Skip to content
FortaRisks
All pillars

See your external exposure, OT/ICS included

See your entire external attack surface the way an attacker does, monitored continuously. Domains, services, certificates, leaked data and look-alike domains, plus the OT/ICS protocols generic scanners miss, all in read-only.

100+

Finding types

9

OT/ICS protocols

30 min

To full surface

Your EASM sees your website. Not your Siemens controller.

Generic scanners miss industrial assets entirely, which is exactly where the real exposure often hides.

Value you can see

Outcomes your team will feel.

  • 24h to spot exposed OT

    Find the controller online before an attacker does.

  • 100+ finding types

    See what generic scanners miss.

  • Read-only by design

    Scan industrial assets without touching production.

Key capabilities

  • Discover unknown assets, see like an attacker

    We reveal everything an attacker can reach, including the assets you forgot you had: shadow subdomains, exposed admin panels, public-facing databases, certificates and technologies, plus 9 OT/ICS protocols generic scanners never touch.

  • Continuous monitoring

    Your surface is watched every day, not once a year. New assets and exposures surface as they appear, not at the next audit.

  • Change detection and validation

    Every change to your surface is detected and validated, so a forgotten test server or a reopened port never slips in unnoticed.

  • Risk-based prioritization

    Findings are ranked by real impact and exploit likelihood (EPSS, CISA KEV), correlated with live threat intel and re-scored the moment a threat is actively exploited, not by raw CVSS. No more alert fatigue.

  • Progress over time

    Trend your exposure down and show the board a surface that shrinks month over month, with evidence.

  • Proactive exposure intel

    Dark web breach exposure, leaked credentials and look-alike domains registered against your brand, caught before they are used against you.

Not 10,000 findings. An Action Feed of what matters.

Every new exposure, change and risk becomes one prioritized action in your feed, routed to the right owner and tracked to closure. Your team focuses only on what moves the needle, not on noise.

Three moments. Three uses.

  • Case 1

    Manufacturing OT (controller exposed after maintenance)

    1,200-employee manufacturer, 8 sites, Siemens S7 and Allen-Bradley fleet. A contractor intervenes on the Trois-Rivières site PLC. Sets up a temporary VPN for remote access. Forgets to close it on departure. At 48h, the FortaRisks OT scanner detects a Siemens S7-1200 controller accessible from the Internet. Slack alert at 2:22 PM. Confirmation by OT team at 2:45 PM. VPN closed at 3:10 PM. No incident.

  • Case 2

    SaaS B2B (subdomain takeover)

    80-employee SaaS publisher, 12 active marketing subdomains. A marketing campaign uses partner.acme.ca pointing to a Webflow page. Campaign ends. Webflow page deleted but DNS remains. At 6 hours, FortaRisks detects a possible takeover. Alert. DNS cleaned in 2 hours. Avoids a phishing attack exploiting a legitimate subdomain.

  • Case 3

    Regional bank (DMARC missing vs Loi 25)

    Quebec cooperative bank, 600 employees. FortaRisks scan: DMARC at p=none, MTA-STS missing, BIMI missing, IP in Spamhaus DNSBL. Email Health score: C. Quantified recommendations: DMARC p=quarantine then p=reject deployment in 60 days, MTA-STS, DNSBL removal. Score climbs to A in 90 days. Avoids a phishing wave impersonating the brand.

What's included

OT/ICS protocols

  • Modbus
  • Siemens S7
  • Allen-Bradley
  • Niagara Fox
  • BACnet
  • EtherNet/IP
  • IEC-104
  • DNP3
  • OPC UA

What we scan

  • Asset discovery (80+ passive sources)
  • Email health (SPF, DKIM, DMARC, MTA-STS, BIMI)
  • Subdomain takeover (83 services)
  • Reputation & exposure
  • 100+ finding types

EASM is not a silo. All pillars use its signals.

EASM produces real exposure signals. Without them, other pillars work in theory. With them, they decide based on what's actually exposed.

  • EASM → Posture & Compliance

    An expected control (e.g., "TLS 1.2 minimum on all exposed services") can be objectively validated by EASM findings. No more declarative. No more questionnaire. The proof is observed.

  • EASM → CTI

    Each detected exposed service (with its exact version via CPE) is automatically correlated to active CVEs. An Apache HTTP 2.4.49 exposed becomes immediately a critical finding if KEV applies.

  • EASM → TPRM

    The 100+ findings are applied to third-party perimeters. The OT/ICS scanner is applied to industrial suppliers. No additional ingestion cost.

  • EASM → AI Risk Engine

    EASM provides the "actual exposure" component of the risk score. Without EASM, the AI can't distinguish a theoretical risk from a tomorrow-morning exploitable risk.

See your real risk in a 30-minute demo.

A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.

Frequently asked questions

Is the OT/ICS scanner active or passive?

Active but read-only. We fingerprint the 8 supported protocols with no writes, no control commands and no state changes, with rate limiting tuned for OT networks. Ultra-sensitive IP ranges can be excluded.

Does it cover exposed cloud buckets?

Yes. Misconfigured S3, Azure Blob and GCS are detected, and subdomain takeover is checked across 83 services including S3, Azure, GitHub Pages, Netlify, Vercel and Webflow.

How do you avoid scanning someone else's assets?

Three safeguards: ownership validation by DNS, HTTP file or attestation; an explicit IP allowlist per tenant; and configurable exclusions. Every scan is logged and exportable.

Are findings actionable or just informational?

Every finding is documented with a technical explanation, proof, severity and a step-by-step fix, with references. Critical findings can be exported to your ITSM.