Australia6 min read

External Attack Surface Management in Australia: PSPF 0211, SOCI and the Essential Eight

Australia has the most explicit external attack surface mandate of any market we operate in, and most organisations have not read it.

PSPF Requirement 0211, effective 1 July 2025 and carried into PSPF Release 2026, states that entities must create a Technology Asset Stocktake and Technology Security Risk Management Plan to "identify and manage the entity's internet-facing systems or services" to ensure "continuous visibility and monitoring" of the technology estate.

That is a description of external attack surface management written into government policy. Not asset management generally. Internet-facing systems specifically, with continuous visibility named as the outcome.

What the Essential Eight actually requires

The Essential Eight Maturity Model, still at its November 2023 version, is more precise about internet-facing assets than most summaries admit. At every maturity level, identically, it requires that "a vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services", and separately for the operating systems of internet-facing servers and internet-facing network devices.

The patch windows are where people get it wrong. For internet-facing services and devices it is 48 hours where a vulnerability is critical or a working exploit exists, and two weeks otherwise. Internal operating systems and workstations get a month. If you have seen "two weeks for internet-facing" quoted without the 48-hour caveat, that summary is incomplete.

Daily scanning of online services is not a posture you can maintain with a quarterly penetration test and a spreadsheet. It requires automation, and it requires knowing what your online services are in the first place, which is the harder half of the problem.

SOCI and the enhanced CIRMP rules

The Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 were registered on 9 June 2026 and commenced the following day. They bind nine asset classes: broadcasting, DNS, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel and water.

Two provisions matter for attack surface work. Section 8C(2)(a) requires responsible entities to identify and maintain "an inventory of critical systems and how they are connected with other critical systems and other computers". Section 8A(3) upgrades the cyber framework obligation from Essential Eight Maturity Level One to Maturity Level Two, which is a meaningful step up in scanning and patching discipline.

There is a 24-month grace period, so the obligation bites around 10 June 2028. That sounds distant. Building an accurate inventory of connected critical systems in an environment that has grown organically for a decade does not take two months, and the annual CIRMP report is due within 90 days of financial year end, on 28 September, board-approved.

The edge device problem ASD keeps writing about

In February 2025 the Australian Signals Directorate published guidance on edge devices that is unusually direct. It states that "it is critical that an organisation regularly identifies all assets within their environment using an automated method of asset discovery", and that organisations "should consider developing their attack surface monitoring capabilities to enhance visibility of what their network edge looks like from the internet".

The guidance also notes that edge devices are "frequently discovered existing outside enterprise asset management consoles". That is shadow IT stated plainly by the national signals authority.

ASD's Annual Cyber Threat Report for 2024 to 2025, published 14 October 2025, recorded more than 120 incidents involving edge devices, of which 96 percent were successful. Edge devices are not a marginal category. They are the front door, they are frequently unmanaged, and attackers know it.

What this means practically

If you are a Commonwealth entity, PSPF 0211 already applies and asks for exactly this capability. If you are a responsible entity for one of the nine enhanced SOCI asset classes, you have an inventory obligation and an Essential Eight Maturity Level Two obligation arriving together. If you are neither, you are almost certainly a supplier to someone who is, and the requirement will reach you contractually.

The common failure is scoping the problem to what you already know about. An asset inventory built from your CMDB tells you about the systems you remembered to record. It tells you nothing about the marketing microsite a contractor stood up in 2023, the test environment that was never decommissioned, or the certificate on a subdomain nobody owns. Those are the assets that get exploited, precisely because nobody is watching them.

EASMLens discovers internet-facing assets from the outside, the way an attacker enumerates them, then monitors them continuously for exposure and CVE risk. That is the gap between an asset register and an attack surface.

Other regions