Forta Exposure
External attack surface (EASM), plants included
See your external exposure, OT/ICS included
See your entire external attack surface the way an attacker does, monitored continuously. Domains, services, certificates, leaked data and look-alike domains, plus the OT/ICS protocols generic scanners miss, all in read-only.

500+
Finding types
15+
Industrial ports monitored
30 min
To full surface
An ordinary scan sees your website. Not your Siemens controller.
Generic scanners miss industrial assets entirely, which is exactly where the real exposure often hides.
Outcomes your team will feel.
One engine, three surfaces
Your perimeter, your vendors', and a prospect's before you sign. Same engine, three uses.
A grade you can explain
Per category, per axis and overall, with actual coverage shown next to it.
Read-only, including on OT
Industrial protocol detection that never disturbs the networks, maximum severity only when exposure is confirmed.
Key capabilities
Find your assets from your company name alone
Give a company name, not a list of domains: the engine finds your domains, subsidiaries and acquisitions on its own, then surfaces subdomains, IPs, services, certificates and technologies. You do not have to build the inventory yourself before you start.
Five axes, 43 detection categories
Email and anti-spoofing, infrastructure and web, reputation and brand, leaks and disclosure, plus OT and ICS. One hundred and seventy-four detection templates built in, nine change types tracked, and signed webhooks to Slack and Teams. Every finding carries its evidence.
The scan tells you what it did not look at
Partial coverage is declared as such, never dressed up as a good grade. Very few products can do this, and none hands it back to the customer. It is what lets you know whether an A+ means "everything is clean" or "we could not see everything".
Official breach registries and leaked credentials
Declarations made to regulators are used by name: CNIL, ICO, OAIC, US attorneys general, SEC EDGAR and CanadaBreaches. A public, dated, legally clean source. Leaked credentials are detected without ever storing an email address in clear text, guaranteed by design.
Progress over time
Trend your exposure down and show the board a surface that shrinks month over month, with evidence.
Proactive exposure intel
Dark web breach exposure, leaked credentials and look-alike domains registered against your brand, caught before they are used against you.
Not 10,000 findings. A short list of what matters.
Every new exposure, change and risk becomes one prioritized action in your feed, routed to the right owner and tracked to closure. Your team focuses only on what moves the needle, not on noise.
Three examples, three situations
- Example · Manufacturer
A controller reachable from the Internet after maintenance
A contractor opens remote access to fix a production line and forgets to close it. At the next scan, Forta Exposure detects the exposed industrial equipment, read-only, without touching production. The action lands in the Action Center with the site and the port concerned.
- Example · Multi-site company
The forgotten assets of an acquisition
You take over a company and its domain names. Forta Exposure finds its subdomains, services and certificates from its name alone, and adds them to your view. You know what you have just inherited.
- Example · Prime contractor
See what your customer will see of you
Before answering a large customer's questionnaire, you look at your own exposure the way they will. You fix what is visible, then attach the report to your answer.
What's included
Discovery & attribution
- Attribution from your company name alone
- Domains, subsidiaries and acquisitions found on their own
- 36 discovery and analysis connectors
- 5 scan axes, 43 detection categories
- 174 detection templates built in
- The scan declares what it did not look at
- Siemens S7 (port 102)
- Modbus TCP (port 502)
- Niagara Fox (port 1911)
- IEC 60870-5-104 (port 2404)
- OPC UA (port 4840)
- DNP3 (port 20000)
- EtherNet/IP (port 44818)
- 8 other industrial ports detected by connection
- Read-only, never disturbing the networks
What we scan
- 500+ finding types, each with its evidence
- Email health: SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI
- Subdomain takeover (83 services)
- Ports, TLS, headers, WAF, exposed APIs
- Typosquatting, blocklists, reputation
- Leaked credentials, with no address stored in clear text
- Dark web monitoring: credentials and brand leaks
- Exposed databases and public source code
- CVE correlation with CVSS, EPSS and CISA KEV
Optional AI enrichment
AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.
In attack surface, AI targets explanation: turning a technical finding into a business consequence, grouping related exposures, drafting the paragraph for the board. Detection and the A+ to F grading stay deterministic and defensible.
Sovereignty: the platform is built and hosted in Canada, by a Canadian company. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.
Forta Exposure is not a silo. All modules use its signals.
EASM produces real exposure signals. Without them, other modules work in theory. With them, they decide based on what's actually exposed.
Forta Exposure → Forta Compliance
An expected control (e.g., "TLS 1.2 minimum on all exposed services") can be objectively validated by EASM findings. No more declarative. No more questionnaire. The proof is observed.
Forta Exposure → Forta Radar
Each detected exposed service (with its exact version via CPE) is automatically correlated to active CVEs. An Apache HTTP 2.4.49 exposed becomes immediately a critical finding if KEV applies.
Forta Exposure → Forta Suppliers
The 500+ finding types are applied to third-party perimeters. The OT/ICS scanner is applied to industrial suppliers. No additional ingestion cost.
Forta Exposure → Forta Cockpit
EASM provides the "actual exposure" component of the risk score. Without EASM, the AI can't distinguish a theoretical risk from a tomorrow-morning exploitable risk.
Explore the other modules.
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities.
Frequently asked questions
Is the OT/ICS scanner active or passive?
Active, but read-only. At least fifteen industrial ports are checked: seven protocols are identified by a read-only handshake, eight other ports by a plain connection. No writes, no control commands, no state changes, and a limited pace per address. The most sensitive address ranges can be excluded.
Does it cover exposed cloud buckets?
Yes. Misconfigured S3, Azure Blob and GCS are detected, and subdomain takeover is checked across 83 services including S3, Azure, GitHub Pages, Netlify, Vercel and Webflow.
How do you avoid scanning a third party's assets?
Attribution starts from your company name and your domains, then every discovered asset carries ownership evidence you can review and correct. The same engine also serves, deliberately, to scan a vendor or a prospect: in that case the perimeter is explicit and, on the vendor side, validated by them.
Are findings actionable or just informational?
Every finding is documented with a technical explanation, proof, severity and a step-by-step fix, with references. Critical findings can be exported to your ITSM.