Organizations using ICS equipment could use this tool to find their own systems that are accessible to the internet. However, I would imagine that companies that are responsible enough to perform checks like these hopefully already have procedures in place to prevent issues like this.
I wonder if there's room to use this software to provide direct feedback to the organizations and let them know without being prosecuted?