Supplier Monitoring
Supplier monitoring allows an organisation to monitor their suppliers' external attack surfaces for new risks, exposed services, and changes that could potentially affect their organisation.
The Supply Chain Risk Management scan group is used to select the suppliers to be monitored, the number of suppliers that can be selected will depend on the license tier for the organisation.
Supply Chain Risk Management scans are refreshed weekly.
Adding a supplier scan to your organisation
Suppliers can be added and removed from your organisation via 'Manage supplier access' (cog icon on the scan group header). Use the supplier catalogue to search for the supplier of interest and click on the '+' to add them.
If the supplier scan doesn't already exist, a new scan will be created based on the seed selected. The new supplier scan will be subsequently reviewed by Hexiosec Support and any additional related seeds will be added.
Differences in the scan overview
A supplier scan overview will look a little different to a scan you have created. For example, there will not be the option to view or manage actions.
Supplier Feedback
We recognise that external security analysis can sometimes lack internal business or technical context. If you have questions about a finding, believe something has been misclassified, or would like to provide additional information, please get in touch.
Our goal is to support constructive, collaborative security improvement — not simply report risks.
Contact the Hexiosec team at [email protected] or via our website.