Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Learning Hub

Sharper thinking on cyber resilience

Explainers, articles, practical guides, threat briefings and composite case studies — on the frameworks, the threats, the technology and the real engagements behind cyber resilience. Written to be useful whether or not you ever talk to us.

ExplainerFrameworks and regulation, in plain terms
ArticlePositions we are willing to argue for
GuidePractical, and usually a checklist
Threat briefingWhat we are seeing, and what to do
Case studyComposite engagements, anonymised
Category
Topic

Explainer

DORA, explained: what it actually asks you to do

The Digital Operational Resilience Act has applied since January 2025. Five obligations, and the one that catches most firms out.

8 min read
Explainer

NIS2: are you in scope, and what changes if you are

Broader sectors, tighter deadlines and personal accountability for management. How to work out whether it reaches you.

7 min read
Explainer

IACS UR E26 and E27, explained for fleet operators

Two unified requirements that changed what a newbuild has to demonstrate. What they cover, who they bind, and what they mean for existing tonnage.

6 min read
Explainer

CMMC 2.0 and the defence supply chain

What the levels mean, how it relates to NIST SP 800-171, and why the assessment is the easy part.

6 min read
Explainer

The NCSC Cyber Assessment Framework, explained

An outcome-based framework rather than a control checklist. Why that distinction changes what you have to produce.

6 min read
Article

Why you cannot scan an OT network

The single most common way an IT security programme causes an industrial incident, and what to do instead.

6 min read
Article

Coverage is not a percentage

What ATT&CK mapping tells you, what it does not, and how a coverage number becomes misleading.

6 min read
Article

Certification assesses the facility. Custody follows the asset.

Why a vendor chain full of assessed facilities can still leak, and what has to be true instead.

5 min read
Article

What an AI agentic SOC actually means

A term doing a lot of work in a lot of marketing. What changes operationally, and what should not.

6 min read
Guide

Twelve questions to ask an MDR provider

The questions that separate providers quickly, including the three most will not answer straight.

7 min read
Guide

Preparing for a TPN assessment

What to do in the eight weeks before, and the three areas that most often cause findings.

6 min read
Guide

Building a third-party risk programme that survives contact with a regulator

Six steps, in the order that actually works, and the one most programmes skip.

7 min read
Threat briefing

Infostealers and the credential you never issued

Why the compromise that gets you may never touch a device you manage, and what to do about it.

5 min read
Case study

Composite: a 40-vessel operator, the first ninety days

What changes, in what order, when a fleet with no OT visibility starts from one vessel class.

6 min read
Case study

Composite: a manufacturer answering customer security schedules

How a bid activity staffed by operations people becomes a repeatable answer drawn from one evidence base.

5 min read
Explainer

ISO 27001 or SOC 2: which one, and when you need both

Two of the most requested procurement assurances, built for different audiences. How to choose, and when doing both is the cheaper path.

7 min read
Explainer

The EU AI Act, for security and risk teams

A risk-tiered law for anyone building or deploying AI. What it classifies, what it demands, and where it reuses your existing security work.

7 min read
Article

“We passed the pen test” is not a security posture

A clean pen test is a snapshot of one scope in one week. Why treating it as a grade quietly stops a programme improving.

6 min read
Article

Compliant is not the same as secure

You can pass every audit and still be breached. Why compliance and security diverge, and how to make one produce the other.

6 min read
Threat briefing

OT ransomware: when they take production and the data

Ransomware crews learned that stopped production pays faster than encrypted files. The double-extortion play against OT, and how to blunt it.

5 min read
Threat briefing

MFA fatigue and stolen session tokens

MFA stopped password reuse, so attackers stopped attacking the password. Two techniques that bypass MFA, and what actually closes them.

5 min read
Case study

Composite: a regional bank getting DORA-ready in two quarters

A composite of DORA engagements: what a bank with a capable IT team but no resilience owner did first, and the order that worked.

6 min read
Case study

Composite: a hospital group securing medical devices without downtime

A composite of healthcare engagements: bringing thousands of unmanaged medical devices into view without a scan that could disrupt care.

6 min read
FAQ

Questions, answered

What is the Learning Hub for?
It is where we put the things that are worth writing down rather than selling: how a framework actually works, why a common approach fails, what to ask a provider. If a piece here answers your question and you never contact us, it has still done its job.
Are the case studies real clients?
They are composites, and every one says so on the page. Each is drawn from the shape of engagements of that type rather than from a single organisation, and no figure in them is a measured result for a named client. When we have named studies with written approval, they will replace these.
How current is the regulatory content?
Explainers state what is a matter of public record at the time of writing and are dated accordingly. Frameworks change, and whether one applies to your organisation is a question for your counsel. We confirm applicability with you during onboarding rather than asserting it here.

Rather talk it through?

Thirty minutes, starting with your environment rather than our product.