Islanded by design
The network can't reach a vendor cloud or a corporate directory — and usually isn't permitted to.
NIST security for isolated camera, IoT, OT & building-automation networks
Skans gives an islanded network of cameras, controllers, and building systems its own root of trust — issuing an identity to every device, admitting only trusted gear, then encrypting, patching, backing up, and producing the compliance evidence. One appliance, set up by the technician who installs the cameras. Your data never leaves the wire; it runs air-gapped by default.
A sealed, air-gapped enclave of cameras, controllers and building systems, each issued its own identity from an on-site root of trust — 2 certificates due for renewal, and your data never crossing the perimeter.
The gap nobody covers
A building full of IP cameras. A campus of BACnet controllers. A plant floor of PLCs. These run on islanded networks stood up by the technician who mounts the hardware — no domain, no IT team, no cloud. Yet NIST 800-171 and CMMC now demand that every device carry an identity, encryption and access control, with evidence to prove it. The tools that do that assume a directory, a security team, and an internet connection — none of which the island has.
The network can't reach a vendor cloud or a corporate directory — and usually isn't permitted to.
A camera, intercom or controller can't domain-join or enroll itself; most ship with a self-signed cert and a default password.
The crew that installs it hangs cameras and pulls cable — they don't run PKI, Active Directory, or RADIUS.
800-171 and CMMC still require identity, encryption, NAC, patching and evidence — for every device on it.
How it works
No PKI knowledge. No IT team. The Setup Wizard asks two or three plain questions, you press one button, and the appliance stands up the whole posture behind it — directory, certificate authority, network admission, device drivers, hardening. The operator never touches AD, Kerberos, or a CLI.
Site name, network, scope. The wizard takes it from there, on golden-config defaults.
The box stands up the directory, CA and RADIUS, then issues identities and pushes certs to every device it finds.
The console reports results, not certificate chains. Renewals, admission and patches keep running on their own.
The close
A new camera ships with a self-signed certificate and a default password — untrusted and exposed. Skans issues it a real identity from your CA, replaces the cert, locks the credentials, and admits it over 802.1X. The browser warning disappears; the device is trusted, encrypted, and accounted for.
What's in the appliance
One appliance stands up the enclave's root of trust and issues an identity to every device on it — cameras, controllers, building systems, network gear, and Windows/Linux/macOS servers and endpoints (via a lightweight agent) — then handles admission, patching, backup and the compliance evidence. One console, air-gapped by default, nothing of yours leaving the wire.
Find every camera, controller, PLC and switch by multi-protocol discovery — ONVIF, network scan, industrial — auto-classified by class and capability tier.
Stand up a root of trust the enclave owns and issue an X.509 identity to every device. Per-vendor drivers push certs onto the cameras, intercoms and controllers that can't enroll themselves.
802.1X EAP-TLS admits only trusted, cert-bearing devices; MAB and dynamic VLANs for limited gear; legacy OT segmented and gated.
Staged patch rings for Windows without WSUS, plus a vetted, hash-verified firmware repository for cameras and IoT/OT gear — no internet required. Air-gapped estates stay current.
TLS on every device and service, default creds gone, a CIS/STIG baseline applied — the island goes from "not secure" to verified-secure, device by device.
Correlated, deduplicated findings bounded by device count — signal that scales with your fleet, not a firehose. Plus offline CVE & ATT&CK intel.
Versioned backups of camera, PLC and network configs, databases, secrets and firmware — encrypted and held off the source machine.
The operator sees outcomes — "cameras encrypted · 2 certs expiring" — never AD or CA internals, and hands the assessor a NIST 800-171 / CMMC evidence pack.
We meet your gear where it is
Mixed-vintage estates are the norm. Skans sorts every device into a tier and applies the strongest control it can support — full identity where possible, a driver-pushed cert where the device is limited, segmentation and a gateway where it's legacy.
Full identity + 802.1X admission + encryption + patching + config backup.
Driver-pushed certificate + config backup + monitoring + a dynamic VLAN.
Segmentation + security gateway + allow-list + monitoring — NIST 800-82 compensating controls.
How it's built
The constraints of a disconnected, regulated network drive the architecture — they aren't worked around after the fact. These are the assumptions Skans was designed on from the first line of code.
Disconnected by default: your identities, keys and data never leave, threat feeds can sync offline, and a severed WAN changes nothing about your protection. The one optional egress — the Skans Update Service — is yours to switch on or leave off.
A field tech can run it — issue a hardware token, approve a device, push a patch ring — without touching a CLI or a specialist.
Your certificate authority, your identities, your data. Nothing about your enclave lives on someone else's server.
Mapped to NIST 800-171 and CMMC controls from the start, so the evidence is in place before the assessor arrives.
How you run it
Skans is a single self-contained Windows Server appliance. It rides the native roles you already license — AD DS, AD CS, NPS — behind one console, and your identities, keys and data never leave the enclave. It's air-gapped by default; the one optional egress is the Skans Update Service, which you control. Start free with the generous Community Edition; step up to Enterprise for compliance evidence, deeper OT/ICS coverage, and vendor support.
Generous and uncapped: no device cap, no per-device fee. The enclave root of trust, the full driver pack, NAC, the credential vault, monitoring and alerts — yours to run in production.
A commercial subscription for serious estates: compliance evidence packs (ISO 27001 / CMMC), OT/ICS certificate management, SIEM forwarding and OIDC single sign-on — plus vendor support and an SLA. Multi-site (Core + Edge) and high availability are on the roadmap.
No directory on site? Skans becomes the enclave's directory, CA and RADIUS.
A Windows fleet joins the Skans domain; GPO pushes trust, policy and patch rings.
A healthy AD already exists? Skans publishes trust through it — it never hijacks your domain.
Compliance by design
Skans maps its capabilities to NIST 800-171 and CMMC control families from the start — no badge-spam, just an honest alignment you can hand an assessor.
The same measured checks also support ISO/IEC 27001:2022 — crosswalked to all 93 Annex A controls via NIST's published OLIR mapping, with a signed supporting-evidence pack and responsibility matrix for your auditor. Skans supplies the technical evidence; organizational, people and physical controls stay yours — it's your ISMS that gets certified, never a product.
The one-command evidence-pack export (NIST 800-171 / CMMC and ISO 27001) is an Enterprise feature.
Questions
By default, no — Skans runs disconnected and never sends your identities, keys or device data out. Threat feeds (CVE/MITRE ATT&CK), AV signatures and agent/patch content reach an air-gapped site by offline sync. If you'd rather have automatic online updates, you can switch on the optional Skans Update Service — a single, operator-controlled egress that only pulls licensed content down; it's off by default and never sends your data anywhere.
Only if you want it to. The Joined profile publishes trust through your AD without taking it over; the Island profile stands up its own directory when you don't have one on site.
It ships meeting the technical controls of NIST 800-171 and CMMC at mandated defaults — FIPS mode, MFA, a CIS/STIG baseline, TLS everywhere — and hands you an evidence pack. Organizational controls stay yours via a control-responsibility matrix, with any gaps tracked in a POA&M.
No — ISO/IEC 27001 certifies your organization's ISMS, not any product. What Skans does is support the audit: its continuously measured technical checks are crosswalked to the 93 Annex A controls of ISO/IEC 27001:2022, and it exports a signed supporting-evidence pack — per-control evidence, a three-way responsibility matrix, and a tamper-evident manifest. Organizational, people and physical controls remain yours.
It's sorted into a capability tier: limited devices get a driver-pushed cert and a dynamic VLAN; legacy devices get segmentation and a security gateway with compensating controls.
The field technician who installs the cameras. The Setup Wizard is two or three plain questions and one button; the PKI, directory and RADIUS run behind it. CLI and PowerShell exist only for experts.
No — Skans is proprietary, closed-source software, solely owned by its author. What you get isn't source access, it's independence: nothing of yours leaves the enclave, and you own the CA, the identities and the data. The Community Edition is free, uncapped and yours to run in production; Enterprise adds scale, compliance and support.
Who holds the line
IP cameras, access control, intercoms and recorders on islanded networks — every device given an identity and encrypted, installed by the integrator who mounts them.
HVAC, lighting, elevators and metering from the major BMS vendors — Siemens, Honeywell, Johnson Controls, Tridium — given identity where the device supports it, segmented and gated where it doesn't, without ripping out the install.
PLCs, SCADA, OPC UA and sensors across plant and utility floors — modern gear gets full identity; legacy gets segmentation and a security gateway.
Talk to us
Skans is built for the teams running networks the cloud can't reach. If your network can't touch the cloud and still has to pass an audit, email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.
Talk straight to engineering, not a sales funnel.
We map Skans to your network, your compliance scope, and your constraints.