Gulf Cooperation Council

External attack surface management for Kuwaiti organisations

Kuwait’s central bank now tiers banks partly on their attack surface. The CBK Cyber and Operational Resilience Framework, issued in December 2025, defines cyber risk exposure to include public-facing systems and legacy technology, and includes asset management, email security and digital risk protection controls. The NCSC’s National Basic Cybersecurity Controls follow, with an 18-month window to comply. EASMLens shows what that surface looks like from outside.

Serving organisations in Kuwait City.

What the rules in Kuwait expect

CBK Cyber and Operational Resilience Framework

The Central Bank of Kuwait issued CORF version 1.0 on 3 December 2025 for all local banks and financial institutions, replacing its 2020 cybersecurity framework. It combines cyber resilience, operational resilience and third-party risk baselines.

CORF’s tiering of entities considers cyber risk exposure, which it defines to include the attack surface created by digital transformation, legacy systems and public-facing systems. Its technology and operations domain includes asset management, email security, cybersecurity testing, threat intelligence and digital risk protection. We describe these areas rather than quoting individual control numbers.

National Basic Cybersecurity Controls

The National Cyber Security Center published its National Basic Cybersecurity Controls through Decision 2/2026 in April 2026, with 18 months to comply. They apply to civil government bodies, military and security bodies, critical private operators and other entities the NCSC designates, and are reported to follow the NIST Cybersecurity Framework functions, including asset inventory and monitoring. The full text was not publicly available when we checked, so treat detail as indicative.

Data privacy for ICT licensees

Kuwait has no comprehensive national data protection law. CITRA’s Data Privacy Protection Regulation (Resolution 26/2024) applies to its licensees and is reported to require breach notification within 72 hours. The Ministry of Health’s September 2024 cyber attack, which took hospital systems and a healthcare app offline, is a reminder of how public-facing services are affected.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
CBK CORF tieringAssess cyber risk exposure, including public-facing systemsThe size and trend of your public-facing attack surface
CBK CORF asset managementMaintain accurate asset informationInternet-facing assets discovered continuously, including legacy systems
CBK CORF email security and digital risk protectionProtect email and monitor digital risks to the brandEmail domain posture and spoofing risk across every domain
NCSC NBCCAsset inventory and monitoringAn external inventory that supports the NBCC identify function

Reporting clocks

  • CITRA licensees

    72 hours (as reported for Resolution 26/2024)

  • CBK and NBCC entities

    Timings set in the instruments; confirm with your regulator

Questions for the board

  1. 1CBK tiers us partly on the attack surface of our public-facing systems. What is that surface today, and has it grown since December 2025?
  2. 2For NBCC entities: with the window closing around October 2027, is our asset inventory complete for internet-facing systems, including those run by suppliers?
  3. 3Do we monitor lookalike domains and email spoofing as part of CORF digital risk protection, or is that a gap?

How EASMLens supports these obligations

  • Measurement of your public-facing attack surface over time
  • Discovery of legacy and forgotten internet-facing systems
  • Email security grading and spoofability checks for every domain
  • Supplier exposure monitoring for CORF third-party baselines

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Does CORF replace the 2020 CBK cybersecurity framework?
Yes. CORF version 1.0, issued on 3 December 2025, supersedes the 2020 framework for local banks and financial institutions.
When must NBCC entities comply?
The controls were published in April 2026 with an 18-month window, which points to around October 2027. Check with the NCSC for your entity.
Does EASMLens send traffic to our systems?
Yes, lightly. EASMLens discovers your estate passively from DNS, certificate transparency and internet-wide datasets, then runs non-destructive active checks, such as service detection and web server checks, against the assets in your scope. It never attempts to exploit a vulnerability, and it is not a penetration test.

Related guides

Primary sources

Regulatory content reviewed on . General information only, not legal advice.