Attack surface compliance, by region
What each regulator actually requires for internet-facing assets. Every claim is cited to a primary source, and where a requirement is commonly misquoted we say so.
- Australia6 min read
External Attack Surface Management in Australia: PSPF 0211, SOCI and the Essential Eight
PSPF Requirement 0211 mandates continuous visibility of internet-facing systems. What Australian entities and SOCI responsible entities actually have to do.
- New Zealand6 min read
External Attack Surface Management in New Zealand: MCSS, NZISM and What Actually Binds You
New Zealand's attack surface obligation comes from MCSS, not NZISM. Standard 3, the CMM4 continuous monitoring expectation, and the two-day patch window.
- Malaysia7 min read
External Attack Surface Management in Malaysia: Act 854, NACSA and the Licensing Trap
Malaysia's Cyber Security Act 2024 requires scanning of all connected systems. It also licenses vulnerability assessment, including for foreign vendors.
- Saudi Arabia7 min read
External Attack Surface Management in Saudi Arabia: ECC-2, NCNICC and Aramco SACS
ECC-2:2024 requires penetration testing across all internet-provided services. What it really says about frequency, plus the new NCNICC private-sector controls.
- United Arab Emirates5 min read
External Attack Surface Management in the UAE: What Is Verified and What Is Not
An honest read of UAE cyber requirements for internet-facing assets, separating what is verifiable in primary sources from what is vendor marketing.
- United Kingdom7 min read
External Attack Surface Management in the UK: CAF v4.0, Cyber Essentials and the Web Check Gap
The NCSC published an EASM buyer's guide then retired Web Check. What CAF v4.0 and Cyber Essentials Plus v3.3 require for internet-facing assets.