Australia
Attack Surface Management for Australian Organisations
Australian critical infrastructure and regulated entities must evidence what they own and what they depend on. EASMLens discovers the internet-facing estate that underpins those obligations.
What drives attack surface management here
SOCI Act and CIRMP
The Security of Critical Infrastructure Act covers 11 sectors and 22 asset classes. Responsible entities must maintain a Critical Infrastructure Risk Management Program taking an all-hazards approach across cyber, personnel, supply chain, and physical and natural hazards, and report annually with board approval within 90 days of the end of the financial year. A CIRMP depends on knowing which assets exist and which third parties you are exposed through, and that inventory is exactly what an external discovery programme produces.
Essential Eight and the ASD Essentials transition
The Essential Eight remains the most referenced Australian baseline, and in June 2026 the Australian Signals Directorate confirmed it will be replaced by a new Essentials series through a staged transition running to around 2028. Both are built on knowing what you are patching and hardening. Assets you have not discovered cannot be assessed against any maturity level.
APRA CPS 234
APRA-regulated entities must maintain information security capability commensurate with the size and extent of threats, and identify and classify information assets including those managed by third parties. Shadow IT and forgotten subdomains are the assets most often missing from that classification.
How EASMLens supports these obligations
- Continuous, agentless discovery of domains, subdomains, cloud services and exposed APIs
- Third-party and supply chain exposure, which is a named CIRMP hazard vector
- Evidence exportable for CIRMP annual reporting and board packs
- Change detection between scans, so new exposures surface within hours rather than at the next audit
EASMLens supports these obligations with discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.
Frequently asked questions
- Does EASMLens make us CIRMP compliant?
- No single tool makes an organisation compliant. A CIRMP is an all-hazards programme covering cyber, personnel, supply chain and physical risk. EASMLens addresses the asset discovery and external exposure elements of the cyber vector, and produces evidence for the annual report.
- How does this help with Essential Eight maturity?
- Maturity is assessed per strategy across your environment. If assets are unknown, patching and hardening cannot be evidenced for them. Discovery establishes the denominator before you measure the numerator.
- Can data stay in Australia?
- Data residency options are available. Tell us your specific requirement and we will confirm precisely what can be committed to in writing rather than in general terms.