Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Guide

Preparing for a TPN assessment

What to do in the eight weeks before, and the three areas that most often cause findings.

Updated August 2026 · 6 minute read

Start with scope

Decide precisely which facilities, systems and workflows are in scope, and be able to draw the boundary on a diagram. Almost every difficult assessment traces back to a boundary nobody agreed.

Be honest about where content actually goes. If a workflow routinely leaves the scoped environment, either bring it in or change the workflow. Assessing a boundary that does not reflect reality wastes everyone time and produces assurance nobody should rely on.

Eight weeks out

Inventory the systems that touch content, including transfer tooling and anything a freelancer uses. Map who has access to what, and remove what has accumulated. Confirm which subcontractors are engaged and what they are contractually required to do.

This is also the point to fix the boring things: shared accounts, leavers with active access, and transfer tools adopted informally.

The three areas that produce most findings

Access control. Broad, long-lived access granted for a project that ended. The fix is unglamorous and effective: review, remove, and make removal part of project close.

Asset handling. Knowing where content is, in which state, and who moved it last. Where this is manual it will not survive a busy schedule.

Subcontractor management. The vendor of your vendor. Assessments increasingly ask, and the answer is often unknown.

Evidence

Evidence gathered the week before an assessment proves something about that week. Assessors know this, and the questions that follow are designed to find out whether the control operates the rest of the time.

The organisations that find assessment easy are the ones whose evidence accumulates as they work. That is a systems decision made months earlier, not something achievable in the run-up.

On the day

Have someone who actually operates the workflow in the room, not only the person who wrote the policy. Assessors ask how it works, and the honest operational answer is usually better than the documented one.

Where a control is partially implemented, say so and show the plan. A known gap with an owner and a date is treated very differently from one discovered by the assessor.

FAQ

Questions, answered

How long does preparation take?
For an organisation with reasonable existing practice, eight weeks is workable. For one starting from a standing start, longer, and the constraint is usually access review and subcontractor mapping rather than anything technical.
Does a TPN assessment cover our subcontractors?
Your own assessment covers your facility, but the questions increasingly reach into how you manage the parties you engage. In practice you are expected to be able to describe and evidence that management, which means knowing who they are before you are asked.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.