Behind on PEMRA's Cybersecurity Directive?
Talk to us about where your channel stands. We'll scope the gap assessment, CISO arrangement, and SOC/SIEM coordination needed to get you audit-ready.
PEMRA's 21 July 2026 directive requires every satellite TV licence holder to complete a third-party cybersecurity audit, stand up SOC/SIEM monitoring, and appoint a CISO — with a completion deadline of 4 August 2026 already behind us. If your channel is still working through this, Cyberox delivers the audit and CISO requirements directly, and coordinates the monitoring piece with a vetted partner.
On the night of 12 March 2026, an attempt was made to disrupt Khyber Network's live broadcast. It failed, but it was not isolated — Geo News, ARY News, and Samaa TV faced related disruptions in the same period. PEMRA responded first with a security advisory, then with a binding directive.
On 21 July 2026, PEMRA gave all satellite TV licence holders three working days to submit a detailed cybersecurity implementation roadmap, with completion of the core measures required by 4 August 2026. Channels were also directed to send their Chief Technical Officers and Chief Cyber Security Officers to a briefing at PEMRA's Islamabad headquarters.
The three required measures — a third-party cybersecurity audit, SOC/SIEM monitoring installed or outsourced, and a named CISO — are not arbitrary. They map directly onto the governance, monitoring, and audit domains of PKCERT's Pakistan Information Security Framework (PISF), the national baseline standard broadcasters are effectively being held to.
Current enforcement is concentrated on satellite TV licence holders, but the underlying obligation extends further.
The highest-profile enforcement target, given the live-transmission disruption risk that triggered PEMRA's directive in the first place.
Same licensing relationship with PEMRA, same three required measures, regardless of programming focus.
Not the current enforcement focus, but PKCERT's mandate covers broadcast media as a sector — this group should confirm status with PEMRA directly rather than assume exemption.
Two delivered directly by Cyberox. One coordinated through a vetted monitoring partner — we don't claim an in-house SOC we don't run.
A structured gap assessment against your network, uplink, and broadcast infrastructure, benchmarked against PISF's control domains and delivered as a report ready for PEMRA submission.
Our Gap Assessment serviceA virtual CISO with cross-industry incident exposure, meeting PEMRA's named-accountability requirement without the cost of a full-time in-house hire.
Our vCISO serviceWe define your monitoring specification and help you select and stand up an outsourced SOC/SIEM arrangement with a qualified partner, so this requirement is met without an unsubstantiated claim on our part.
Talk to us about scopeStructured around PISF's own four-phase roadmap, sequenced for urgency rather than a standard multi-month rollout.
Network, uplink, and access-control review against PISF's governance and core control domains. Produces the audit report PEMRA can request.
MFA on remote access, revoking excess access to playout and master control systems, and confirming encrypted backups — while the full program is built.
Virtual CISO onboarded to own the program; SOC/SIEM requirement scoped and handed to a vetted monitoring partner.
Evidence and records maintained so the channel can respond quickly if PEMRA requests proof of compliance progress.
The third-party audit PEMRA requires, benchmarked against PISF and delivered as a submission-ready report.
Learn moreMeet PEMRA's named-accountability requirement with a virtual CISO on a flexible retainer.
Learn moreFull overview of Cyberox's Pakistan and regional regulatory compliance coverage.
Learn moreTalk to us about where your channel stands. We'll scope the gap assessment, CISO arrangement, and SOC/SIEM coordination needed to get you audit-ready.