Patch & firmware management

Every host patched. Every image verified. No endpoint touches the internet.

Skans keeps an isolated enclave current the way an island demands. The appliance pulls and caches Microsoft updates, stages them through pilot-then-production rings, and Authenticode-verifies every payload to a Microsoft publisher before a single host installs it — while a hash-verified repository does the same for camera and OT firmware. No WSUS, no vendor cloud, nothing of yours leaving the wire.

Skans console · Updates
The Skans updates view — Microsoft-signature-gated updates, per-ring approval, a fleet patch-compliance bar chart and a hash-verified firmware repository.

Change control

Staged rings, not a WSUS server.

WSUS is a dead end on Windows Server 2025 — its catalog sync floods errors and never completes, so Skans doesn't use it. Instead the appliance's own Windows Update Agent pulls and caches updates, and you stage the rollout by ring. Promote a representative host into the pilot ring, approve the update there, watch it, then roll the fleet. Both rings keep Windows Update quiescent, so nothing installs and nothing reboots until you say so.

  • The appliance is the source — it pulls from Microsoft Update once and caches; no endpoint ever reaches out for a patch.
  • Pilot → production — move a host into the Skans-Pilot ring, approve there, then promote. Ring-based change control that maps to NIST CM-3.
  • Signed before it installs — every OS-update and Defender payload is Authenticode-verified to a Microsoft publisher first (SI-7).
  • No surprise reboots — GPO keeps Windows Update quiescent, so nothing installs or reboots on Microsoft's timetable; the rollout waits on your approval.
Skans console · Updates
The Skans updates view — signature-gated updates with per-ring approval and a fleet patch-compliance bar chart.

Visibility

Know exactly what's missing — offline.

You can't patch what you can't see, and an island can't ask Microsoft what it's short. So Skans scans each Windows host against Microsoft's offline wsusscn2.cab catalog with the Windows Update Agent — no internet required — and lists the exact KBs each host lacks. Open a device's Updates tab to read enclave-wide patch posture without a single endpoint calling home.

  • Offline catalog — scans against Microsoft's signed wsusscn2.cab, so no outbound path is needed to know what's missing.
  • Per-host missing KBs — every Windows device's Updates tab shows the specific KBs it lacks, drawn from the distributed catalog.
  • Runs on a schedule — a weekly in-process job refreshes posture, so the picture the console shows is never stale.
  • Evidence built in — the missing-KB report supports NIST SI-2 (flaw remediation) and RA-5 (reporting).
Skans console · Devices
The Skans device inventory — Windows hosts, cameras and switches with their patch and certificate status.

Firmware

A firmware repository you can actually trust.

Cameras, intercoms and controllers don't take Windows updates — they take vendor firmware, and firmware is exactly where a supply-chain attack hides. Skans keeps a vetted, SHA-256-hashed repository per vendor and model, populated offline from a signed bundle so nothing enters the enclave unverified. The box compares each device's live firmware against the vetted baseline and flags what's drifted.

  • Hash-verified, offline-loaded — every image carries a recorded SHA-256 and enters only from a signed bundle, never off the open internet.
  • STALE flagging — a scheduler job compares live inventory to the baseline with a version-aware compare and flags devices that have fallen behind.
  • Hard-gated push — a flash can brick a device, so a push needs an explicit confirm and re-hashes the image against the repository immediately before flashing; any tampering aborts it.
  • Honest by design — Skans flags the currency it can see; it never claims to patch a device the vendor has no update for.
Skans console · Firmware
The Skans firmware repository — vetted, hash-verified images per vendor and model, with stale devices flagged against the baseline.

Why it holds

Built for a network that can't phone Microsoft.

Signed, then installed

OS updates, Defender payloads and firmware images are all cryptographically verified — Authenticode to a Microsoft publisher, SHA-256 to the repository — before anything touches a host.

Offline by default

The appliance caches everything endpoints need. For a true air-gap, content imports from a signed bundle; the optional, operator-controlled Skans Update Service only pulls signed content down — it never sends your data out.

You approve — nothing auto-fires

Windows Update stays quiescent and a human approves each update into each ring. There is deliberately no CVE-to-exact-fix automation making changes behind your back.

Findings become fixes

A vulnerability finding hands off to the patch-approval flow carrying the fixed-in version — so the path from 'what's wrong' to 'approved and staged' is one lane, not two disconnected tools.

Compliance

The evidence an assessor asks for — already in place.

Patch and firmware currency isn't a certification; it's an enabler. Skans maps the work you're already doing to the control families an assessor asks about and hands the record over. It supplies the technical evidence — the attestation stays a human process, and the organizational, people and physical controls stay yours.

  • CM-3 — ring-based change control keeping a documented, enforced baseline.
  • SI-2 / RA-5 — the offline missing-KB scan evidences flaw remediation and reporting.
  • SI-7 — signature verification of every payload before it installs.
  • Tamper-evident record — approvals and results feed the audit trail you export for the assessor.
Skans console · Compliance
The Skans compliance view — a NIST posture ring and per-control-family status cards including CM and SI.

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.