Gulf Cooperation Council

External attack surface management for Bahraini organisations

Bahrain’s central bank expects external, public-facing systems to be assessed weekly or more often, and since August 2026 critical sector entities must run an annual cyber risk assessment under NCSC Decision 36/2026. Both start with knowing what you expose. EASMLens keeps that list current between assessments.

Serving organisations in Manama.

What the rules in Bahrain expect

Central Bank of Bahrain OM-5.5

The CBB Rulebook module on cyber security risk management requires licensees to run regular technical vulnerability assessments covering internal technology, external technology and connections with third parties. OM-5.5.25 says assessments should preferably be monthly for internal systems and weekly or more often for external public-facing services and systems. Penetration testing is required at least twice a year, and the SOC must maintain the asset inventory and network diagrams.

NCSC Decision 36/2026 and the national baseline

Royal Order 17/2025 gave the National Cyber Security Center powers to set mandatory policies, standards and controls. On 19 August 2026 NCSC Decision 36/2026 introduced cyber security standards for critical sectors, a national maturity measurement programme and a national risk assessment programme. Critical sector entities must apply the standards on notification and carry out an annual cyber risk assessment, repeated after incidents or major changes. The critical sector standards themselves are circulated privately and are not quoted here.

NCSC’s published baseline controls, still labelled as a draft, ask organisations to keep an asset inventory (3.1.1), enforce DMARC on inbound and outbound email (3.2.7), run periodic vulnerability assessments and annual penetration tests (3.3) and review third-party services (5.1.3).

Personal data protection

Under Ministerial Order 43/2022 made under Bahrain’s PDPL, controllers must inform the Personal Data Protection Authority within 72 hours of discovering a breach that affects data subjects’ rights, and must carry out periodic vulnerability assessment and penetration testing to verify their security measures.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
CBB OM-5.5.25External public-facing systems assessed preferably weekly or more oftenA continuously refreshed list of public-facing systems, so every weekly assessment is complete
NCSC Decision 36/2026 Art 8Annual cyber risk assessment for critical sectorsAn external exposure baseline and trend for each assessment
NCSC baseline 3.2.7Enforce DMARC on inbound and outbound emailDMARC policy and alignment for every domain you own
NCSC baseline 3.1.1Maintain an asset inventory, preferably automaticallyAutomated discovery of internet-facing assets missing from the register

Reporting clocks

  • CBB licensees

    Immediately, within one hour, with a full report including root cause within 10 calendar days

  • PDPL controllers

    72 hours to the Personal Data Protection Authority

  • NCSC baseline

    Inform NCSC and the sector regulator of medium and high incidents

Questions for the board

  1. 1Are our external public-facing systems assessed weekly or more often, as OM-5.5.25 prefers, and does that start from a complete list of what we expose?
  2. 2If we are in a critical sector under Decision 36/2026, does our annual risk assessment include an independent view of our internet-facing assets and supplier exposure?
  3. 3Is DMARC enforced on every domain we send from?

How EASMLens supports these obligations

  • Continuous discovery that keeps weekly external assessments complete
  • Exposure intelligence on public-facing services and third-party connections
  • DMARC, SPF, DKIM and DNSSEC grading for every domain
  • Trend evidence for annual NCSC risk assessments
Royal Order 17/2025 lets the NCSC set approval standards for devices and software used in critical sectors. No such standard had been published for software platforms at the time of writing. We will update this page if that changes.

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Does EASMLens replace CBB penetration testing?
No. EASMLens runs automated checks on your public-facing systems and keeps the list of them current, but it does not exploit anything. Your twice-yearly penetration tests by independent testers are still required.
Can you share the Decision 36/2026 critical sector standards?
No. Article 3 of the Decision says they are not for publication and are circulated to entities through secure channels.
Is the NCSC baseline final?
The public version is labelled as a draft. We describe it as NCSC’s published baseline rather than a final binding text.