Pacific Islands

External attack surface management for Papua New Guinea

Papua New Guinea is building its cyber regime quickly. Public bodies already follow mandatory government cyber security and email standards, banks follow Bank of PNG technology risk rules, and a draft Cybersecurity Bill 2026 would add critical infrastructure duties and 24-hour reporting. EASMLens shows what each organisation actually exposes to the internet.

Serving organisations in Port Moresby, Lae.

What the rules in Papua New Guinea expect

Government standards under the Digital Government Act

The Digital Government Act 2022 established the National Cyber Security Centre. Under that Act, the PNG Government Cybersecurity Standards, Guidelines and Best Practices 2023 became mandatory for all public bodies from 1 July 2023. They require a patch programme covering all system assets, timely information on technical vulnerabilities, and continuous monitoring.

The companion Email Standards 2023 require public bodies to use .gov.pg for official email and to implement an approved email security solution. EASMLens can show which domains are sending mail on an agency’s behalf and how well each is protected against spoofing.

Bank of PNG technology risk management

The Bank of PNG’s Technology Risk Management Prudential Standard 2025 and its guide expect authorised financial institutions to run regular vulnerability assessments sized to the criticality and exposure of each system. The guide says the scope typically covers weak configurations, open network ports and application vulnerabilities, and that institutions should keep an up-to-date software inventory.

The draft Cybersecurity Bill 2026

DICT consulted on a draft Cybersecurity Bill until 19 August 2026. It proposes NICTA as an interim National Cybersecurity Authority, designation of critical information infrastructure with security plans, risk assessments and audits, continuing accountability for systems hosted in the cloud or by third parties, and incident notification within 24 hours. It is a draft, not law.

Recent events show why. The NCSC has issued advisories on actively exploited internet-facing products such as Citrix NetScaler and Microsoft WSUS, and the Internal Revenue Commission suffered a reported cyber attack in January 2025.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
Government Cybersecurity Standards 2023Patch all system assets; track technical vulnerabilities; monitor continuouslyInternet-facing government assets with known vulnerabilities, refreshed continuously
Government Email Standards 2023Official mail on .gov.pg with an approved email security solutionWhich domains send mail for an agency and their SPF, DKIM and DMARC posture
BPNG TRM Guide 2025Vulnerability assessments covering open ports and web applicationsThe full list of exposed services and ports, so assessments miss nothing
Draft Cybersecurity Bill 2026Security plans and accountability for cloud and third-party hosted systemsAssets in offshore clouds and supplier platforms that carry your name

Reporting clocks

  • Critical information infrastructure (proposed)

    24 hours, then a full report

  • Private organisations today

    No general statutory incident reporting duty found

Questions for the board

  1. 1If our systems are designated critical information infrastructure, could we show a live register of internet-facing assets, including those in offshore clouds we remain accountable for?
  2. 2For banks: does our vulnerability assessment scope cover every open port and web application the internet can see, or only what IT has recorded?
  3. 3Are our official domains protected against spoofing, and would a 24-hour reporting clock be achievable?

How EASMLens supports these obligations

  • Discovery of domains, IPs, open services and certificates attributed to your organisation
  • Exposure intelligence mapped to advisories like those NCSC PNG publishes
  • Email domain security grading for government and business domains
  • Visibility of systems hosted in offshore clouds and by suppliers
The draft Cybersecurity Bill 2026 proposes licensing for providers of cybersecurity auditing, penetration testing, forensics and managed security services. EASMLens is a software platform that runs automated vulnerability checks. It does not provide auditing, penetration testing, forensics or managed security services, but the final wording of the Bill, and whether automated checks fall within it, is not yet known. We will review the position when the Bill is finalised.

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Is the Cybersecurity Bill 2026 law?
No. Consultation closed on 19 August 2026 and the Bill had not been enacted at the time of writing.
Does PNG have a data protection law?
Not yet. A Data Governance and Data Protection Bill 2026 went to consultation in August 2026.
Does EASMLens replace a vulnerability assessment?
Not on its own. EASMLens runs automated checks and shows what is exposed, which strengthens your vulnerability assessments, but the Bank of PNG expects a documented assessment programme around it.

More in Pacific Islands