Skip to main content

Help us improve the Digital Marketplace - send your feedback

HEXIOSEC LIMITED

Hexiosec Attack Surface Management

Hexiosec Attack Surface Management helps identify, monitor, and secure digital assets. Surface scans reveal vulnerabilities and risks in your external attack surface. Discover issues before costly disruptions. Gain real-time insights, prioritise risks, and protect against cyber threats with our expert-developed platform. Hexiosec ASM was part of NCSC's ACD2.0 testing programme.

Features

  • Continuous external attack surface scanning for vulnerabilities and misconfigurations
  • Real-time alerts on changes and emerging threats across digital assets
  • Automated asset discovery including shadow IT and forgotten systems
  • Risk scoring enriched with threat intelligence and Known Exploited Vulnerabilities
  • Cloud-based platform with instant access and no installation required
  • Open API integration with existing security tools and workflows
  • Daily vulnerability reporting for exposed assets with resource tagging
  • Non-intrusive on-demand scanning for third-party and supply chain risk assessment
  • UK-hosted solution
  • Discover internet-facing AWS, Azure and GCP cloud assets

Benefits

  • Identify and prioritise vulnerabilities before they cause costly disruptions
  • Maintain continuous visibility of external risks across complex infrastructures
  • Improve resource efficiency by focusing penetration testing on real exposures
  • Enable evidence-based decisions for senior security leadership teams
  • Reduce supply chain risk by monitoring partners and vendors
  • Enhance compliance readiness with UK standards and regulatory frameworks
  • Gain actionable insights for active cyber defence
  • Facilitate data-driven conversations on organisational risk exposure
  • Strengthen resilience against evolving threats
  • Expand scan coverage to include changing cloud footprints

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frameworks@hexiosec.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 0 4 7 6 6 5 0 0 5 6 9 3 2 0

Contact

HEXIOSEC LIMITED Rob Wright
Telephone: 01242474970
Email: frameworks@hexiosec.com

About your service

Service categories

Applications

Enterprise resource management

  • Asset life-cycle management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
N/A
System requirements
Available via your browser

User support

Email or online ticketing support
Yes
Support response times
Usually within 4 hours during office hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support is provided during office hours via email and phone. This is triaged by a Product Support Specialist, who will either resolve the query themselves or engage one of our engineering team as required.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Every new organisation will be provided with a video call and demonstration of Hexiosec Attack Surface Management so they can easily set up and start using the service. We help users start using our service by providing comprehensive online user documentation through our support portal and documentation site. This includes detailed guides on setup, running scans, and API integration. We also offer responsive online support via email and in-app help during UK business hours, with typical response times within 4 hours.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
No user data would need to be extracted at the end of the contract. If the customer moved to a different Attack Surface Management service then the initial scan would repopulate their risks and actions.
End-of-contract process
No special provisions are required at the end of the contract.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
N/A
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Hexiosec ASM provides an API designed for integration with external systems and automation of attack surface management tasks. Users authenticate via OpenID Connect (e.g., Microsoft Entra ID) and generate API tokens from an authenticated session. API calls require either a valid session token or API key header.
Through the API, users can initiate scans, retrieve scan results, and access detailed vulnerability and risk data. They can manage their own profiles and perform tenant-scoped tasks based on assigned roles and groups. Configuration changes, such as adjusting scan parameters or exporting reports, are permitted only if the user has the necessary permissions.
All interactions are logged for audit and compliance. Limitations include strict role-based access control, meaning low-privilege users have limited capabilities (often read-only). API tokens cannot be created without prior authentication and appropriate privileges. Requests must meet validation rules; invalid calls return errors. MFA may be enforced by the tenant’s identity provider. Documentation is available in HTML and PDF formats, with additional internal resources.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • Other
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
Hexiosec ASM uses scalable cloud services so there are no practical limitations through demand. The service is monitored during office hours to ensure this is the case.

Analytics

Service usage metrics
Yes
Metrics types
Users are provided with a usage dashboard that shows scan and asset consumption across the service. This includes the number of domains and IP addresses processed per scan, usage against plan limits, scan types, rescans, seed counts and overall scanning activity over time.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
Less than once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
No user data is held by the service. All data presented is the result of passive scanning of internet-facing assets.
Data export formats
Other
Other data export formats
N/A
Data import formats
Other
Other data import formats
N/A

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We aim to provide continuous access to Hexiosec ASM using high-availability infrastructure, but we do not guarantee a specific uptime level unless a separate SLA is agreed. Maintenance, updates, or unforeseen events may cause interruptions. Standard terms include email-based support during UK business hours, with no guaranteed response times unless covered by an SLA.
Approach to resilience
Available on request.
Outage reporting
Email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Hexiosec ASM has been written by cyber security engineers with experience in developing software for the highest level of government security. For more information about Hexiosec ASM, including how we restrict access in management interfaces and support channels, please ask for further information.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Hexiosec operates a single, coherent set of policies and processes aligned with ISO 27001 and NCSC Cyber Assessment Framework. Governance ensures security risk ownership at appropriate levels with documented roles and responsibilities. All employees, contractors, and third-party users must read and understand the Information Security Policy. Policies map to ISO 27001 controls and CAF objectives, supporting compliance and resilience. Risk management includes structured assessments, asset visibility through Hexiosec ASM, supply chain assurance, and defined incident response processes. Governance is reinforced by continuous improvement through regular reviews, audits, and updates, embedding security awareness and accountability across the organisation.
Information security policies and processes
Hexiosec follows a single, coherent set of policies and processes aligned with ISO 27001 and NCSC Cyber Assessment Framework objectives. Our Information Security Policy applies to all employees, contractors, and third-party users who interact with Hexiosec information. Policies map directly to ISO 27001 controls, ensuring compliance and resilience. Security risk ownership is embedded at appropriate levels with documented roles and responsibilities. Governance includes structured risk assessments, asset visibility through Hexiosec ASM, supply chain assurance, and defined incident response processes. Policies are enforced through continuous improvement, regular reviews, audits, and updates. All staff must read and understand the Information Security Policy, embedding security awareness and accountability across the organisation.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Hexiosec follows documented configuration and change management processes aligned with ISO 27001. All components are tracked through their lifecycle using formal records and audit trails to ensure accuracy and accountability. Changes are managed through structured reviews and approval workflows, with each change assessed for potential impact before implementation. This includes validation against established policies and documented controls to confirm compliance and minimise risk. Regular audits and continuous improvement cycles ensure that configuration baselines remain current and that all changes are properly recorded, authorised, and communicated across the organisation.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Hexiosec is an expert in vulnerability management. We maintain a vulnerability management plan that captures, triages, and prioritises issues based on severity and impact. Knowledge of public vulnerabilities is kept up to date through automated dependency advisories and external scanning of public-facing sites. Renovate is used for automated updates, ensuring timely remediation. Threat intelligence sources include CISA’s Known Exploited Vulnerability list and Exploit Prediction Scoring System (EPSS) data, adding real-world context to risk assessments. Combining severity, known exploits, and likelihood of active exploitation ensures critical vulnerabilities are addressed promptly while lower-severity items are managed effectively within development sprints.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Hexiosec’s incident management policy defines how vulnerabilities are escalated and communicated to relevant internal security stakeholders. Clear escalation to internal security teams ensures vulnerabilities are assessed quickly and addressed effectively, reducing the risk of delayed response. The policy also covers communication with affected customers in the event of a vulnerability or incident. Customers are notified promptly with appropriate guidance, helping them take protective action, reducing impact, and maintaining trust in Hexiosec’s services. This structured approach ensures timely reporting to internal teams and affected customers, supporting rapid containment and remediation.
Incident management type
Supplier-defined controls
Incident management approach
Hexiosec has pre-defined processes for common security events as part of its incident management policy. The policy defines how vulnerabilities and incidents are escalated and communicated to relevant internal security stakeholders, ensuring rapid assessment and effective response. Users can report incidents through established communication channels defined in the policy, which include direct escalation to internal security teams. When an incident occurs, affected customers are informed promptly with appropriate guidance to help them take protective action and reduce impact. Incident reports are provided in line with the policy, ensuring clear communication and maintaining trust in Hexiosec’s services.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
You can book a live demo to see the platform in action or create a free account to try out the key functionality. Our team will walk you through the key features and help you get set up quickly.
Link to free trial
https://asm.hexiosec.com/register?tier=free

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
6%
Between £1,000,001 and £2,500,000
9%
Between £2,500,001 and £5,000,000
12%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Ba00785d-7c2f-403c-9759-0f8d8067aa6a
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Volunteering opportunities for staff
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frameworks@hexiosec.com. Tell them what format you need. It will help if you say what assistive technology you use.