CTDISR-2025 Section 1 mandates the formal appointment of a Chief Information Security Officer for every PTA-licensed telecom operator. This is not a soft recommendation. It is a hard requirement, it is audited, and an auditor who finds no documented CISO appointment will record it as a finding regardless of how good your technical controls are. Without a designated accountability owner for cybersecurity, every other control in the framework is orphaned, and that's exactly how auditors treat it.

What the regulation does not specify is whether the CISO must be a full-time employee, a part-time hire, or an externally contracted role. That flexibility matters practically for the majority of Pakistani ISPs, which are not large enough to justify a full-time security executive but are large enough to need real governance.

What the CISO Role Actually Requires Under CTDISR-2025

The appointment itself needs to be documented: a board resolution, a formal letter, or equivalent documentation that names a specific person in the CISO role with a defined scope of responsibility. The name on that document is who the auditor will expect to find when they ask who owns cybersecurity governance at your organisation.

Beyond the appointment, the CISO has three hard regulatory deliverables under CTDISR-2025 that are audited directly.

The first is ISSC governance. The Information Security Steering Committee must be chaired by the CEO, but the CISO is responsible for running it operationally: setting the agenda, ensuring the required topics are covered (risk register, audit findings, incident summaries, policy reviews), and maintaining meeting minutes. Auditors look for minutes that demonstrate actual governance activity, not just a committee that exists on paper and hasn't met.

The second is board-level cybersecurity reporting. CTDISR-2025 requires cybersecurity status to be reported to the board at a defined cadence. The CISO owns producing that report, and the report format matters: it should cover risk posture, compliance status, incident activity, and remediation progress in a way that a board-level audience can act on. Auditors will ask for these reports.

The third is the 24-hour incident reporting obligation. When a qualifying incident occurs, the 24-hour clock to notify PTA starts at detection. The CISO is the accountable owner for ensuring that clock is met, that the notification format is correct, and that nTCERT coordination happens where required. An organisation without a designated CISO in an actual incident will discover that nobody owns this obligation, which compounds the incident with a compliance failure.

Full-Time Hire Versus Fractional CISO

A full-time CISO makes sense for larger operators: national ISPs, MNOs, LDI operators, infrastructure providers with complex multi-site environments. The governance workload at that scale, the volume of ISSC business, the breadth of policy work, and the incident response complexity justifies a dedicated resource.

For most Pakistani ISPs and WISPs, the honest answer is that the CTDISR-2025 governance obligations, at the actual volume of work they generate for a mid-sized operator, don't fill a full-time role. A Tier 1 WISP or a regional ISP needs four to six hours of CISO-level governance per month to meet the ISSC cadence, board reporting, and policy maintenance requirements. Hiring a full-time CISO at a salary that reflects the qualification the role requires is a poor economic fit for that workload.

A fractional CISO, contracted for a defined number of hours per month, covers the same regulatory obligations at a fraction of the cost, with the added advantage that a fractional arrangement from a firm with multiple ISP clients brings sector-specific knowledge that a standalone hire often doesn't.

The critical contractual boundary for a fractional CISO arrangement is scope. The governance role (ISSC, board reporting, policy, audit coordination) needs to be explicitly separated from technical remediation work. A CISO who is also doing the network hardening, deploying the SIEM, and running the pen tests is conflating governance with technical execution in a way that creates segregation of duties problems under Section 17, and that's an audit finding. The CISO governs, oversees, and holds accountable. Technical implementation is separate.

What an Auditor Checks for the CISO Requirement

The documentation check is: does a named individual hold the CISO role with a formal appointment document. The activity check is: can you produce ISSC meeting minutes from the past year showing the committee has convened at the required frequency. The substance check is: do the board reports show meaningful cybersecurity governance content, not just a status light that flips between green and amber.

The auditor will also look at whether the CISO was involved in incident handling if any incidents occurred during the audit period. A qualifying incident where the 24-hour PTA notification happened but the CISO had no documented involvement in the response is a governance gap even if the notification itself was timely.

How ISP World Structures the Role

Our CISO-as-a-Service is built around three engagement tiers by operator size. The governance deliverables are consistent across all tiers: ISSC setup and facilitation, board reporting, policy development, audit coordination, and the 24-hour incident reporting obligation. The hours per month scale with the complexity of the environment.

The scope boundary is contractual: governance responsibilities are explicitly separated from technical remediation, which is delivered separately through our service and product lines. That separation is deliberate and keeps both the governance function and the technical work clean for audit purposes.

If you haven't yet established the governance structure Section 1 requires and are approaching an audit cycle, CTDISR Audit Readiness covers the governance setup alongside the technical gap assessment. For visibility into your compliance posture across all 19 sections, ComplianceIQ gives the CISO a live dashboard rather than a point-in-time spreadsheet.