Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Guide

Building a third-party risk programme that survives contact with a regulator

Six steps, in the order that actually works, and the one most programmes skip.

Updated August 2026 · 7 minute read

Step one: map services, not vendors

Start from your important business services and work outward to what they depend on. A vendor list built from accounts payable tells you who you pay, not what would break.

This is the step most often skipped, and skipping it is why so many registers are simultaneously enormous and useless.

Step two: tier by consequence

Tier on what happens if the vendor fails, not on spend. A small supplier holding privileged access to a critical system outranks a large one supplying stationery.

Then let the tier drive the effort. Assessing every vendor to the same depth guarantees the programme either stalls or becomes a formality.

Step three: assess consistently

One model, applied the same way, so results are comparable. Different assessors with different templates produce scores that cannot be ranked against each other, which quietly destroys the value of the exercise.

Step four: watch from outside

A questionnaire tells you what a supplier believed about themselves on the day they filled it in. External monitoring observes their actual exposure continuously: internet-facing infrastructure, leaked credentials, dark-web mentions, breach disclosure.

The two together are considerably stronger than either alone, and the external half requires no cooperation from the supplier, which is exactly what you want when a relationship is deteriorating.

Step five: answer the concentration question

Several critical suppliers depending on the same underlying provider is the scenario the regulations were written about. It is also the one a conventional vendor register cannot show you, because each entry looks independent.

You need the dependency, not just the relationship. Ask suppliers where they host, who they subcontract to, and what their own concentration looks like.

Step six: make evidence a by-product

The assessment history, monitoring record and remediation trail should be the evidence pack. If your programme produces evidence only when asked, the asking is what you will optimise for.

Under DORA in particular, the register of information is far easier to maintain as an operational record than to reconstruct per submission.

FAQ

Questions, answered

How many vendors should be in the top tier?
Fewer than most organisations initially think. If more than roughly a tenth of your suppliers are critical, the tiering is probably measuring importance to procurement rather than consequence of failure. Tightening it makes the programme deliverable.
Can we monitor suppliers who will not cooperate?
Yes. External monitoring observes what is publicly and semi-publicly visible about an organisation and requires no access to their environment and no permission from them. It is often most valuable precisely where cooperation is poor.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.