ISLAMABAD: Government employees and public-sector organisations have been warned against using personal email accounts, unapproved devices, commercial cloud services and public AI tools for official or sensitive government information.
Titled the “National Cybersecurity Handbook 2026-27”, the document, issued by the National Cyber Emergency Response Team (PKCERT) and the Ministry of IT and Telecommunications, outlines baseline operational standards for digital security across public-sector entities.
According to the handbook, cybersecurity is not solely a technical responsibility but a shared one, as every user can affect the confidentiality, integrity and availability of government information assets.
The handbook’s guidance on artificial intelligence highlights a growing area of cybersecurity risk.
Govt warns staff against using personal emails, devices, AI tools
It says officials should not enter classified government documents, official emails, source code or citizens’ personally identifiable information into public AI platforms.
Government employees are advised to use only AI tools authorised by their departments and to remove names and sensitive information from prompts or uploaded files.
AI-generated outputs should also be reviewed by humans for accuracy and potential security implications.
The document also warns against installing unapproved AI extensions or plugins and sharing administrative credentials, API keys or passwords with AI tools.
One of the key instructions is that official email accounts must be used for government correspondence and departmental work. Personal accounts such as Gmail and Yahoo should not be used except where exceptionally authorised by the department, while official emails must not be forwarded to personal inboxes.
The handbook further says official email addresses should not be used to register on shopping, gaming or social media websites, while mailing lists and directories should not be shared with unauthorised entities.
Only authorised government devices are to be used for official work. Where a personal device is operationally necessary, prior departmental authorisation is required, and the device must meet prescribed security standards.
Officials have similarly been instructed to use only sanctioned cloud services and approved applications.
The handbook places particular emphasis on the early reporting of cyber incidents. These include unauthorised access attempts, ransomware notes, suspicious emails, unusual deletion or modification of files and unexplained system behaviour.
Published in Dawn, September 19th, 2026
No comments yet. Be the first to comment!
© 2026 Star News 1. सर्वाधिकार सुरक्षित। गोपनीयता नीति | नियम और शर्तें | अस्वीकरण
🇮🇳 भारत माता की जय 🇮🇳