When Cybersecurity Becomes National Security

Pakistan and the Chinese machine it already owns

There is a question I have heard asked at three conferences in Islamabad this year, and it is never asked politely. If every major Chinese tech company now answers to the state, who are they answering to when the state is not theirs? The question has an edge because the people asking it are holding Chinese-made equipment. I do, professionally, in ways I will describe. Pakistan, the country whose security I have spent a career thinking about, holds rather more of it.

The law that sits above the shareholder

Start with the law, because the law is where the fact lives. In June 2017 China’s National People’s Congress passed the National Intelligence Law. Article 7 requires all organisations and citizens to support, assist and cooperate with national intelligence work. [1][2] The Cybersecurity Law of 2017, the Data Security Law, and the Personal Information Protection Law of 2021 add further requirements concerning data security, security assessments, and regulatory oversight. [3][4] Taken together, these laws create a regulatory environment in which Chinese technology companies may face obligations to cooperate with state authorities. Whatever a board might prefer, the statute sits above the shareholder and the state sits above the statute. When cybersecurity becomes national security, the company stops being only a vendor. It becomes an instrument of policy, in precisely the way the law describes.

What Pakistan has already bought

Now look at what we have installed under that legal sky. The China–Pakistan Fibre Optic Project runs 820 kilometres from Rawalpindi toward the Khunjerab Pass at a cost of roughly forty-four million dollars, carrying voice and data between the two countries as a CPEC core project. [5] At least nine Pakistani cities have taken Huawei Safe City systems since 2015, including a data centre in Islamabad whose arrival prompted a genuine argument about digital sovereignty. [6] Islamabad’s own Safe City deployment close to two thousand cameras and five hundred kilometres of fibre was financed by a Chinese Eximbank loan. [7] Our mobile networks run in large part on Huawei and ZTE equipment, because it is affordable.

Exposure is not espionage

I have installed and audited some of this equipment myself, so let me be exact about what the risk is and what it is not. There is no public technical proof that Huawei or ZTE has ever placed a backdoor in a Pakistani network on Chinese state instruction. The allegation is made repeatedly in Western capitals and has never been confirmed by technical evidence in the public record. What the law establishes is something different, and for a security professional more interesting: a legal channel that could be used, a duty binding the vendor to a foreign intelligence service, and a company that cannot publicly refuse. In our field this is a supply-chain trust problem. It is not a claim of espionage. It is a claim of exposure and exposure is measurable, manageable, and ours to govern.

The comparison that stings

When Washington or Brussels worries about Chinese law, it writes a procurement ban and walks away; the European Union is moving to exclude Huawei and ZTE from key telecom networks. [8] Pakistan cannot walk away. The fibre is already in the ground, the cameras are already on the poles, and the base stations hum in every city we love. Our geography, our budget and our one dependable strategic partnership all point toward Beijing. Sovereignty here is not a shopping decision. It is an architecture we have to build around equipment we already own a harder discipline than a ban, and in some ways a more honest one. We are not choosing whether to live with Chinese technology. We are choosing on whose terms.

The architecture begins with law, and implementation matters

Pakistan’s National Cyber Security Policy dates to 2021, and our enforcement bodies are young: the national CERT was certified under rules made in 2023. [9][10] The Personal Data Protection Bill has been promised for years without becoming an enforceable privacy statute. The PECA amendment of 2025 added policing powers and content controls, which is a different thing from data governance, and civil-society scrutiny of it has been severe. [11][12] In practice, Pakistan has expanded its surveillance and digital-security capabilities and has not yet built a credible accountability framework around it. That asymmetry is the real national-security risk not the equipment, but the absence of rules binding whoever holds it.

Five moves

Procurement with leverage. Every future contract with any foreign vendor Chinese, European or otherwise should require source-code escrow, third-party security testing and local control of cryptographic keys, so that the state rather than the supplier holds the master switch. Data residency. Pakistani citizens’ data should live on Pakistani soil under Pakistani law, which means finishing the data-protection statute instead of leaving it in committee purgatory. Vendor-neutral audit. A technical audit body, staffed by Pakistanis and answerable to parliament rather than to any ministry, able to test any network regardless of whose logo is on the router without asking permission from the vendor or its embassy. Redundancy. The fibre to China is a national asset, but a single secure route is a dependency. We should be building alternate capacity, including undersea routes that do not transit any one partner’s territory, so that no neighbour can switch us off. And quietly, the fifth: train more of our own. Every Pakistani engineer who can read a network trace, audit a router or hold a cryptographic key is a unit of sovereignty that no contract can recall.

None of this is anti-China

I want to say that plainly, because the debate usually collapses into cartoon. China has built infrastructure Pakistan needed and could not fund alone. The friendship is real and useful, and there is no version of Pakistan’s future in which it is not central. But friendship between states, like trust between machines, works best when it is verified. A security professional’s job is not to choose whose politics he prefers. It is to make sure the networks his country depends on answer, first and last, to his own country.

A room outside Islamabad

I think often about a day I spent in a network operations centre outside Islamabad, in a room of Pakistani engineers keeping a Chinese-built system alive through a load-shedding blackout, drinking chai that had gone cold while they rerouted traffic around a fibre cut. The system worked. The engineers were excellent. The question that followed me out of that room was simple. Everything in it answered to a contract, and the contract answered to a law, and the law answered to a state that was not ours. That is the whole story of cybersecurity as national security, told in one line. Pakistan’s task in the decade ahead is to become the last word in that chain the sovereign that owns its keys, audits its own wires, and can look any partner in the eye and say: friend, yes; master, no.

References

1. National Intelligence Law of the People’s Republic of China (2017), Article 7. China Law Translate. Source
2. National Intelligence Law of the People’s Republic of China. Wikipedia. Source
3. China’s New Data Security and Personal Information Protection Laws. Skadden, Arps, Slate, Meagher & Flom, November 2021. Source
4. Translation: Personal Information Protection Law of the People’s Republic of China, effective 1 November 2021. Stanford DigiChina. Source
5. Information Technology projects under CPEC. CPEC Secretariat, Government of Pakistan. Source
6. Nikkei Asia reporting on Huawei Safe City deployments in Pakistan. Source
7. Islamabad Safe City project, China Eximbank loan project record 37016. AidData, William & Mary. Source
8. Reporting on European Union moves to exclude Huawei and ZTE from key telecom networks. Pakistan TV Global. Source
9. Policies and Legislation. Pakistan Computer Emergency Response Team (PKCERT). Source
10. Pakistan Computer Emergency Response Team. Wikipedia. Source
11. Pakistan: Authorities pass bill with sweeping controls on social media. Amnesty International, January 2025. Source
12. Data Protection Laws of the World: Pakistan. DLA Piper. Source

The views presented in this article are the authors’ own and do not necessarily reflect the views of Global Strategic Forum – GSF.

Imran Bhatti

Imran Bhatti holds an M.Phil. in Governance and Public Policy and professional certifications as a Certified Information Systems Security Professional (CISSP) and Project Management Professional (PMP). He is a geopolitical analyst and writer specializing in energy geopolitics, great-power competition, Eurasian strategic affairs, and South Asian security dynamics. His work explores regional geopolitics, border disputes, infrastructure, security, and economic statecraft in an increasingly multipolar world.

About Imran Bhatti 6 Articles
Imran Bhatti holds an M.Phil. in Governance and Public Policy and professional certifications as a Certified Information Systems Security Professional (CISSP) and Project Management Professional (PMP). He is a geopolitical analyst and writer specializing in energy geopolitics, great-power competition, Eurasian strategic affairs, and South Asian security dynamics. His work explores regional geopolitics, border disputes, infrastructure, security, and economic statecraft in an increasingly multipolar world.

Be the first to comment

Leave a Reply

Your email address will not be published.


*