Operating a virtual asset business in Pakistan means navigating a developing regulatory landscape. Beyond the requirements for anti-money laundering and counter-terrorist financing (AML/CFT), a critical area for all prospective and licensed firms is cybersecurity. The integrity and security of client assets and data are paramount, not just for business continuity but also for maintaining trust and meeting regulatory expectations.

Cybersecurity is not merely an IT function; it is a core business responsibility that impacts every aspect of a virtual asset service provider (VASP). A robust cybersecurity framework protects against financial loss, reputational damage, and potential regulatory penalties. As Pakistan’s virtual asset framework takes shape, understanding these foundational requirements is essential for sustainable operation.

This analysis delves into the proposed cybersecurity requirements for virtual asset firms in Pakistan, drawing on the latest information from regulatory bodies. It aims to provide clarity for operators on what is expected to safeguard their systems, data, and client assets against evolving digital threats.

What are the core cybersecurity requirements for virtual asset firms?

The core cybersecurity requirements for virtual asset firms in Pakistan focus on protecting systems, data, and client assets from unauthorised access, use, disclosure, disruption, modification, or destruction. These mandates cover technical controls, operational procedures, and governance structures designed to ensure the resilience and integrity of a VASP’s entire digital infrastructure.

Regulators, including the Pakistan Virtual Assets Regulatory Authority (PVARA), are expected to mandate comprehensive cybersecurity frameworks. These frameworks typically align with international best practices, such as those from the National Institute of Standards and Technology (NIST) or ISO 27001. While the specific rules are still under consultation, the general principles are clear: firms must implement robust security measures across all their operations. This includes everything from network security and data encryption to employee training and incident response planning. The goal is to build a resilient environment that can withstand sophisticated cyber threats. Understanding the broader context of virtual asset regulation in Pakistan, including the role of PVARA, is crucial for all operators. For more details on the regulator, see our guide on what is PVARA? A plain-english guide to Pakistan’s virtual asset regulator.

Who do these cybersecurity requirements apply to?

These cybersecurity requirements apply to all entities seeking or holding a licence as a virtual asset service provider (VASP) in Pakistan, regardless of their specific licence category. This includes virtual asset exchanges, custodians, transfer service providers, and any other business engaged in virtual asset activities that fall under PVARA’s purview.

The scope extends to all aspects of a VASP’s operations that involve virtual assets, client data, or critical infrastructure. This means that whether a firm is primarily an exchange facilitating trades or a custodian holding client assets, it must adhere to the same foundational cybersecurity standards. The specific application may vary based on the scale and complexity of operations, but the underlying obligation to protect against cyber threats remains universal. Firms should review the PVARA licence categories explained: Finding your business fit to understand their specific obligations. Furthermore, the State Bank of Pakistan’s position on virtual assets also influences the broader financial landscape that VASPs operate within, as detailed in the State Bank of Pakistan’s crypto policy: What operators need to know.

What are the key areas of cybersecurity focus?

Key areas of cybersecurity focus for virtual asset firms encompass governance, risk management, technical controls, data protection, and incident response. These pillars ensure a holistic approach to security, addressing both preventive measures and the ability to react effectively to security breaches.

A comprehensive cybersecurity strategy goes beyond just firewalls and antivirus software. It involves a continuous cycle of identification, protection, detection, response, and recovery. Regulators expect firms to demonstrate a proactive approach to security, embedding it into their organisational culture and operational processes. This includes regular security assessments, employee training, and a clear chain of command for managing security incidents.

Governance and Risk Management

Effective cybersecurity starts at the top. Regulators expect VASP boards and senior management to take ultimate responsibility for cybersecurity risk. This involves establishing clear policies, assigning roles, and ensuring adequate resources are allocated.

Technical Controls and System Security

These are the foundational technical measures implemented to protect the VASP’s infrastructure, applications, and data.

  1. Network Security: Implementation of firewalls, intrusion detection/prevention systems, and network segmentation to isolate critical systems and restrict unauthorised access.
  2. Endpoint Security: Deployment of anti-malware, host-based firewalls, and data loss prevention (DLP) solutions on all devices accessing the VASP’s network.
  3. Access Controls: Strict access control mechanisms, including multi-factor authentication (MFA) for all internal and external access to systems and virtual asset wallets. This should follow the principle of least privilege.
  4. Data Encryption: Encryption of sensitive data both in transit and at rest. This includes client personal data, transaction records, and virtual asset wallet keys. For more on data retention, refer to VASP record keeping in Pakistan: What to retain and for how long.
  5. Secure Development Lifecycle (SDLC): For firms developing their own software, incorporating security considerations throughout the entire software development lifecycle, including secure coding practices and regular security testing.
  6. Vulnerability Management: Regular vulnerability scanning and penetration testing of all systems and applications. Identified vulnerabilities must be remediated promptly.
  7. Virtual Asset Custody Security: Robust security measures for virtual asset storage, including cold storage for a significant portion of assets, multi-signature wallets, and hardware security modules (HSMs). Specific rules govern how client virtual assets must be segregated, as outlined in our guide on virtual asset custody: Segregating client crypto in Pakistan.

Data Protection and Privacy

Protecting client data is a critical component of cybersecurity, intertwining with broader data privacy regulations.

Incident Response and Business Continuity

Even with the best preventive measures, incidents can occur. A VASP must be prepared to detect, respond to, and recover from security breaches.

How does FATF Recommendation 15 influence Pakistan’s cybersecurity rules?

FATF Recommendation 15, which focuses on new technologies, significantly influences Pakistan’s cybersecurity rules for virtual assets by requiring countries to regulate VASPs for AML/CFT purposes and manage associated risks. This recommendation mandates that countries ensure VASPs are subject to appropriate regulation and supervision, including for security.

The Financial Action Task Force (FATF) sets international standards to prevent money laundering and terrorist financing. Recommendation 15 specifically calls for countries to assess and mitigate the risks associated with virtual assets and VASPs. This includes ensuring that VASPs have robust controls to prevent misuse and protect the integrity of the financial system. For Pakistan, aligning with FATF standards is crucial, and this extends to mandating strong cybersecurity to protect against illicit activities and system vulnerabilities. The broader implications of this recommendation are detailed in our article what is FATF Recommendation 15 and why does it shape Pakistan’s rules?. These requirements are foundational for any entity seeking a VASP licensing service in Pakistan.

What role does the SECP play in VASP cybersecurity?

The Securities and Exchange Commission of Pakistan (SECP) plays a crucial role in VASP cybersecurity by overseeing the corporate governance, financial integrity, and operational resilience of companies, including those involved in virtual assets. While PVARA focuses on virtual asset specific regulation, SECP ensures broader company law compliance.

SECP’s mandate extends to ensuring that companies, including prospective VASPs, have adequate internal controls and risk management frameworks in place. This naturally encompasses cybersecurity as a critical component of operational risk. SECP might, for instance, require companies to demonstrate robust IT governance, data protection policies, and business continuity plans as part of their licensing or ongoing compliance. The interplay between SECP and virtual asset regulations is complex; our guide SECP’s role in Pakistan’s virtual asset regulation: A guide for operators provides further insights.

What should operators do to prepare for these requirements?

Operators should proactively develop and implement a comprehensive cybersecurity framework, conduct thorough risk assessments, and invest in appropriate technical and human resources. Engaging with regulatory guidance and seeking expert advice is also critical for effective preparation.

Given that Pakistan’s virtual asset framework is still under consultation, operators have an opportunity to build robust systems from the ground up. This involves:

A well-prepared firm will not only meet regulatory expectations but also build greater trust with its clients and stakeholders, establishing a strong foundation for long-term success in Pakistan’s virtual asset sector. For specific guidance on licensing and compliance, operators can also contact us.

About this analysis

This article was researched using publicly available information from Pakistani regulatory bodies such as the State Bank of Pakistan, the Securities and Exchange Commission of Pakistan (SECP), and the Financial Action Task Force (FATF), as well as general international best practices in virtual asset regulation and cybersecurity. As Pakistan’s virtual asset regulatory framework is currently at a consultation stage, specific requirements are subject to change and finalisation. Operators are strongly advised to verify all specific requirements directly with the Pakistan Virtual Assets Regulatory Authority (PVARA) or other relevant regulators. This content is provided for informational purposes only and does not constitute legal or professional advice. For more information about Sarzif Policy and our approach, please visit our about page and review our editorial policy. Further details on PVARA’s work can be found at https://pvara.org.

Noor Aslam, Chief Executive Officer of Sarzif Policy

Noor Aslam

Chief Executive Officer of Sarzif Policy, with eight years in virtual assets — four of them advising on VARA licensing in Dubai. She leads the research team that tracks Pakistan's framework and reviews every consultant shortlist that goes out. More about the team.

This article is information, not legal or financial advice. Regulatory positions change. Confirm any requirement against the official position published by PVARA before you act on it. Spotted an error? Write to sarzifpolicy@gmail.com and we will correct it.

Related updates