Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Article

Certification assesses the facility. Custody follows the asset.

Why a vendor chain full of assessed facilities can still leak, and what has to be true instead.

Updated August 2026 · 5 minute read

Two different questions

A content security assessment answers: does this facility have appropriate controls. A custody record answers: where did this asset actually go.

They sound like the same question. They are not, and confusing them is how organisations end up with a fully assessed vendor chain and no ability to investigate a leak.

What assessment can and cannot do

Assessment is genuinely valuable. It raises the floor across a supply chain, it gives buyers a common language, and it forces small vendors to think about controls they would otherwise not have.

Its limits are structural rather than a criticism. It samples a facility at a moment. It cannot speak to the subcontractor engaged after the assessment, the freelancer working from a personal device, or the transfer tool someone reached for because the sanctioned one was slow that afternoon.

The moment it matters

A screener surfaces before its release date. The commercial damage is immediate and the investigation begins.

What the investigation has to work with is whatever records happened to exist. Usually that is email, access logs from several systems that do not correlate, and people memories. The investigation runs for weeks and frequently ends inconclusive, not because nobody tried but because the records were never designed to answer this question.

What has to be true instead

The asset has to carry its own history. Tagged in metadata, with each transfer logged as it happens, across organisational boundaries rather than only inside yours.

That produces something assessment cannot: after a leak you can trace the material back toward a source vendor or contributor in minutes. The conversation with the studio, the distributor and the insurer moves from blame to which control to close.

Making the secure path the fast path

One practical note that matters more than it should. Most custody failures are not defiance, they are friction. When the approved route is slow, people route around it, and the audit trail ends at that moment.

Any custody scheme that is slower than the workaround will be worked around. If the tracked path is also the fastest path, the behaviour resolves itself.

FAQ

Questions, answered

Are you saying TPN is not worth doing?
No, the opposite. It is the shared language of the industry and it raises the floor across a large and fragmented supply chain. Our position is that custody is additive to it, not a replacement: certification assesses the facility, custody follows the asset, and both matter.
Does custody tracking slow production down?
It should not, and if it does it will be bypassed. The approach that works is one where the same component that maintains the record also accelerates the transfer, so the tracked route is the quickest one available rather than a tax on doing the right thing.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.