Skip to content
FortaRisks
The whole platform

See your external exposure, OT/ICS included

See your entire external attack surface the way an attacker does, monitored continuously. Domains, services, certificates, leaked data and look-alike domains, plus the OT/ICS protocols generic scanners miss, all in read-only.

110+

Finding types

15+

OT/ICS ports monitored

30 min

To full surface

Your EASM sees your website. Not your Siemens controller.

Generic scanners miss industrial assets entirely, which is exactly where the real exposure often hides.

Value you can see

Outcomes your team will feel.

  • One engine, three surfaces

    Your perimeter, your vendors', and a prospect's before you sign. Same engine, three uses.

  • A grade you can explain

    Per category, per axis and overall, with actual coverage shown next to it.

  • Read-only, including on OT

    Industrial protocol detection that never disturbs the networks, maximum severity only when exposure is confirmed.

Key capabilities

  • Find your assets from your company name alone

    Give a company name, not a list of domains: the engine finds your domains, subsidiaries and acquisitions on its own, then surfaces subdomains, IPs, services, certificates and technologies. This is the first complaint raised against platforms in large-account tenders, and it is solved here.

  • Five axes, 43 detection categories

    Email and anti-spoofing, infrastructure and web, reputation and brand, leaks and disclosure, plus OT and ICS. One hundred and seventy-four detection templates built in, nine change types tracked, and signed webhooks to Slack and Teams. Every finding carries its evidence.

  • The scan tells you what it did not look at

    Partial coverage is declared as such, never dressed up as a good grade. Very few products can do this, and none hands it back to the customer. It is what lets you know whether an A+ means "everything is clean" or "we could not see everything".

  • Official breach registries and leaked credentials

    Declarations made to regulators are used by name: CNIL, ICO, OAIC, US attorneys general, SEC EDGAR and CanadaBreaches. A public, dated, legally clean source. Leaked credentials are detected without ever storing an email address in clear text, guaranteed by design.

  • Progress over time

    Trend your exposure down and show the board a surface that shrinks month over month, with evidence.

  • Proactive exposure intel

    Dark web breach exposure, leaked credentials and look-alike domains registered against your brand, caught before they are used against you.

Not 10,000 findings. An Action Feed of what matters.

Every new exposure, change and risk becomes one prioritized action in your feed, routed to the right owner and tracked to closure. Your team focuses only on what moves the needle, not on noise.

Three moments. Three uses.

  • Case 1

    Manufacturing OT (controller exposed after maintenance)

    1,200-employee manufacturer, 8 sites, Siemens S7 and Allen-Bradley fleet. A contractor intervenes on the Trois-Rivières site PLC. Sets up a temporary VPN for remote access. Forgets to close it on departure. At 48h, the FortaRisks OT scanner detects a Siemens S7-1200 controller accessible from the Internet. Slack alert at 2:22 PM. Confirmation by OT team at 2:45 PM. VPN closed at 3:10 PM. No incident.

  • Case 2

    SaaS B2B (subdomain takeover)

    80-employee SaaS publisher, 12 active marketing subdomains. A marketing campaign uses partner.acme.ca pointing to a Webflow page. Campaign ends. Webflow page deleted but DNS remains. At 6 hours, FortaRisks detects a possible takeover. Alert. DNS cleaned in 2 hours. Avoids a phishing attack exploiting a legitimate subdomain.

  • Case 3

    Regional bank (DMARC missing vs Loi 25)

    Quebec cooperative bank, 600 employees. FortaRisks scan: DMARC at p=none, MTA-STS missing, BIMI missing, IP in Spamhaus DNSBL. Email Health score: C. Quantified recommendations: DMARC p=quarantine then p=reject deployment in 60 days, MTA-STS, DNSBL removal. Score climbs to A in 90 days. Avoids a phishing wave impersonating the brand.

What's included

Discovery & attribution

  • Attribution from your company name alone
  • Domains, subsidiaries and acquisitions found on their own
  • 36 discovery and analysis connectors
  • 5 scan axes, 43 detection categories
  • 174 detection templates built in
  • The scan declares what it did not look at
  • Modbus
  • Siemens S7
  • Allen-Bradley
  • Niagara Fox
  • BACnet
  • EtherNet/IP
  • IEC-104
  • DNP3
  • OPC UA
  • Read-only, never disturbing the networks

What we scan

  • 110+ finding types, each with its evidence
  • Email health: SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI
  • Subdomain takeover (83 services)
  • Ports, TLS, headers, WAF, exposed APIs
  • Typosquatting, blocklists, reputation
  • Leaked credentials, with no address stored in clear text
  • Dark web monitoring: credentials and brand leaks
  • Exposed databases and public source code
  • CVE correlation with CVSS, EPSS and CISA KEV

Optional AI enrichment

AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.

In attack surface, AI targets explanation: turning a technical finding into a business consequence, grouping related exposures, drafting the paragraph for the board. Detection and the A+ to F grading stay deterministic and defensible.

Sovereignty: the platform is built and hosted in Canada, beyond the reach of the US CLOUD Act. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.

EASM is not a silo. All modules use its signals.

EASM produces real exposure signals. Without them, other modules work in theory. With them, they decide based on what's actually exposed.

  • EASM → Posture & Compliance

    An expected control (e.g., "TLS 1.2 minimum on all exposed services") can be objectively validated by EASM findings. No more declarative. No more questionnaire. The proof is observed.

  • EASM → CTI

    Each detected exposed service (with its exact version via CPE) is automatically correlated to active CVEs. An Apache HTTP 2.4.49 exposed becomes immediately a critical finding if KEV applies.

  • EASM → TPRM

    The 110+ finding types are applied to third-party perimeters. The OT/ICS scanner is applied to industrial suppliers. No additional ingestion cost.

  • EASM → Risk Engine

    EASM provides the "actual exposure" component of the risk score. Without EASM, the AI can't distinguish a theoretical risk from a tomorrow-morning exploitable risk.

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.

Frequently asked questions

Is the OT/ICS scanner active or passive?

Active but read-only. We fingerprint the 8 supported protocols with no writes, no control commands and no state changes, with rate limiting tuned for OT networks. Ultra-sensitive IP ranges can be excluded.

Does it cover exposed cloud buckets?

Yes. Misconfigured S3, Azure Blob and GCS are detected, and subdomain takeover is checked across 83 services including S3, Azure, GitHub Pages, Netlify, Vercel and Webflow.

How do you avoid scanning a third party's assets?

Attribution starts from your company name and your domains, then every discovered asset carries ownership evidence you can review and correct. The same engine also serves, deliberately, to scan a vendor or a prospect: in that case the perimeter is explicit and, on the vendor side, validated by them.

Are findings actionable or just informational?

Every finding is documented with a technical explanation, proof, severity and a step-by-step fix, with references. Critical findings can be exported to your ITSM.