NIST security for isolated camera, IoT, OT & building-automation networks

Everything inside.
Nothing out.

Skans gives an islanded network of cameras, controllers, and building systems its own root of trust — issuing an identity to every device, admitting only trusted gear, then encrypting, patching, backing up, and producing the compliance evidence. One appliance, set up by the technician who installs the cameras. Your data never leaves the wire; it runs air-gapped by default.

A sealed, air-gapped enclave of cameras, controllers and building systems, each issued its own identity from an on-site root of trust — 2 certificates due for renewal, and your data never crossing the perimeter.

The gap nobody covers

Installed by trades. Audited like IT.

A building full of IP cameras. A campus of BACnet controllers. A plant floor of PLCs. These run on islanded networks stood up by the technician who mounts the hardware — no domain, no IT team, no cloud. Yet NIST 800-171 and CMMC now demand that every device carry an identity, encryption and access control, with evidence to prove it. The tools that do that assume a directory, a security team, and an internet connection — none of which the island has.

Islanded by design

The network can't reach a vendor cloud or a corporate directory — and usually isn't permitted to.

Dumb devices, no identity

A camera, intercom or controller can't domain-join or enroll itself; most ship with a self-signed cert and a default password.

No IT team on site

The crew that installs it hangs cameras and pulls cable — they don't run PKI, Active Directory, or RADIUS.

Audited anyway

800-171 and CMMC still require identity, encryption, NAC, patching and evidence — for every device on it.

The cloud can't reach here.
So we built the security that lives inside.

How it works

From cable to compliant — by the tech who hung the cameras.

No PKI knowledge. No IT team. The Setup Wizard asks two or three plain questions, you press one button, and the appliance stands up the whole posture behind it — directory, certificate authority, network admission, device drivers, hardening. The operator never touches AD, Kerberos, or a CLI.

1

Plug in, answer 2–3 questions

Site name, network, scope. The wizard takes it from there, on golden-config defaults.

2

One button → secured site

The box stands up the directory, CA and RADIUS, then issues identities and pushes certs to every device it finds.

3

Run it by outcomes

The console reports results, not certificate chains. Renewals, admission and patches keep running on their own.

The close

Every device, from default to defended.

A new camera ships with a self-signed certificate and a default password — untrusted and exposed. Skans issues it a real identity from your CA, replaces the cert, locks the credentials, and admits it over 802.1X. The browser warning disappears; the device is trusted, encrypted, and accounted for.

CAMERA-07
  • self-signed untrusted certificate
  • default creds factory password
  • open unrestricted on the LAN
CAMERA-07
  • CA-issued identity from your root of trust
  • hardened credentials rotated & vaulted
  • 802.1X admitted, encrypted, accounted for

What's in the appliance

Every device secured. The whole enclave compliant.

One appliance stands up the enclave's root of trust and issues an identity to every device on it — cameras, controllers, building systems, network gear, and Windows/Linux/macOS servers and endpoints (via a lightweight agent) — then handles admission, patching, backup and the compliance evidence. One console, air-gapped by default, nothing of yours leaving the wire.

Device discovery & inventory

Find every camera, controller, PLC and switch by multi-protocol discovery — ONVIF, network scan, industrial — auto-classified by class and capability tier.

Identity for every device

Stand up a root of trust the enclave owns and issue an X.509 identity to every device. Per-vendor drivers push certs onto the cameras, intercoms and controllers that can't enroll themselves.

Network access control

802.1X EAP-TLS admits only trusted, cert-bearing devices; MAB and dynamic VLANs for limited gear; legacy OT segmented and gated.

Patch & firmware

Staged patch rings for Windows without WSUS, plus a vetted, hash-verified firmware repository for cameras and IoT/OT gear — no internet required. Air-gapped estates stay current.

Encryption & hardening

TLS on every device and service, default creds gone, a CIS/STIG baseline applied — the island goes from "not secure" to verified-secure, device by device.

Continuous monitoring

Correlated, deduplicated findings bounded by device count — signal that scales with your fleet, not a firehose. Plus offline CVE & ATT&CK intel.

Backup & config vault

Versioned backups of camera, PLC and network configs, databases, secrets and firmware — encrypted and held off the source machine.

One console & compliance evidence

The operator sees outcomes — "cameras encrypted · 2 certs expiring" — never AD or CA internals, and hands the assessor a NIST 800-171 / CMMC evidence pack.

We meet your gear where it is

Not everything can hold a certificate. We plan for that.

Mixed-vintage estates are the norm. Skans sorts every device into a tier and applies the strongest control it can support — full identity where possible, a driver-pushed cert where the device is limited, segmentation and a gateway where it's legacy.

A

Cert-capablemodern cameras, servers, network gear, OPC UA

Full identity + 802.1X admission + encryption + patching + config backup.

B

Limitedcert or proprietary mgmt only; maybe no 802.1X

Driver-pushed certificate + config backup + monitoring + a dynamic VLAN.

C

Legacyold PLCs, serial-over-ethernet, BACnet MS/TP, raw Modbus

Segmentation + security gateway + allow-list + monitoring — NIST 800-82 compensating controls.

How it's built

Air-gap-first, not air-gap-capable.

The constraints of a disconnected, regulated network drive the architecture — they aren't worked around after the fact. These are the assumptions Skans was designed on from the first line of code.

  1. 01

    Air-gap-first

    Disconnected by default: your identities, keys and data never leave, threat feeds can sync offline, and a severed WAN changes nothing about your protection. The one optional egress — the Skans Update Service — is yours to switch on or leave off.

  2. 02

    Simple to operate

    A field tech can run it — issue a hardware token, approve a device, push a patch ring — without touching a CLI or a specialist.

  3. 03

    You own the keys

    Your certificate authority, your identities, your data. Nothing about your enclave lives on someone else's server.

  4. 04

    Aligned by design

    Mapped to NIST 800-171 and CMMC controls from the start, so the evidence is in place before the assessor arrives.

How you run it

Your keys. Your data never leaves.

Skans is a single self-contained Windows Server appliance. It rides the native roles you already license — AD DS, AD CS, NPS — behind one console, and your identities, keys and data never leave the enclave. It's air-gapped by default; the one optional egress is the Skans Update Service, which you control. Start free with the generous Community Edition; step up to Enterprise for compliance evidence, deeper OT/ICS coverage, and vendor support.

Community Edition — free

Generous and uncapped: no device cap, no per-device fee. The enclave root of trust, the full driver pack, NAC, the credential vault, monitoring and alerts — yours to run in production.

Enterprise — licensed

A commercial subscription for serious estates: compliance evidence packs (ISO 27001 / CMMC), OT/ICS certificate management, SIEM forwarding and OIDC single sign-on — plus vendor support and an SLA. Multi-site (Core + Edge) and high availability are on the roadmap.

Island · flagship

No directory on site? Skans becomes the enclave's directory, CA and RADIUS.

Full-Site

A Windows fleet joins the Skans domain; GPO pushes trust, policy and patch rings.

Joined

A healthy AD already exists? Skans publishes trust through it — it never hijacks your domain.

What holds the line

0bytes of your data sent to any cloud — by design.
0%CVE + MITRE ATT&CK feeds synced without internet.
1,471 → 2raw events correlated to calm findings.
0console — every control, every device, role-based.

Compliance by design

The evidence is already in place.

Skans maps its capabilities to NIST 800-171 and CMMC control families from the start — no badge-spam, just an honest alignment you can hand an assessor.

NIST 800-171 familyCovered byHow
Access ControlNetwork access control802.1X + MAB with RADIUS-assigned VLANs gates the network to trusted devices only.
Identification & AuthenticationHardware-backed identityPIV + FIDO2 from your own CA satisfies hardware-backed MFA and device trust.
Configuration ManagementPatch managementStaged patch rings without WSUS keep a documented, enforced baseline.
Risk AssessmentVulnerability & threat intelOffline CVE matching + ATT&CK mapping evidences continuous risk assessment.
System & Information IntegrityContinuous monitoringCorrelated, deduplicated findings provide bounded, reviewable integrity signal.
Media ProtectionEndpoint & server backupOff-source backups protect the confidentiality of backup CUI at rest (§3.8.9), held off the source machine.

The same measured checks also support ISO/IEC 27001:2022 — crosswalked to all 93 Annex A controls via NIST's published OLIR mapping, with a signed supporting-evidence pack and responsibility matrix for your auditor. Skans supplies the technical evidence; organizational, people and physical controls stay yours — it's your ISMS that gets certified, never a product.

The one-command evidence-pack export (NIST 800-171 / CMMC and ISO 27001) is an Enterprise feature.

Questions

What security teams ask first.

Does it phone home?

By default, no — Skans runs disconnected and never sends your identities, keys or device data out. Threat feeds (CVE/MITRE ATT&CK), AV signatures and agent/patch content reach an air-gapped site by offline sync. If you'd rather have automatic online updates, you can switch on the optional Skans Update Service — a single, operator-controlled egress that only pulls licensed content down; it's off by default and never sends your data anywhere.

Will it touch our existing Active Directory?

Only if you want it to. The Joined profile publishes trust through your AD without taking it over; the Island profile stands up its own directory when you don't have one on site.

What standards does it meet?

It ships meeting the technical controls of NIST 800-171 and CMMC at mandated defaults — FIPS mode, MFA, a CIS/STIG baseline, TLS everywhere — and hands you an evidence pack. Organizational controls stay yours via a control-responsibility matrix, with any gaps tracked in a POA&M.

Can Skans make us ISO 27001 certified?

No — ISO/IEC 27001 certifies your organization's ISMS, not any product. What Skans does is support the audit: its continuously measured technical checks are crosswalked to the 93 Annex A controls of ISO/IEC 27001:2022, and it exports a signed supporting-evidence pack — per-control evidence, a three-way responsibility matrix, and a tamper-evident manifest. Organizational, people and physical controls remain yours.

What if a device can't hold a certificate?

It's sorted into a capability tier: limited devices get a driver-pushed cert and a dynamic VLAN; legacy devices get segmentation and a security gateway with compensating controls.

Who installs and runs it?

The field technician who installs the cameras. The Setup Wizard is two or three plain questions and one button; the PKI, directory and RADIUS run behind it. CLI and PowerShell exist only for experts.

Is Skans open source?

No — Skans is proprietary, closed-source software, solely owned by its author. What you get isn't source access, it's independence: nothing of yours leaves the enclave, and you own the CA, the identities and the data. The Community Edition is free, uncapped and yours to run in production; Enterprise adds scale, compliance and support.

Who holds the line

Built for the networks that can't touch the cloud.

Video surveillance & physical security

IP cameras, access control, intercoms and recorders on islanded networks — every device given an identity and encrypted, installed by the integrator who mounts them.

Building automation & facilities

HVAC, lighting, elevators and metering from the major BMS vendors — Siemens, Honeywell, Johnson Controls, Tridium — given identity where the device supports it, segmented and gated where it doesn't, without ripping out the install.

Industrial & OT networks

PLCs, SCADA, OPC UA and sensors across plant and utility floors — modern gear gets full identity; legacy gets segmentation and a security gateway.

Talk to us

Tell us about the network
you can't put in the cloud.

Skans is built for the teams running networks the cloud can't reach. If your network can't touch the cloud and still has to pass an audit, email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.

Request a briefing

A real conversation

Talk straight to engineering, not a sales funnel.

Built around your enclave

We map Skans to your network, your compliance scope, and your constraints.