissioned and uses no classified sources. Where analysis reaches beyond what open sources strictly support, that is analytical judgement — challenge is welcome. Expert engagement is invited from energy-sector operations, OT security, national cybersecurity policy, and South Asian strategic affairs.

Responses: [email protected]

Cite

Shehzad, M. A. (2026). Exposed by Design: SCADA, ICS, and the Cyber Vulnerability of Pakistan's Power Grid (Working Paper 01). Star Strategic Systems. https://doi.org/10.13140/RG.2.2.17302.72004

Licensed under CC BY 4.0.

© Star Strategic Systems · March 2026 · All publications