Factory security: know what can be reached from the Internet
A maintenance access left open, a controller plugged straight into the Internet, a forgotten gateway. Forta Exposure spots this equipment from the outside, read-only, without touching production.
15+
Industrial ports monitored
7
Protocols identified read-only
2 days
Between two scans of your perimeter
Equipment designed to be isolated, now connected to the Internet
Controllers, operator interfaces and gateways were designed for closed networks. Remote maintenance and the convergence of IT and plants open access paths nobody decided on. Several of these protocols require no authentication: whoever reaches the port can read, and sometimes change, what the machine does.
A standard scan sees your website and your email. It does not recognize a controller.
How we look, without touching production
The scan starts from the outside, as an attacker would: no agent to install in the plant, no access to your internal networks. It covers the Internet addresses attributed to your company.
Read-only
No writes, no control commands, no state changes. Only the minimum needed to recognize the protocol is sent.
Limited pace
Each address receives at most one connection attempt per monitored port, at a limited rate.
Exclusions possible
The most sensitive address ranges can be excluded from the scan.
Severity based on evidence
Maximum severity is reserved for exposures confirmed by the equipment's response. A port that is simply open is flagged as to be verified.
The ports monitored
Seven protocols are identified by a read-only handshake: the equipment's response confirms the protocol. Eight other ports are detected by a plain connection.
| Protocol | Port | Where it is found |
|---|---|---|
| Siemens S7 | 102 | Siemens SIMATIC S7 controllers |
| Modbus TCP | 502 | Controllers and sensors from many manufacturers |
| Niagara Fox | 1911 | Building management (Tridium Niagara) |
| IEC 60870-5-104 | 2404 | Telecontrol of power grids |
| OPC UA | 4840 | Data exchange between machines and systems |
| DNP3 | 20000 | Water and power networks |
| EtherNet/IP | 44818 | Rockwell Automation (Allen-Bradley) controllers, among others |
| Protocol | Port | Where it is found |
|---|---|---|
| Red Lion Crimson | 789 | Red Lion operator interfaces |
| Omron FINS | 9600 | Omron controllers |
| GE SRTP | 18245, 18246 | GE controllers (PAC, RX3i, RX7i) |
| PCWorx | 20256 | Phoenix Contact controllers |
| Mitsubishi MELSOFT | 50020 | Mitsubishi controllers |
| Mitsubishi Q | 55555 | Mitsubishi Q series controllers |
| CODESYS | 2455 | Controllers from many manufacturers programmed with CODESYS |
What the scan does not cover
Protocols that run over UDP, including BACnet/IP and PROFINET, are not scanned. The scan sees what can be reached from the Internet: it does not replace monitoring inside the plant network.
How often, and what happens next
Your perimeter
Scanned every 2 days.
Your suppliers
Scanned every week, with the same engine.
Each exposure found
Becomes an action in the Action Center, with the address and port concerned.
A maintenance access left open
A contractor opens remote access to fix a line and forgets to close it. At the next scan, Forta Exposure detects the exposed equipment, read-only. The action reaches the Action Center with the address and port concerned: the site manager knows what to close.
IEC 62443: the parts supported
Forta Compliance supports four parts of the IEC 62443 standard, among its 40+ frameworks. Your controls are assessed against them and your evidence attached, as for the other frameworks.
- IEC 62443-2-1
Security program for the asset owner.
- IEC 62443-3-3
System security requirements and security levels.
- IEC 62443-4-1
Secure product development lifecycle.
- IEC 62443-4-2
Technical security requirements for components.
Where to start
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities.
Frequently asked questions
Can the scan disrupt a production line?
It is designed to avoid that: read-only, no commands, limited pace. It only addresses what can already be reached from the Internet.
Do we need to install anything in the plant?
No. The scan starts from the outside: no agent, no probe, no access to your networks.
Is BACnet covered?
No. BACnet/IP runs over UDP and is not scanned today.
Are Allen-Bradley controllers covered?
Yes, through EtherNet/IP (port 44818), the protocol these controllers use.
What happens when exposed equipment is found?
The exposure becomes a prioritized action in Forta Actions, assigned to an owner and tracked until it is resolved.