Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Industry

Cyber resilience for fleets, ports and everything ashore

A vessel is a floating industrial site with a skeleton crew, an intermittent satellite link and equipment that will still be running in twenty years. Add a port estate, a charterer’s systems and a shore-side ERP, and maritime becomes one of the hardest security problems there is. HexaShield covers all of it as one estate.

90%
of world trade moves by sea
Cyber disruption to a fleet or terminal is a supply-chain event, not just an IT one.
Where we are brought in

Three problems we are asked to solve at sea

A vessel is an operational technology estate that moves, loses connectivity, and changes crew every few weeks. These are the three situations fleet and technical leaders bring to us most often, what we put against each, and what changes for the business as a result.

01

Nobody holds a current picture of what is on the vessel network

OT
The problem

Shoreside IT is documented. Aboard, ECDIS, engine management, ballast, cargo and power systems were integrated by different yards and vendors across two decades of refits. There is no current inventory, the drawings are out of date, and nothing may be actively scanned while the vessel is under way.

How HexaShield solves it

Operational Technology, delivered on HexaOT. Passive and non-intrusive by design, so discovery and monitoring never interrupt a safety-critical or continuous process. One unified view from bridge and engine control through to field and remote assets, per vessel and across the fleet.

Operational TechnologyHexaOT
The business outcome

A current asset picture you can actually stand behind, per vessel and fleet-wide. Change aboard becomes visible as it happens rather than being discovered at the next dry dock, and questions from class, flag or a charterer are answered from evidence instead of from memory.

02

An incident at 03:00 mid-ocean is reported by telephone

SOC
The problem

Vessels are intermittently connected, crews rotate, and shared operational credentials remain normal practice. When something goes wrong at sea, the shore team usually finds out when the master calls, or when a system stops doing what it should.

How HexaShield solves it

Managed SOC / MDR, run on HexaSOC, with HexaOT feeding correlated vessel telemetry into the same operation. AI agents triage in seconds; HexaShield analysts own every consequential action, 24/7. What you see, we see, through HexaView.

Managed SOC / MDRHexaViewHexaSOCHexaOT
The business outcome

Events aboard surface ashore as they develop rather than after the fact. The master receives an instruction from people who already hold the vessel context, instead of a question. Technical superintendents stop being the first line of cyber triage.

03

Remote maintenance access nobody has a register for

GRC
The problem

OEM engineers, technical superintendents, ship managers, class surveyors and port systems all touch vessel systems, frequently under arrangements agreed years ago by someone who has since left. Access is real, active and largely unmapped.

How HexaShield solves it

Cyber Intelligence on HexaInt for third-party risk intelligence and dark-web monitoring of exposed credentials, working alongside Governance, Risk and Compliance on HexaComply for vendor risk, questionnaires and supply-chain visibility.

Cyber Intelligence, Governance Risk & ComplianceHexaIntHexaComply
The business outcome

You know who holds access, to what, and which of those parties is currently exposed. Supplier assurance becomes a live register rather than an annual spreadsheet, and a vendor problem stops quietly becoming your vessel problem.

What sits behind it

The problems, and what answers each

Each situation, the capability that answers it and the platform it is delivered on
#The situationCapabilityDelivered on
01Nobody holds a current picture of what is on the vessel networkOperational TechnologyHexaOT
02An incident at 03:00 mid-ocean is reported by telephoneManaged SOC / MDRHexaView, HexaSOC, HexaOT
03Remote maintenance access nobody has a register forCyber Intelligence, Governance Risk & ComplianceHexaInt, HexaComply

What your regulators, class societies and charterers are asking for

IMO cyber risk management expectations within the safety management system (MSC-FAL.1/Circ.3) · IACS UR E26 and E27 for newbuild vessels and onboard systems · flag state and class society survey questions · charterer and P&I due-diligence questionnaires.

We map the ones that apply to your jurisdiction, flag, licence or trade during onboarding rather than assuming them here. Compliance frameworks and regulatory requirements change over time; the specific frameworks in scope, and their current requirements, are confirmed and verified with your counsel during onboarding.

Schedule an OT Review

Bring one vessel class and we will scope what visibility looks like across it.

Schedule an OT Review
Threat landscape

What actually goes wrong in Maritime

Ransomware ashore, disruption afloat

Shore-side compromise routinely halts port operations, cargo release and vessel scheduling. The operational technology need never be touched for the business to stop.

Bridge and engine-room OT

ECDIS, VDR, engine management and cargo control systems sit on networks that were designed for reliability, not adversaries, and are frequently serviced by third-party engineers with removable media.

GNSS and AIS interference

Jamming and spoofing of position and identification signals is now a routine feature of several shipping lanes, with direct navigational and safety consequences.

Crew as the only on-site IT

There is no security team on board. Whatever happens at 03:00 mid-ocean is handled by people whose job is running a ship.

Satellite bandwidth constraints

Security tooling that assumes a fat, always-on link is not deployable. Anything sent ashore has to be worth the bandwidth.

A crowded third-party estate

Class societies, technical managers, agents, chandlers and integrators all touch vessel systems. Each is a route in.

One connected picture

Every signal from ship and shore, in one place

Fleet security usually lives in fragments: one view on the bridge, another at the terminal, a third in head office and a fourth at the technical manager. HexaCore takes all of it into one correlated picture, so a signal from any of them sharpens every other.

Bridge & navigation ECDIS, VDR, GNSS, AIS
Engine & cargo control Machinery, ballast, cargo systems
Terminal & port systems TOS, gate, crane and yard
Shore-side IT ERP, mail, identity, cloud
Crew & remote access Vendor sessions, satcom, welfare
Class, agents & suppliers Third-party exposure
HexaCore Resilience core Correlate · enrich · decide
One fleet-wide picture Every vessel and site in HexaView
Class- and flag-ready evidence MSC.428(98), E26, E27, NIS2
24/7 agentic response HexaSOC acts while the crew sails

Nothing here needs a security analyst on board. Signals leave the vessel only when they are worth the satellite bandwidth: the correlation happens in HexaCore, and the answer comes back to whoever needs it.

Obligations

The regulatory picture

The frameworks and regimes that shape security programmes in this sector. HexaComply maps one control set across all of them.

IMO Resolution MSC.428(98)

Requires cyber risk to be addressed in safety management systems under the ISM Code, effective from the first annual Document of Compliance verification after 1 January 2021.

IACS UR E26

Cyber resilience of ships. Applies to vessels contracted for construction on or after 1 July 2024.

IACS UR E27

Cyber resilience of on-board systems and equipment. Same applicability date as E26.

USCG maritime cyber rules

Cybersecurity requirements for US-flagged vessels, facilities and OCS facilities under 33 CFR, including plans, assessments and reporting.

NIS2

Maritime transport is in scope as an essential sector for EU operators.

ISO/IEC 27001

Commonly required by charterers and increasingly written into commercial terms.

The approach

How HexaShield covers it

  1. 1Passive OT visibility on board and ashore

    HexaOT discovers vessel and terminal assets without probing equipment, so an inventory exists without a safety conversation about scanning.

  2. 2Bandwidth-aware architecture

    HexaOT deploys locally and reports upward selectively, so a constrained satellite link is not the limiting factor on visibility.

  3. 3A SOC that covers the night watch

    HexaSOC agents investigate and act 24/7 across the fleet, which is the only realistic model when there is no security staff on board.

  4. 4Intelligence about your fleet, not shipping in general

    HexaInt tracks leaked credentials, exposed remote-access services and lookalike domains across your operating companies, agents and managers.

  5. 5Evidence for class and flag

    HexaComply maps operating evidence to MSC.428(98), E26 and E27 expectations, so surveys draw on live records rather than a pre-audit exercise.

One accountable partner

Integrated capabilities and proprietary platforms under one operating model, so there is no gap between the team that detects something and the team that answers for it.

No rip-and-replace

We sit above the stack you already run and take telemetry from any source. Nothing here depends on you replacing tooling you have already bought and trained people on.

Transparency by default

Whatever you buy feeds HexaView, the same truth our analysts see, at the depth each audience needs, exported on demand for leadership, auditors and insurers.

FAQ

Questions, answered

What does IMO MSC.428(98) require?
It requires shipowners and managers to address cyber risk within their safety management system under the ISM Code, and it has applied since the first annual verification of the Document of Compliance after 1 January 2021. In practice that means identifying vessel systems at risk, assessing that risk, implementing protective measures and being able to evidence all of it during survey.
What are IACS UR E26 and E27?
They are unified requirements from the International Association of Classification Societies. E26 covers the cyber resilience of ships as a whole; E27 covers the cyber resilience of on-board systems and equipment. Both apply to vessels contracted for construction on or after 1 July 2024, which makes them a newbuild and major-conversion concern first and a fleet-wide one over time.
Can you secure vessels with limited satellite bandwidth?
Yes, and it is a core design constraint rather than an afterthought. HexaOT runs locally on the vessel and reports selectively, so detection does not depend on shipping full telemetry ashore. What crosses the link is chosen to be worth the bandwidth.
Is scanning safe on a vessel's OT network?
HexaOT does not actively scan. Discovery is passive, based on observing traffic, which is what makes it deployable on bridge and engine-room networks where an unexpected probe can have navigational or safety consequences.
Do you cover ports and terminals as well as ships?
Yes. Terminal operating systems, cargo handling, gate and crane control and the shore-side corporate estate are all covered by the same platform and the same SOC, which matters because incidents rarely respect the boundary between ship and shore.

Talk to someone who knows your sector

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.