Pacific Islands

External attack surface management for Tonga

Tonga has passed one of the Pacific’s most complete cyber security laws. Once it commences, designated critical infrastructure operators must assess their security periodically and report incidents to CERT Tonga within 24 hours, including incidents on systems that merely connect to theirs. EASMLens gives operators and their suppliers a clear view of what they expose to the internet before that clock starts.

Serving organisations in Nuku‘alofa.

What the rules in Tonga expect

Cybersecurity Act 2025

The Cybersecurity Act 2025 received royal assent on 28 August 2025 and commences on a date proclaimed by Cabinet. It lets the Minister designate critical infrastructure, including electronic communications, banking and financial services, electricity, transport, utilities, health and government functions, and keep a register of operators.

Designated operators must carry out and submit periodic cyber security assessments (section 14), report incidents to CERT Tonga within 24 hours (section 15) and follow remedial orders. Section 15 also covers incidents on any information system interconnected with or communicating with critical systems, which brings suppliers and partners into scope. Civil penalties reach TOP 1,000,000 per contravention for a company.

Privacy Act 2025

The Privacy Act 2025 requires security measures that identify foreseeable internal and external risks and verify safeguards regularly. Its 72-hour breach notification rule only applies from the second anniversary of commencement, which gives organisations time to prepare.

Banking and the threat picture

The National Reserve Bank of Tonga’s Prudential Banking Standard No. 15 on cyber security has applied to banks since July 2021.

The Ministry of Health was hit by ransomware on 15 June 2025. CERT Tonga led the response with Australian support and systems were restored from backup. A joint advisory in March 2026 attributed the attack to INC Ransom, whose affiliates typically enter through unpatched internet-facing devices or VPNs without multi-factor authentication. The advisory does not say how the Ministry itself was breached, but the pattern is a clear reason to know every exposed entry point.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
Cybersecurity Act s14Periodic cyber security assessments by critical infrastructure operatorsAn evidence base of internet-facing assets and exposures to support each assessment
Cybersecurity Act s15Report incidents within 24 hours, including on interconnected systemsWhich supplier and partner systems connected to you are exposed, before an incident
Privacy Act s36Identify foreseeable external risks and verify safeguards regularlyExposed services, weak TLS and email spoofing risk across your domains

Reporting clocks

  • Designated critical infrastructure (once commenced)

    24 hours to CERT Tonga

  • Privacy Act 2025 controllers

    72 hours to the Commission, from the second anniversary of commencement

Questions for the board

  1. 1If we are designated critical infrastructure, what will our first section 14 assessment say about our internet-facing systems, and who will produce it?
  2. 2Could we report within 24 hours an incident on a supplier system that only connects to ours, and do we know which of those systems are exposed?
  3. 3Are our VPNs, remote access portals and edge devices inventoried and patched, given how ransomware groups have entered Pacific networks?

How EASMLens supports these obligations

  • Continuous discovery of internet-facing assets across your organisation and connected suppliers
  • Exposure intelligence on VPNs, remote access portals and edge devices with known vulnerabilities
  • Evidence you can use in the periodic assessments the Act requires
  • Email security grading to protect government and business domains from spoofing

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Is the Cybersecurity Act 2025 in force?
It received royal assent in August 2025 and commences on a date proclaimed by Cabinet. We had not found a proclamation at the time of writing, so check with CERT Tonga for the current position.
Would suppliers be affected?
Indirectly, yes. Section 15 covers incidents on systems that connect to or communicate with critical infrastructure, so operators will want to understand their suppliers’ exposure.
Does EASMLens send traffic to our systems?
Yes, lightly. EASMLens discovers your estate passively from DNS, certificate transparency and internet-wide datasets, then runs non-destructive active checks, such as service detection and web server checks, against the assets in your scope. It never attempts to exploit a vulnerability, and it is not a penetration test. Only include supplier systems you are authorised to test.

More in Pacific Islands