NIST security for isolated camera, IoT, OT & building-automation networks

Everything inside.
Nothing out.

Skans gives an islanded network of cameras, controllers, and building systems its own root of trust — an identity for every device, admission for only trusted gear, then encryption, patching, backup and the compliance evidence. One appliance, set up by the technician who installs the cameras.

Community Edition is free forever — $0, no credit card, production-ready up to 25 endpoints.

Air-gapped by default NIST 800-171 / CMMC Set up by the install tech
Skans console · Devices
The Skans console device inventory — cameras, switches and firewalls with certificate status and capability tiers

A sealed, air-gapped enclave of cameras, controllers and building systems, each issued its own identity from an on-site root of trust — and your data never crossing the perimeter.

Works with the gear you already run — from cameras to controllers to the plant floor

Cameras & physical securityAxis · Hanwha · Bosch · 2N · Uniview
Building automationSiemens Desigo · Honeywell · Johnson Controls · Tridium
NetworkCisco · Juniper · Aruba · Fortinet
Industrial & OTSiemens S7 · Beckhoff · Wago · OPC UA

The gap nobody covers

Installed by trades.
Audited like IT.

A building full of IP cameras. A campus of BACnet controllers. A plant floor of PLCs. These run on islanded networks stood up by the technician who mounts the hardware — no domain, no IT team, no cloud. Yet NIST 800-171 and CMMC now demand that every device carry an identity, encryption and access control, with evidence to prove it. The tools that do that assume a directory, a security team, and an internet connection — none of which the island has.

Islanded by design

The network can't reach a vendor cloud or a corporate directory — and usually isn't permitted to.

Dumb devices, no identity

A camera, intercom or controller can't domain-join or enroll itself; most ship with a self-signed cert and a default password.

No IT team on site

The crew that installs it hangs cameras and pulls cable — they don't run PKI, Active Directory, or RADIUS.

Audited anyway

800-171 and CMMC still require identity, encryption, NAC, patching and evidence — for every device on it.

The cloud can't reach here.
So we built the security that lives inside.

How it works

From cable to compliant — by the tech who hung the cameras.

No PKI knowledge. No IT team. The Setup Wizard asks two or three plain questions, you press one button, and the appliance stands up the whole posture behind it — directory, certificate authority, network admission, device drivers, hardening. The operator never touches AD, Kerberos, or a CLI.

1

Plug in, answer 2–3 questions

Site name, network, scope. The wizard takes it from there, on golden-config defaults.

2

One button → secured site

The box stands up the directory, CA and RADIUS, then issues identities and pushes certs to every device it finds.

3

Run it by outcomes

The console reports results, not certificate chains. Renewals, admission and patches keep running on their own.

The console

See it the way the operator does.

One console for the whole enclave — every device and its identity, the compliance posture an assessor asks for, and the alerts that actually matter. Air-gapped, role-based, nothing leaving the wire.

One question away

The whole appliance, run by outcomes.

Ask the box in plain language, or read the triage at a glance — what needs you, where compliance stands, whether last night's backup ran. The operator sees results, never certificate chains.

  • Ask or command the appliance — "certs", "what needs me", "open incidents".
  • Correlated triage — a bounded worklist, not a firehose of events.
  • Outcomes, not internals — never AD, Kerberos or a CLI.
Skans console · Home
The Skans console home — an ask-the-appliance command bar over a correlated worklist of what needs attention

Compliance by design

The evidence an assessor asks for — already in place.

Live NIST 800-171 posture mapped to control families, with an ISO 27001 crosswalk, a signed evidence pack, reports and an audit trail you hand straight over.

  • Posture by control family — AC, AU, CM, IA, RA, SC…
  • Signed evidence pack — per-control and tamper-evident.
  • An icon and a word, never colour alone.
Skans console · Compliance
The Skans compliance view — a NIST posture ring and per-control-family status cards

Signal, not noise

Detection is the product's judgment. Where it lands is yours.

Correlated, deduplicated findings — bounded by device count, not raw volume. Rules decide what fires; routing decides where it goes; suppressions are recorded exceptions.

  • Rules & routing per severity, with cooldowns.
  • Offline security feeds — CVE, KEV, EPSS, ATT&CK (incl. ICS), Sigma + malware defs.
  • Recorded exceptions, never silent muting.
Skans console · Alerting
The Skans alerting view — alert rules by type and severity with cooldowns

What's in the appliance

Every device secured. The whole enclave compliant.

One appliance stands up the enclave's root of trust and issues an identity to every device on it — cameras, controllers, building systems, network gear, and Windows/Linux/macOS servers and endpoints (via a lightweight agent) — then handles admission, patching, backup and the compliance evidence. One console, air-gapped by default, nothing of yours leaving the wire.

Device discovery & inventory

Find every camera, controller, PLC and switch by multi-protocol discovery — ONVIF, network scan, industrial — auto-classified by class and capability tier.

Identity for every device

Stand up a root of trust the enclave owns and issue an X.509 identity to every device. Per-vendor drivers push certs onto the cameras, intercoms and controllers that can't enroll themselves.

Network access control

802.1X EAP-TLS admits only trusted, cert-bearing devices; MAB and dynamic VLANs for limited gear; legacy OT segmented and gated.

Patch & firmware

Staged patch rings for Windows without WSUS, plus a vetted, hash-verified firmware repository for cameras and IoT/OT gear — no internet required. Air-gapped estates stay current.

Encryption & hardening

TLS on every device and service, default creds gone, a CIS/STIG baseline applied — the island goes from "not secure" to verified-secure, device by device.

Continuous monitoring

Correlated, deduplicated findings bounded by device count — signal that scales with your fleet, not a firehose. Plus offline CVE, KEV, EPSS, ATT&CK & Sigma intel.

Backup & config vault

Versioned backups of camera, PLC and network configs, databases, secrets and firmware — encrypted and held off the source machine.

One console & compliance evidence

The operator sees outcomes — "cameras encrypted · 2 certs expiring" — never AD or CA internals, and hands the assessor a NIST 800-171 / CMMC evidence pack.

We meet your gear where it is

Not everything can hold a certificate. We plan for that.

Mixed-vintage estates are the norm. Skans sorts every device into a tier and applies the strongest control it can support — full identity where possible, a driver-pushed cert where the device is limited, segmentation and a gateway where it's legacy.

A

Cert-capablemodern cameras, servers, network gear, OPC UA

Full identity + 802.1X admission + encryption + patching + config backup.

B

Limitedcert or proprietary mgmt only; maybe no 802.1X

Driver-pushed certificate + config backup + monitoring + a dynamic VLAN.

C

Legacyold PLCs, serial-over-ethernet, BACnet MS/TP, raw Modbus

Segmentation + security gateway + allow-list + monitoring — NIST 800-82 compensating controls.

How it's built

Air-gap-first, not air-gap-capable.

The constraints of a disconnected, regulated network drive the architecture — they aren't worked around after the fact. These are the assumptions Skans was designed on from the first line of code.

  1. 01

    Air-gap-first

    Disconnected by default: your identities, keys and data never leave, threat feeds can sync offline, and a severed WAN changes nothing about your protection. The one optional egress — the Skans Update Service — is yours to switch on or leave off.

  2. 02

    Simple to operate

    A field tech can run it — issue a hardware token, approve a device, push a patch ring — without touching a CLI or a specialist.

  3. 03

    You own the keys

    Your certificate authority, your identities, your data. Nothing about your enclave lives on someone else's server.

  4. 04

    Aligned by design

    Mapped to NIST 800-171 and CMMC controls from the start, so the evidence is in place before the assessor arrives.

Editions

Start free. Grow by the site.

One self-contained appliance, five editions — priced per site by the managed endpoints you protect, never by seats or agents. Community is free forever ($0, no card); paid editions add depth as a site grows. Each includes everything in the one before it.

What holds the line

0bytes of your data sent to any cloud — by design.
0%Security feeds (CVE, KEV, EPSS, ATT&CK, Sigma) + malware defs — offline or via optional SUS.
1,471 → 2raw events correlated to calm findings.
0console — every control, every device, role-based.

Compliance by design

The evidence is already in place.

Skans maps its capabilities to NIST 800-171 and CMMC control families from the start — no badge-spam, just an honest alignment you can hand an assessor.

NIST 800-171 familyCovered byHow
Access ControlNetwork access control802.1X + MAB with RADIUS-assigned VLANs gates the network to trusted devices only.
Identification & AuthenticationHardware-backed identityPIV + FIDO2 from your own CA satisfies hardware-backed MFA and device trust.
Configuration ManagementPatch managementStaged patch rings without WSUS keep a documented, enforced baseline.
Risk AssessmentVulnerability & threat intelOffline CVE/KEV/EPSS matching + ATT&CK (incl. ICS) + Sigma mapping evidences continuous risk assessment.
System & Information IntegrityContinuous monitoringCorrelated, deduplicated findings provide bounded, reviewable integrity signal.
Media ProtectionEndpoint & server backupOff-source backups protect the confidentiality of backup CUI at rest (§3.8.9), held off the source machine.

The same measured checks also support ISO/IEC 27001:2022 — crosswalked to all 93 Annex A controls via NIST's published OLIR mapping, with a signed supporting-evidence pack and responsibility matrix for your auditor. Skans supplies the technical evidence; organizational, people and physical controls stay yours — it's your ISMS that gets certified, never a product.

The one-command evidence-pack export (NIST 800-171 / CMMC and ISO 27001) is an Enterprise feature.

Questions

What security teams ask first.

Straight answers on phoning home, your existing Active Directory, the standards it meets, and who actually installs and runs it.

Does it phone home?

By default, no — Skans runs disconnected and never sends your identities, keys or device data out. Security feeds (CVE, KEV, EPSS, MITRE ATT&CK including ICS, Sigma), malware definitions, and agent/product content reach an air-gapped site by offline sync. If you'd rather have automatic online updates, you can switch on the optional Skans Update Service — a single, operator-controlled egress that only pulls signed content down (available on every edition, including free Community); it's off by default and never sends your data anywhere. Offline sneakernet bundles and offline licensing are Enterprise.

Will it touch our existing Active Directory?

Only if you want it to. The Joined profile publishes trust through your AD without taking it over; the Island profile stands up its own directory when you don't have one on site.

What standards does it meet?

It ships meeting the technical controls of NIST 800-171 and CMMC at mandated defaults — FIPS mode, MFA, a CIS/STIG baseline, TLS everywhere — and hands you an evidence pack. Organizational controls stay yours via a control-responsibility matrix, with any gaps tracked in a POA&M.

Can Skans make us ISO 27001 certified?

No — ISO/IEC 27001 certifies your organization's ISMS, not any product. What Skans does is support the audit: its continuously measured technical checks are crosswalked to the 93 Annex A controls of ISO/IEC 27001:2022, and it exports a signed supporting-evidence pack — per-control evidence, a three-way responsibility matrix, and a tamper-evident manifest. Organizational, people and physical controls remain yours.

What if a device can't hold a certificate?

It's sorted into a capability tier: limited devices get a driver-pushed cert and a dynamic VLAN; legacy devices get segmentation and a security gateway with compensating controls.

Who installs and runs it?

The field technician who installs the cameras. The Setup Wizard is two or three plain questions and one button; the PKI, directory and RADIUS run behind it. CLI and PowerShell exist only for experts.

Is Community Edition really free?

Yes — free forever. Community is $0 with no credit card and is production-ready up to 25 managed endpoints: root of trust, full driver pack, NAC visibility, security feeds (CVE, KEV, EPSS, ATT&CK, Sigma) and malware defs, vault and monitoring. When a site outgrows that band or needs deeper controls, step up to a paid edition — each includes everything below it. See editions →

Is Skans open source?

No — Skans is proprietary, closed-source software, solely owned by its author. What you get isn't source access, it's independence: nothing of yours leaves the enclave, and you own the CA, the identities and the data. The Community Edition is free forever ($0, no credit card) for production use up to 25 managed endpoints; paid editions add depth, scale and support as a site grows.

Who holds the line

Built for the networks that can't touch the cloud.

The same root of trust, tuned to three worlds that live off the cloud — physical security, building automation, and the plant floor. Need design help beyond a single product? We offer IoT / OT professional services across cameras, BMS and plant floor.

Video surveillance & physical security

IP cameras, access control, intercoms and recorders on islanded networks — every device given an identity and encrypted, installed by the integrator who mounts them.

Building automation & facilities

HVAC, lighting, elevators and metering from the major BMS vendors — Siemens, Honeywell, Johnson Controls, Tridium — given identity where the device supports it, segmented and gated where it doesn't, without ripping out the install.

Industrial & OT networks

PLCs, SCADA, OPC UA and sensors across plant and utility floors — modern gear gets full identity; legacy gets segmentation and a security gateway.

Professional services — broad IoT/OT expertise: architecture, identity, containment, firmware risk, and evidence planning for air-gapped islands. Not limited to the Skans appliance — design the enclave first; product is optional.

Talk to us

Tell us about the network
you can't put in the cloud.

Skans is built for the teams running networks the cloud can't reach. If your network can't touch the cloud and still has to pass an audit, email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.

A real conversation

Talk straight to engineering, not a sales funnel.

Product or professional services

Appliance briefings when you want the box — or broader IoT/OT architecture and risk help on whatever stack you run.