The National Cyber Security Agency has warned that the risk of cyberattacks on state, financial, and other critical digital infrastructures may increase during the upcoming Eid-ul-Azha holiday period.
It said reduced staffing, limited monitoring, and slower emergency response during the holidays could be exploited by cybercriminal groups, hacktivists, and organized threat actors to carry out various cyberattacks.
The agency has urged all national critical information infrastructure, banks, financial institutions, and public and private essential service providers to follow a set of security directives, including:
24/7 monitoring: Continuous monitoring of all critical servers, networks, applications, SIEM, SOC, and security systems must be ensured.
Incident response readiness: Cyber incident response teams must remain on standby at all times, with updated emergency contact lists.
Security updates: All servers, firewalls, endpoints, VPNs, email systems, and security devices must be updated with the latest security patches.
Multi-factor authentication (MFA): MFA must be enabled for all key administrative accounts, remote access systems, VPNs, and email accounts.
Privileged access control: Administrative privileges should be restricted, with strengthened logging and monitoring.
Backup and disaster recovery: Secure offline backups of critical data and configurations must be maintained, and disaster recovery plans kept operational.
Phishing awareness: Staff must be alerted to suspicious emails, links, attachments, and fraudulent instructions during the holiday period.
Service hardening: Unnecessary services, open ports, test accounts, and inactive access should be disabled temporarily.
Web and system monitoring: Internet-facing systems, web applications, and DNS infrastructure must be regularly monitored and secured.
DDoS and ransomware protection: Anti-DDoS, endpoint detection and response (EDR), anti-malware, and other protective systems must remain active.
Log management: System logs must be preserved and analyzed to detect suspicious activity quickly.
Third-party access control: Vendor and third-party remote access should be restricted and closely monitored.
Emergency communications: Alternative communication channels (phone, email, messaging apps) must remain active for SOC/NOC coordination.
Incident reporting: Any suspicious activity, unauthorized access, data breach, or malware infection must be reported immediately, with all relevant logs and evidence preserved.
Contact emails: [email protected], [email protected], [email protected]
Authorities have also been instructed to maintain SOC/NOC duty rosters during the holiday period, ensure proper system backups, and remain vigilant against misinformation, fake messages, and online fraud campaigns.
All institutions have been urged to maintain maximum vigilance and coordination to safeguard critical national infrastructure, financial systems, and citizen services.


