Gulf Cooperation Council
External attack surface management for Kuwaiti organisations
Kuwait’s central bank now tiers banks partly on their attack surface. The CBK Cyber and Operational Resilience Framework, issued in December 2025, defines cyber risk exposure to include public-facing systems and legacy technology, and includes asset management, email security and digital risk protection controls. The NCSC’s National Basic Cybersecurity Controls follow, with an 18-month window to comply. EASMLens shows what that surface looks like from outside.
Serving organisations in Kuwait City.
What the rules in Kuwait expect
CBK Cyber and Operational Resilience Framework
The Central Bank of Kuwait issued CORF version 1.0 on 3 December 2025 for all local banks and financial institutions, replacing its 2020 cybersecurity framework. It combines cyber resilience, operational resilience and third-party risk baselines.
CORF’s tiering of entities considers cyber risk exposure, which it defines to include the attack surface created by digital transformation, legacy systems and public-facing systems. Its technology and operations domain includes asset management, email security, cybersecurity testing, threat intelligence and digital risk protection. We describe these areas rather than quoting individual control numbers.
National Basic Cybersecurity Controls
The National Cyber Security Center published its National Basic Cybersecurity Controls through Decision 2/2026 in April 2026, with 18 months to comply. They apply to civil government bodies, military and security bodies, critical private operators and other entities the NCSC designates, and are reported to follow the NIST Cybersecurity Framework functions, including asset inventory and monitoring. The full text was not publicly available when we checked, so treat detail as indicative.
Data privacy for ICT licensees
Kuwait has no comprehensive national data protection law. CITRA’s Data Privacy Protection Regulation (Resolution 26/2024) applies to its licensees and is reported to require breach notification within 72 hours. The Ministry of Health’s September 2024 cyber attack, which took hospital systems and a healthcare app offline, is a reminder of how public-facing services are affected.
What each rule asks for, and what EASMLens shows you
| Rule | What it asks for | What EASMLens shows you |
|---|---|---|
| CBK CORF tiering | Assess cyber risk exposure, including public-facing systems | The size and trend of your public-facing attack surface |
| CBK CORF asset management | Maintain accurate asset information | Internet-facing assets discovered continuously, including legacy systems |
| CBK CORF email security and digital risk protection | Protect email and monitor digital risks to the brand | Email domain posture and spoofing risk across every domain |
| NCSC NBCC | Asset inventory and monitoring | An external inventory that supports the NBCC identify function |
Reporting clocks
CITRA licensees
72 hours (as reported for Resolution 26/2024)
CBK and NBCC entities
Timings set in the instruments; confirm with your regulator
Questions for the board
- 1CBK tiers us partly on the attack surface of our public-facing systems. What is that surface today, and has it grown since December 2025?
- 2For NBCC entities: with the window closing around October 2027, is our asset inventory complete for internet-facing systems, including those run by suppliers?
- 3Do we monitor lookalike domains and email spoofing as part of CORF digital risk protection, or is that a gap?
How EASMLens supports these obligations
- Measurement of your public-facing attack surface over time
- Discovery of legacy and forgotten internet-facing systems
- Email security grading and spoofability checks for every domain
- Supplier exposure monitoring for CORF third-party baselines
EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.
Frequently asked questions
- Does CORF replace the 2020 CBK cybersecurity framework?
- Yes. CORF version 1.0, issued on 3 December 2025, supersedes the 2020 framework for local banks and financial institutions.
- When must NBCC entities comply?
- The controls were published in April 2026 with an 18-month window, which points to around October 2027. Check with the NCSC for your entity.
- Does EASMLens send traffic to our systems?
- Yes, lightly. EASMLens discovers your estate passively from DNS, certificate transparency and internet-wide datasets, then runs non-destructive active checks, such as service detection and web server checks, against the assets in your scope. It never attempts to exploit a vulnerability, and it is not a penetration test.
Primary sources
Regulatory content reviewed on . General information only, not legal advice.