Cybersecurity Handbook Issued to Prevent Cyberattack on Government Systems

A new National Cybersecurity Handbook 2026-27 has been issued to prevent cyberattack risks across government departments, warning public-sector employees against using personal email accounts, unapproved devices, commercial cloud services and public AI tools for official or sensitive information. The document, released by the National Cyber Emergency Response Team (PKCERT) and the Ministry of IT and Telecommunications, sets baseline operational standards for digital security in all public-sector entities.

The handbook stresses that cybersecurity is not solely a technical responsibility but a shared one, as every user can affect the confidentiality, integrity and availability of government information assets. It outlines clear rules for handling official correspondence, devices and emerging technologies.

On artificial intelligence, the guidance highlights a growing area of cybersecurity risk. Officials are instructed not to enter classified government documents, official emails, source code or citizens’ personally identifiable information into public AI platforms. Government employees must use only AI tools authorised by their departments and should remove names and sensitive information from prompts or uploaded files. AI-generated outputs must also be reviewed by humans for accuracy and potential security implications.

The document further warns against installing unapproved AI extensions or plugins and against sharing administrative credentials, API keys or passwords with AI tools. These measures aim to prevent cyberattack vectors that could exploit careless AI usage.

One of the key instructions is that official email accounts must be used for government correspondence and departmental work. Personal accounts such as Gmail and Yahoo should not be used except where exceptionally authorised by the department, and official emails must not be forwarded to personal inboxes. The handbook also says official email addresses should not be used to register on shopping, gaming or social media websites, while mailing lists and directories should not be shared with unauthorised entities.

The issuance of the handbook reflects mounting concerns over digital security lapses in the public sector. By mandating these baseline standards, PKCERT and the Ministry of IT aim to reduce the likelihood of a cyberattack that could compromise sensitive government data or citizen information. The guidelines apply across all public-sector organisations and are expected to be enforced through departmental oversight.

While the handbook provides a framework, its success depends on compliance by individual employees and departments. The warning against personal emails, unapproved devices and public AI tools marks a significant tightening of operational rules. Officials will need to adapt their daily workflows to align with these requirements. The government’s proactive approach signals a recognition that human error remains a leading cause of security breaches, and that collective vigilance is essential to prevent cyberattack incidents.

Source: Dawn News

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles