South Asia

External attack surface management for Pakistani organisations

Pakistan’s new national framework covers every externally accessible web application an organisation runs, wherever it is hosted, and requires SPF, DKIM and DMARC on email domains. PKCERT’s 2026 advisories show why: exposed firewall management interfaces were being compromised at scale. EASMLens gives security teams and boards a continuous, outside-in view of that estate.

Serving organisations in Karachi, Lahore, Islamabad.

What the rules in Pakistan expect

Pakistan Information Security Framework 2026

PKCERT published the merged PISF 2026 in March 2026, and the Federal Cabinet was reported to have approved it in August 2026. It applies to federal and provincial ministries, departments, autonomous bodies, corporations and designated critical information infrastructure.

PISF requires an inventory of information assets with their vulnerabilities and threats (3.5), a vulnerability and patch management lifecycle with continuous monitoring (5.6), and security requirements for all internal and externally accessible web applications regardless of the hosting environment, including regular vulnerability assessment and remediation tracking (10.4). Control PISFID-168 requires SPF, DKIM and DMARC for organisations that run email services. Section 10.4 also asks organisations hosting websites outside Pakistan to plan migration to local data centres.

Telecoms: PTA Critical Telecom Data and Infrastructure Security Regulations

The PTA’s CTDISR 2020 apply to all licensees. They require critical telecom assets to be inventoried with named owners (9(2)), critical patches applied within 72 hours (9(11)), vulnerability scans, penetration tests at least every six months (13(3)) and breach reporting within 72 hours (18(2)).

Banking: SBP technology governance

The State Bank’s Enterprise Technology Governance and Risk Management Framework requires banks, DFIs and microfinance banks to keep an inventory of information assets with owners (2.4.1), monitor external interfaces and connections for attacks (2.5), and run vulnerability assessments and periodic penetration tests (2.7). Significant cyber breaches must be reported to SBP within 48 hours.

What PKCERT is seeing

PKCERT’s June 2026 advisory described a large-scale compromise of internet-exposed FortiGate firewalls and VPN gateways, tens of thousands worldwide, and gave the first action as removing management interfaces from public internet access. Knowing which of your management interfaces are reachable from the internet is exactly the question EASMLens answers.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
PISF 10.4Security for all externally accessible web applications, wherever hostedEvery public web application attributed to you, including those hosted outside Pakistan
PISF PISFID-168SPF, DKIM and DMARC on email domainsSPF, DKIM and DMARC status for every domain, including dormant and campaign domains
PISF 3.5, 5.6Asset inventory with vulnerabilities; continuous monitoringInternet-facing assets with known vulnerabilities, refreshed continuously
PTA CTDISR 9(2), 9(11)Inventory critical telecom assets; patch critical issues within 72 hoursExposed telecom-facing services with critical CVEs so the 72-hour clock starts on time

Reporting clocks

  • Banks (SBP ETGRMF)

    48 hours for significant cyber breaches

  • CII under PISF

    Detailed report within 72 hours; data breaches within 72 hours

  • Non-CII entities under PISF

    120 hours for verified incidents and data breaches

  • PTA licensees (CTDISR)

    72 hours from discovery of a breach

Questions for the board

  1. 1PISF covers every externally accessible web application wherever it is hosted. Do we have that list, and which of those applications are still hosted outside Pakistan?
  2. 2Are all our email domains, including dormant and campaign domains, on enforced DMARC with SPF and DKIM?
  3. 3After the FortiGate advisory, how many of our firewall or VPN management interfaces are reachable from the internet today?

How EASMLens supports these obligations

  • Discovery of every public web application and service, wherever it is hosted
  • Email security grading against the SPF, DKIM and DMARC expectations in PISF
  • Detection of exposed management interfaces and edge devices with known vulnerabilities
  • Evidence that supports audits by PKCERT-registered audit firms

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Is PISF 2026 mandatory?
It applies to government bodies and designated critical information infrastructure. It was reported as approved by the Federal Cabinet in August 2026; check the current notification for your organisation.
Is EASMLens a PKCERT audit firm?
No. EASMLens is a software platform, not an audit service. Registered audit firms can use its evidence, and they carry the registration.
Can we point EASMLens at any system?
Only at systems you own or are authorised to test. Unauthorised access to critical infrastructure systems is an offence under PECA 2016. EASMLens never exploits vulnerabilities, but its active checks do send traffic to the assets in your scope, so keep that scope to assets you are responsible for.

More in South Asia