Gulf Cooperation Council
External attack surface management for Bahraini organisations
Bahrain’s central bank expects external, public-facing systems to be assessed weekly or more often, and since August 2026 critical sector entities must run an annual cyber risk assessment under NCSC Decision 36/2026. Both start with knowing what you expose. EASMLens keeps that list current between assessments.
Serving organisations in Manama.
What the rules in Bahrain expect
Central Bank of Bahrain OM-5.5
The CBB Rulebook module on cyber security risk management requires licensees to run regular technical vulnerability assessments covering internal technology, external technology and connections with third parties. OM-5.5.25 says assessments should preferably be monthly for internal systems and weekly or more often for external public-facing services and systems. Penetration testing is required at least twice a year, and the SOC must maintain the asset inventory and network diagrams.
NCSC Decision 36/2026 and the national baseline
Royal Order 17/2025 gave the National Cyber Security Center powers to set mandatory policies, standards and controls. On 19 August 2026 NCSC Decision 36/2026 introduced cyber security standards for critical sectors, a national maturity measurement programme and a national risk assessment programme. Critical sector entities must apply the standards on notification and carry out an annual cyber risk assessment, repeated after incidents or major changes. The critical sector standards themselves are circulated privately and are not quoted here.
NCSC’s published baseline controls, still labelled as a draft, ask organisations to keep an asset inventory (3.1.1), enforce DMARC on inbound and outbound email (3.2.7), run periodic vulnerability assessments and annual penetration tests (3.3) and review third-party services (5.1.3).
Personal data protection
Under Ministerial Order 43/2022 made under Bahrain’s PDPL, controllers must inform the Personal Data Protection Authority within 72 hours of discovering a breach that affects data subjects’ rights, and must carry out periodic vulnerability assessment and penetration testing to verify their security measures.
What each rule asks for, and what EASMLens shows you
| Rule | What it asks for | What EASMLens shows you |
|---|---|---|
| CBB OM-5.5.25 | External public-facing systems assessed preferably weekly or more often | A continuously refreshed list of public-facing systems, so every weekly assessment is complete |
| NCSC Decision 36/2026 Art 8 | Annual cyber risk assessment for critical sectors | An external exposure baseline and trend for each assessment |
| NCSC baseline 3.2.7 | Enforce DMARC on inbound and outbound email | DMARC policy and alignment for every domain you own |
| NCSC baseline 3.1.1 | Maintain an asset inventory, preferably automatically | Automated discovery of internet-facing assets missing from the register |
Reporting clocks
CBB licensees
Immediately, within one hour, with a full report including root cause within 10 calendar days
PDPL controllers
72 hours to the Personal Data Protection Authority
NCSC baseline
Inform NCSC and the sector regulator of medium and high incidents
Questions for the board
- 1Are our external public-facing systems assessed weekly or more often, as OM-5.5.25 prefers, and does that start from a complete list of what we expose?
- 2If we are in a critical sector under Decision 36/2026, does our annual risk assessment include an independent view of our internet-facing assets and supplier exposure?
- 3Is DMARC enforced on every domain we send from?
How EASMLens supports these obligations
- Continuous discovery that keeps weekly external assessments complete
- Exposure intelligence on public-facing services and third-party connections
- DMARC, SPF, DKIM and DNSSEC grading for every domain
- Trend evidence for annual NCSC risk assessments
EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.
Frequently asked questions
- Does EASMLens replace CBB penetration testing?
- No. EASMLens runs automated checks on your public-facing systems and keeps the list of them current, but it does not exploit anything. Your twice-yearly penetration tests by independent testers are still required.
- Can you share the Decision 36/2026 critical sector standards?
- No. Article 3 of the Decision says they are not for publication and are circulated to entities through secure channels.
- Is the NCSC baseline final?
- The public version is labelled as a draft. We describe it as NCSC’s published baseline rather than a final binding text.
Primary sources
- NCSC Decision 36/2026 (Arabic)
- NCSC baseline cyber security controls
- CBB Rulebook OM-5.5
- Royal Order 17/2025 (Arabic)
- Personal Data Protection Authority
Regulatory content reviewed on . General information only, not legal advice.