Gulf Cooperation Council

External attack surface management for Omani organisations

Oman’s internet-facing government and business systems have been directly targeted. Research published in 2026 described a campaign that probed citizen portals and government mail servers from the outside. With a new national strategy, the Central Bank of Oman’s cyber resilience framework and a fully enforced data protection law, knowing your external estate is now a board question.

Serving organisations in Muscat, Sohar, Salalah.

What the rules in Oman expect

Central Bank of Oman cyber resilience framework

The Central Bank of Oman issued its Cyber Security and Resilience Framework (CS&RF) in September 2023 for banks, money exchange companies, payment service providers and finance and leasing companies, with controls due by July 2024. Its domains include technology and operations and third-party supply chain. The published framework is a scanned document, so we describe its scope rather than quoting clause numbers.

Personal data protection

The Personal Data Protection Law (Royal Decree 6/2022) and its Executive Regulation are overseen by MTCIT and are reported to be fully enforced from February 2026. Summaries of the regulation describe a 72-hour window to notify the Ministry of a breach that threatens data subjects’ rights. Exposed databases, file shares and forgotten systems are the fastest route to such a breach.

Government and critical infrastructure assessments

MTCIT’s Security Assessment Services Standard sets minimum requirements for providers carrying out vulnerability assessments, penetration tests and configuration reviews for government units and critical infrastructure. EASMLens does not replace those assessments. It gives assessors and owners a complete list of what is exposed, so each assessment starts from the real estate.

The threat is not theoretical. Research reported in 2026 found an attacker staging server documenting brute-force attempts against a police eVisa portal, exploit attempts against government mail servers and a web shell on a ministry system. Each entry point was an internet-facing service.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
CBO CS&RFTechnology, operations and third-party supply chain controlsInternet-facing assets you and your suppliers expose under your name
PDPL and Executive RegulationAppropriate security; breach notification to the MinistryExposed data stores and services that could lead to a notifiable breach
MTCIT Security Assessment Services StandardAssessments by qualified providers for government and CNIA complete external asset list to scope each assessment

Reporting clocks

  • PDPL controllers

    72 hours to the Ministry (as reported in summaries of the Executive Regulation)

Questions for the board

  1. 1If our mail servers, VPNs or customer portals were probed by the kind of campaign reported against Omani government bodies in 2026, would we know, and how quickly?
  2. 2For CBO licensees: can we evidence the framework’s technology and third-party controls with a current view of what suppliers expose on our behalf?
  3. 3Does every external security assessment we buy for government or CNI work start from a complete list of our internet-facing assets?

How EASMLens supports these obligations

  • Continuous discovery of portals, mail servers, VPNs and other internet-facing services
  • Exposure intelligence on known vulnerabilities, including mail server flaws
  • Supplier exposure monitoring for CBO third-party requirements
  • Email domain security grading for government and business domains

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Is EASMLens a security assessment provider under the MTCIT standard?
EASMLens is software that runs automated, non-destructive vulnerability checks. It does not carry out penetration tests. Whether the standard applies to a given government or CNI engagement depends on how the work is procured, so confirm with MTCIT before relying on EASMLens output as a formal assessment.
Why do you not quote CBO framework clause numbers?
The published framework is a scanned document. We would rather describe it accurately than quote numbers we cannot verify.
Is Arabic-language material available?
Contact us and we will provide Arabic material for your team or board.