Skip to content
FortaRisks
The whole platform

Forta Exposure

External attack surface (EASM), plants included

See your external exposure, OT/ICS included

See your entire external attack surface the way an attacker does, monitored continuously. Domains, services, certificates, leaked data and look-alike domains, plus the OT/ICS protocols generic scanners miss, all in read-only.

Forta Exposure

500+

Finding types

15+

Industrial ports monitored

30 min

To full surface

An ordinary scan sees your website. Not your Siemens controller.

Generic scanners miss industrial assets entirely, which is exactly where the real exposure often hides.

Value you can see

Outcomes your team will feel.

  • One engine, three surfaces

    Your perimeter, your vendors', and a prospect's before you sign. Same engine, three uses.

  • A grade you can explain

    Per category, per axis and overall, with actual coverage shown next to it.

  • Read-only, including on OT

    Industrial protocol detection that never disturbs the networks, maximum severity only when exposure is confirmed.

Key capabilities

  • Find your assets from your company name alone

    Give a company name, not a list of domains: the engine finds your domains, subsidiaries and acquisitions on its own, then surfaces subdomains, IPs, services, certificates and technologies. You do not have to build the inventory yourself before you start.

  • Five axes, 43 detection categories

    Email and anti-spoofing, infrastructure and web, reputation and brand, leaks and disclosure, plus OT and ICS. One hundred and seventy-four detection templates built in, nine change types tracked, and signed webhooks to Slack and Teams. Every finding carries its evidence.

  • The scan tells you what it did not look at

    Partial coverage is declared as such, never dressed up as a good grade. Very few products can do this, and none hands it back to the customer. It is what lets you know whether an A+ means "everything is clean" or "we could not see everything".

  • Official breach registries and leaked credentials

    Declarations made to regulators are used by name: CNIL, ICO, OAIC, US attorneys general, SEC EDGAR and CanadaBreaches. A public, dated, legally clean source. Leaked credentials are detected without ever storing an email address in clear text, guaranteed by design.

  • Progress over time

    Trend your exposure down and show the board a surface that shrinks month over month, with evidence.

  • Proactive exposure intel

    Dark web breach exposure, leaked credentials and look-alike domains registered against your brand, caught before they are used against you.

Not 10,000 findings. A short list of what matters.

Every new exposure, change and risk becomes one prioritized action in your feed, routed to the right owner and tracked to closure. Your team focuses only on what moves the needle, not on noise.

Three examples, three situations

  • Example · Manufacturer

    A controller reachable from the Internet after maintenance

    A contractor opens remote access to fix a production line and forgets to close it. At the next scan, Forta Exposure detects the exposed industrial equipment, read-only, without touching production. The action lands in the Action Center with the site and the port concerned.

  • Example · Multi-site company

    The forgotten assets of an acquisition

    You take over a company and its domain names. Forta Exposure finds its subdomains, services and certificates from its name alone, and adds them to your view. You know what you have just inherited.

  • Example · Prime contractor

    See what your customer will see of you

    Before answering a large customer's questionnaire, you look at your own exposure the way they will. You fix what is visible, then attach the report to your answer.

What's included

Discovery & attribution

  • Attribution from your company name alone
  • Domains, subsidiaries and acquisitions found on their own
  • 36 discovery and analysis connectors
  • 5 scan axes, 43 detection categories
  • 174 detection templates built in
  • The scan declares what it did not look at
  • Siemens S7 (port 102)
  • Modbus TCP (port 502)
  • Niagara Fox (port 1911)
  • IEC 60870-5-104 (port 2404)
  • OPC UA (port 4840)
  • DNP3 (port 20000)
  • EtherNet/IP (port 44818)
  • 8 other industrial ports detected by connection
  • Read-only, never disturbing the networks

What we scan

  • 500+ finding types, each with its evidence
  • Email health: SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI
  • Subdomain takeover (83 services)
  • Ports, TLS, headers, WAF, exposed APIs
  • Typosquatting, blocklists, reputation
  • Leaked credentials, with no address stored in clear text
  • Dark web monitoring: credentials and brand leaks
  • Exposed databases and public source code
  • CVE correlation with CVSS, EPSS and CISA KEV

Optional AI enrichment

AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.

In attack surface, AI targets explanation: turning a technical finding into a business consequence, grouping related exposures, drafting the paragraph for the board. Detection and the A+ to F grading stay deterministic and defensible.

Sovereignty: the platform is built and hosted in Canada, by a Canadian company. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.

Forta Exposure is not a silo. All modules use its signals.

EASM produces real exposure signals. Without them, other modules work in theory. With them, they decide based on what's actually exposed.

  • Forta Exposure → Forta Compliance

    An expected control (e.g., "TLS 1.2 minimum on all exposed services") can be objectively validated by EASM findings. No more declarative. No more questionnaire. The proof is observed.

  • Forta Exposure → Forta Radar

    Each detected exposed service (with its exact version via CPE) is automatically correlated to active CVEs. An Apache HTTP 2.4.49 exposed becomes immediately a critical finding if KEV applies.

  • Forta Exposure → Forta Suppliers

    The 500+ finding types are applied to third-party perimeters. The OT/ICS scanner is applied to industrial suppliers. No additional ingestion cost.

  • Forta Exposure → Forta Cockpit

    EASM provides the "actual exposure" component of the risk score. Without EASM, the AI can't distinguish a theoretical risk from a tomorrow-morning exploitable risk.

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities.

Frequently asked questions

Is the OT/ICS scanner active or passive?

Active, but read-only. At least fifteen industrial ports are checked: seven protocols are identified by a read-only handshake, eight other ports by a plain connection. No writes, no control commands, no state changes, and a limited pace per address. The most sensitive address ranges can be excluded.

Does it cover exposed cloud buckets?

Yes. Misconfigured S3, Azure Blob and GCS are detected, and subdomain takeover is checked across 83 services including S3, Azure, GitHub Pages, Netlify, Vercel and Webflow.

How do you avoid scanning a third party's assets?

Attribution starts from your company name and your domains, then every discovered asset carries ownership evidence you can review and correct. The same engine also serves, deliberately, to scan a vendor or a prospect: in that case the perimeter is explicit and, on the vendor side, validated by them.

Are findings actionable or just informational?

Every finding is documented with a technical explanation, proof, severity and a step-by-step fix, with references. Critical findings can be exported to your ITSM.