Back to Blog

Cameras, Printers and PLCs: The Attack Surface Nobody Watches

Ask a security team to list their internet-facing assets and they'll name servers, websites and VPN gateways. Ask an attacker the same question and they'll add the IP camera above the loading dock, the network video recorder in the comms room, and the building controller someone connected a decade ago. TONK, our external attack surface management (EASM) platform, now watches the devices nobody else does.

Why attackers love embedded devices

Operational technology (OT) and Internet of Things (IoT) devices are a gift to attackers, and the reasons are structural. They ship with default credentials that never get changed. They run firmware that can't take an endpoint agent and rarely sees a patch. They're installed by facilities teams, integrators or vendors — so they never enter the IT asset register, never join the patch cycle, and never appear in the vulnerability management tooling built around servers and workstations.

The consequences are well documented: cameras and recorders conscripted into botnets, network storage devices hit by dedicated ransomware strains, and exposed industrial control systems (ICS) drawing the specific attention of the Australian Signals Directorate, which has repeatedly warned critical infrastructure operators about internet-reachable control equipment. For organisations covered by the Security of Critical Infrastructure (SOCI) Act, an unwatched exposed controller isn't just a security gap — it's a compliance one.

Your servers are patched, monitored and behind a WAF. The camera on the warehouse wall is running 2019 firmware with the password it shipped with. Guess which one the attacker tries first.

What's new: device exposures become first-class findings

TONK now recognises OT and IoT equipment during every scan and raises device exposures as findings in their own right — in a dedicated OT/IoT view in the Response Centre, with the same severity rating, triage workflow and remediation tracking as any CVE. When a scan identifies an exposed camera, recorder or industrial protocol on your perimeter, it becomes a tracked piece of work, not a line buried in a port list.

Detection is only half the answer, so verification grew to match. Our active probing now covers roughly forty device and appliance vendor families — IP cameras and video recorders, small-office routers, network storage, out-of-band server management controllers, printers, security appliances, VoIP systems, and SCADA equipment — checking for the known vulnerabilities, exposed panels and default credentials specific to each family. Fragile OT equipment is probed deliberately gently: industrial gear that predates the modern internet deserves care, and a verification that crashes a controller isn't a verification.

TONK Response Centre showing a dedicated OT/IoT category with four active findings — an exposed Modbus ICS/SCADA service, a network printer, a Dahua video recorder and a Hikvision IP camera — each with its own severity and triage state.
Exposed cameras, recorders, printers and industrial protocols surface as first-class findings in a dedicated OT/IoT triage view. (Demo environment shown.)

What you can now see

  • Device exposures as findings — cameras, recorders and industrial protocols surface in a dedicated OT/IoT triage view the moment a scan sees them.
  • Verified, not guessed — active checks confirm real vulnerabilities, exposed panels and default credentials across dozens of device families, so triage starts from evidence.
  • Safe for fragile equipment — OT-aware probing that verifies exposure without endangering the device behind it.
  • One lifecycle — device findings flow through the same triage, remediation and reporting pipeline as everything else, so they can't fall between teams.

Who this is for

Any organisation with a physical footprint has this exposure: warehouses, depots, manufacturing sites, branch offices, campuses. It matters most to operators of critical infrastructure under the SOCI Act, and to any security leader whose asset register stops at the devices that can run an agent. The perimeter doesn't care which team installed the device — and neither do attackers.

How it fits

OT and IoT coverage is part of TONK's continuous external attack surface management — the same platform that discovers your internet-facing assets, verifies real vulnerabilities, and tracks them through to remediation. Built in Australia, hosted in Australia, operated by Australians.

Back to Blog

Find the Devices on Your Perimeter

Before someone else does. Talk to our team about OT/IoT exposure discovery in TONK.

Request a Demo