Hexiosec Attack Surface Management
Hexiosec Attack Surface Management helps identify, monitor, and secure digital assets. Surface scans reveal vulnerabilities and risks in your external attack surface. Discover issues before costly disruptions. Gain real-time insights, prioritise risks, and protect against cyber threats with our expert-developed platform. Hexiosec ASM was part of NCSC's ACD2.0 testing programme.
Features
- Continuous external attack surface scanning for vulnerabilities and misconfigurations
- Real-time alerts on changes and emerging threats across digital assets
- Automated asset discovery including shadow IT and forgotten systems
- Risk scoring enriched with threat intelligence and Known Exploited Vulnerabilities
- Cloud-based platform with instant access and no installation required
- Open API integration with existing security tools and workflows
- Daily vulnerability reporting for exposed assets with resource tagging
- Non-intrusive on-demand scanning for third-party and supply chain risk assessment
- UK-hosted solution
- Discover internet-facing AWS, Azure and GCP cloud assets
Benefits
- Identify and prioritise vulnerabilities before they cause costly disruptions
- Maintain continuous visibility of external risks across complex infrastructures
- Improve resource efficiency by focusing penetration testing on real exposures
- Enable evidence-based decisions for senior security leadership teams
- Reduce supply chain risk by monitoring partners and vendors
- Enhance compliance readiness with UK standards and regulatory frameworks
- Gain actionable insights for active cyber defence
- Facilitate data-driven conversations on organisational risk exposure
- Strengthen resilience against evolving threats
- Expand scan coverage to include changing cloud footprints
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 0 4 7 6 6 5 0 0 5 6 9 3 2 0
Contact
HEXIOSEC LIMITED
Rob Wright
Telephone: 01242474970
Email: frameworks@hexiosec.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Asset life-cycle management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- N/A
- System requirements
- Available via your browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Usually within 4 hours during office hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support is provided during office hours via email and phone. This is triaged by a Product Support Specialist, who will either resolve the query themselves or engage one of our engineering team as required.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Every new organisation will be provided with a video call and demonstration of Hexiosec Attack Surface Management so they can easily set up and start using the service. We help users start using our service by providing comprehensive online user documentation through our support portal and documentation site. This includes detailed guides on setup, running scans, and API integration. We also offer responsive online support via email and in-app help during UK business hours, with typical response times within 4 hours.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- No user data would need to be extracted at the end of the contract. If the customer moved to a different Attack Surface Management service then the initial scan would repopulate their risks and actions.
- End-of-contract process
- No special provisions are required at the end of the contract.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- N/A
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
Hexiosec ASM provides an API designed for integration with external systems and automation of attack surface management tasks. Users authenticate via OpenID Connect (e.g., Microsoft Entra ID) and generate API tokens from an authenticated session. API calls require either a valid session token or API key header.
Through the API, users can initiate scans, retrieve scan results, and access detailed vulnerability and risk data. They can manage their own profiles and perform tenant-scoped tasks based on assigned roles and groups. Configuration changes, such as adjusting scan parameters or exporting reports, are permitted only if the user has the necessary permissions.
All interactions are logged for audit and compliance. Limitations include strict role-based access control, meaning low-privilege users have limited capabilities (often read-only). API tokens cannot be created without prior authentication and appropriate privileges. Requests must meet validation rules; invalid calls return errors. MFA may be enforced by the tenant’s identity provider. Documentation is available in HTML and PDF formats, with additional internal resources. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- Hexiosec ASM uses scalable cloud services so there are no practical limitations through demand. The service is monitored during office hours to ensure this is the case.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Users are provided with a usage dashboard that shows scan and asset consumption across the service. This includes the number of domains and IP addresses processed per scan, usage against plan limits, scan types, rescans, seed counts and overall scanning activity over time.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- No user data is held by the service. All data presented is the result of passive scanning of internet-facing assets.
- Data export formats
- Other
- Other data export formats
- N/A
- Data import formats
- Other
- Other data import formats
- N/A
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We aim to provide continuous access to Hexiosec ASM using high-availability infrastructure, but we do not guarantee a specific uptime level unless a separate SLA is agreed. Maintenance, updates, or unforeseen events may cause interruptions. Standard terms include email-based support during UK business hours, with no guaranteed response times unless covered by an SLA.
- Approach to resilience
- Available on request.
- Outage reporting
- Email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Hexiosec ASM has been written by cyber security engineers with experience in developing software for the highest level of government security. For more information about Hexiosec ASM, including how we restrict access in management interfaces and support channels, please ask for further information.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Hexiosec operates a single, coherent set of policies and processes aligned with ISO 27001 and NCSC Cyber Assessment Framework. Governance ensures security risk ownership at appropriate levels with documented roles and responsibilities. All employees, contractors, and third-party users must read and understand the Information Security Policy. Policies map to ISO 27001 controls and CAF objectives, supporting compliance and resilience. Risk management includes structured assessments, asset visibility through Hexiosec ASM, supply chain assurance, and defined incident response processes. Governance is reinforced by continuous improvement through regular reviews, audits, and updates, embedding security awareness and accountability across the organisation.
- Information security policies and processes
- Hexiosec follows a single, coherent set of policies and processes aligned with ISO 27001 and NCSC Cyber Assessment Framework objectives. Our Information Security Policy applies to all employees, contractors, and third-party users who interact with Hexiosec information. Policies map directly to ISO 27001 controls, ensuring compliance and resilience. Security risk ownership is embedded at appropriate levels with documented roles and responsibilities. Governance includes structured risk assessments, asset visibility through Hexiosec ASM, supply chain assurance, and defined incident response processes. Policies are enforced through continuous improvement, regular reviews, audits, and updates. All staff must read and understand the Information Security Policy, embedding security awareness and accountability across the organisation.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Hexiosec follows documented configuration and change management processes aligned with ISO 27001. All components are tracked through their lifecycle using formal records and audit trails to ensure accuracy and accountability. Changes are managed through structured reviews and approval workflows, with each change assessed for potential impact before implementation. This includes validation against established policies and documented controls to confirm compliance and minimise risk. Regular audits and continuous improvement cycles ensure that configuration baselines remain current and that all changes are properly recorded, authorised, and communicated across the organisation.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Hexiosec is an expert in vulnerability management. We maintain a vulnerability management plan that captures, triages, and prioritises issues based on severity and impact. Knowledge of public vulnerabilities is kept up to date through automated dependency advisories and external scanning of public-facing sites. Renovate is used for automated updates, ensuring timely remediation. Threat intelligence sources include CISA’s Known Exploited Vulnerability list and Exploit Prediction Scoring System (EPSS) data, adding real-world context to risk assessments. Combining severity, known exploits, and likelihood of active exploitation ensures critical vulnerabilities are addressed promptly while lower-severity items are managed effectively within development sprints.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Hexiosec’s incident management policy defines how vulnerabilities are escalated and communicated to relevant internal security stakeholders. Clear escalation to internal security teams ensures vulnerabilities are assessed quickly and addressed effectively, reducing the risk of delayed response. The policy also covers communication with affected customers in the event of a vulnerability or incident. Customers are notified promptly with appropriate guidance, helping them take protective action, reducing impact, and maintaining trust in Hexiosec’s services. This structured approach ensures timely reporting to internal teams and affected customers, supporting rapid containment and remediation.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Hexiosec has pre-defined processes for common security events as part of its incident management policy. The policy defines how vulnerabilities and incidents are escalated and communicated to relevant internal security stakeholders, ensuring rapid assessment and effective response. Users can report incidents through established communication channels defined in the policy, which include direct escalation to internal security teams. When an incident occurs, affected customers are informed promptly with appropriate guidance to help them take protective action and reduce impact. Incident reports are provided in line with the policy, ensuring clear communication and maintaining trust in Hexiosec’s services.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- You can book a live demo to see the platform in action or create a free account to try out the key functionality. Our team will walk you through the key features and help you get set up quickly.
- Link to free trial
- https://asm.hexiosec.com/register?tier=free
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 9%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ba00785d-7c2f-403c-9759-0f8d8067aa6a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Volunteering opportunities for staff
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-