Regions
External attack surface management, country by country
Regulators across Asia-Pacific, the Gulf and the UK now expect organisations to know what they expose to the internet. Each guide sets out the rules that apply in that country, the reporting clocks, and the questions boards should be asking, with links to primary sources.
Australia and New Zealand
Government stocktakes, critical infrastructure rules and prudential standards that name internet-facing systems.
Attack surface management in Australia
EASM for Australia: evidence for PSPF 0211, the Essential Eight, SOCI enhanced CIRMP rules and APRA CPS 234 from a continuous, outside-in view of your estate.
Attack surface management in New Zealand
EASM for New Zealand: evidence for MCSS Standard 3, PSR INFOSEC 1.1 and the Secure Government Email deadline in October 2026, with no agents to install.
Pacific Islands
New cyber security laws, central bank cyber standards and 24-hour reporting clocks in Fiji, Tonga and Papua New Guinea.
Attack surface management in Fiji
EASM for Fiji: an accurate asset inventory, vulnerability management and 24-hour incident reporting under the Reserve Bank of Fiji cyber standard.
Attack surface management in Tonga
EASM for Tonga: prepare for the Cybersecurity Act 2025, with periodic assessments and 24-hour reporting to CERT Tonga for critical infrastructure.
Attack surface management in Papua New Guinea
EASM for Papua New Guinea: government cyber and email standards, Bank of PNG technology risk rules and the draft Cybersecurity Bill 2026.
South East Asia
Critical infrastructure codes, central bank technology risk rules and service provider licensing in Indonesia, Malaysia and Singapore.
Attack surface management in Indonesia
EASM for Indonesia: the public asset list BSSN CSIRT registration needs, OJK cyber resilience rules and the UU PDP 3 x 24 hour breach notice.
Attack surface management in Malaysia
EASM for Malaysia: evidence for the Cyber Security Act 2024 (Act 854) and BNM RMiT, including the S 10.49 duty to manage third-party attack surfaces.
Attack surface management in Singapore
EASM for Singapore: evidence for CCoP 2026 asset inventory and DNSSEC clauses, MAS TRM vulnerability management and the amended Cybersecurity Act.
Gulf Cooperation Council
National controls, central bank frameworks and fast incident clocks across the six GCC states.
Attack surface management in United Arab Emirates
EASM for the UAE: evidence for the CIIP Policy, CBUAE Operational Risk Regulation C 1/2026 and ADGM cyber rules, from an outside-in view of your estate.
Attack surface management in Saudi Arabia
EASM for Saudi Arabia: evidence for NCA ECC-2:2024, NCNICC-1:2025 external application scanning, Haseen email records and SAMA asset discovery.
Attack surface management in Oman
EASM for Oman: support for the Central Bank of Oman cyber resilience framework, PDPL security duties and government security assessments.
Attack surface management in Bahrain
EASM for Bahrain: support for CBB OM-5.5 weekly external assessments, NCSC Decision 36/2026 risk assessments and DMARC enforcement, from outside.
Attack surface management in Kuwait
EASM for Kuwait: support for the CBK Cyber and Operational Resilience Framework, the NCSC National Basic Cybersecurity Controls and CITRA data rules.
Attack surface management in Qatar
EASM for Qatar: NCSA 2026 guidelines put external-facing assets in a 3 to 7 day fix window. Know which assets are exposed, plus QCB and NIAS rules.
External attack surface management across the GCC
How the UAE, Saudi Arabia, Oman, Bahrain, Kuwait and Qatar regulate the internet-facing estate: asset discovery, email security and incident clocks.
South Asia
New national frameworks and cyber security laws in Pakistan and Bangladesh.
Attack surface management in Pakistan
EASM for Pakistan: evidence for PISF 2026 web application and DMARC controls, PTA CTDISR and SBP technology risk rules, from an outside-in view.
Attack surface management in Bangladesh
EASM for Bangladesh: support for the Cyber Security Act 2026 annual external audits, Bangladesh Bank ICT Security Guideline v4.0 and the new PDP Act.
United Kingdom
Cyber Essentials scoping, the Cyber Assessment Framework and UK GDPR.