Pacific Islands
External attack surface management for Fiji
Fiji’s financial regulator has set some of the clearest cyber rules in the Pacific. The Reserve Bank of Fiji expects supervised entities to keep an accurate inventory of every asset, manage vulnerabilities without undue delay and report material incidents within 24 hours. EASMLens shows boards and security teams what their organisation exposes to the internet, including systems run by vendors and overseas parents.
Serving organisations in Suva, Nadi, Lautoka.
What the rules in Fiji expect
Reserve Bank of Fiji: PSPS No. 2
The RBF’s Prudential Supervision Policy Statement No. 2, in effect since 31 March 2023, sets minimum cyber security requirements for licensed banks, credit institutions, insurers and brokers, the securities exchange, fund managers, FNPF, Fiji Development Bank and foreign exchange dealers.
Paragraph 6.1.1 requires all information, processing and communication assets to be identified, inventoried and kept accurate. Paragraph 10.6 requires timely vulnerability information, an evaluation of exposure, and patching without undue delay, starting with high-risk systems. Paragraph 13 says the use of third parties must not weaken the control environment. Paragraph 15.3 expects vulnerability scans and penetration tests at regular intervals, at least for high-risk systems.
Payment service providers
Payment service providers came under their own RBF standard, PSP SPS No. 1, from 31 March 2025. It adds a cyber security strategy, penetration testing at least every three years and RBF approval before outsourcing.
A national strategy and a new CERT
The Government announced the Fiji CERT in October 2024 and launched the National Cybersecurity and Resilience Strategy 2026 to 2031 in March 2026, with protecting critical infrastructure among its aims. The strategy is policy rather than law, but it signals the direction regulators are taking.
The regional threat is real. A joint advisory by Australia’s ACSC, CERT Tonga and NCSC New Zealand in March 2026 warned that Pacific island states are being targeted by ransomware affiliates who break in through unpatched internet-facing devices and VPNs without multi-factor authentication.
What each rule asks for, and what EASMLens shows you
| Rule | What it asks for | What EASMLens shows you |
|---|---|---|
| PSPS No. 2, para 6.1.1 | Identify and inventory all assets; keep the inventory accurate | The internet-facing part of that inventory, discovered continuously rather than recorded once a year |
| PSPS No. 2, para 10.6 | Obtain vulnerability information in time; evaluate exposure; patch high-risk systems first | Known CVEs and end-of-life software on exposed services, prioritised by exposure |
| PSPS No. 2, para 13 | Third parties must not weaken the control environment | Services that vendors and parent companies run under your domains |
| PSPS No. 2, para 15.3 | Regular vulnerability scans and penetration tests | A complete target list, so periodic tests cover everything the internet can see |
Reporting clocks
RBF supervised entities
Within 24 hours of a cyber incident that materially affects the entity or its customers, plus a quarterly incident report
Questions for the board
- 1Can we give the RBF an accurate inventory under paragraph 6.1.1 that includes internet-facing systems run by our vendors and overseas parent?
- 2Between our periodic scans and penetration tests, what tells us when a new internet-facing service, certificate or email domain appears?
- 3Could we meet the 24-hour RBF clock if an incident started at a supplier’s exposed system?
How EASMLens supports these obligations
- Continuous discovery of the internet-facing assets behind your RBF asset inventory
- Exposure intelligence on known vulnerabilities and unsupported software, updated continuously
- Vendor and parent-company exposure under your brand and domains
- Email domain security grading to reduce impersonation of your bank, insurer or fund
EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.
Frequently asked questions
- Does Fiji have a data protection law?
- Not a general one yet. Drafting of a data protection bill was under way in 2026, but none had been tabled at the time of writing. Financial institutions are covered by the RBF cyber standard in the meantime.
- Does EASMLens replace the penetration testing PSPS No. 2 expects?
- No. EASMLens runs automated, non-destructive vulnerability checks, but it never exploits anything, so it does not replace penetration testing. It does make sure your tests and scans are pointed at everything you actually expose.
- Can we monitor subsidiaries and vendors too?
- Yes. You can monitor the external exposure of subsidiaries and key vendors alongside your own estate, which helps with the third-party expectations in paragraph 13.
Primary sources
- RBF PSPS No. 2 (2023)
- Fiji CERT announcement (Fiji Government)
- INC Ransom joint advisory, March 2026 (ACSC, CERT Tonga, NCSC NZ)
Regulatory content reviewed on . General information only, not legal advice.