Building automation & facilities

Bring the whole building under one root of trust — without ripping out the install.

HVAC, lighting, elevators, metering and the BMS head-ends from Siemens Desigo, Honeywell, Johnson Controls Metasys and Tridium Niagara run on islanded networks a trades integrator stood up — no directory, no security team, no internet. Skans becomes that enclave's root of trust: an identity for every controller that can hold one, segmentation and read-only monitoring for the gear that can't, and the compliance evidence to prove it. One appliance, set up by the technician who commissions the building.

Skans console · NOC
The Skans NOC wall for a facility — metric tiles for fleet health, open incidents, compliance percent, certificate status, devices by capability tier, vulnerabilities and 24-hour events.

Identity for every controller

Give every building system an identity your CA owns.

Skans stands up an on-premises certificate authority the enclave owns, then issues an X.509 identity to every controller, head-end and field panel that can hold one. Per-vendor drivers push and bind the certificate onto gear that can't domain-join or enroll itself — Siemens Desigo, Honeywell, Johnson Controls Metasys, Tridium Niagara, Distech Controls, Belimo and the S7 controllers behind them. OPC UA servers get spec-correct application-instance certificates instead of the permanent, hand-made self-signed ones they usually ship with.

  • Your own root of trust — an on-prem CA issues and rotates every identity; nothing about your building lives on a vendor cloud.
  • Driver-pushed certificates — the BAS driver pack installs and binds TLS on controllers that can't enroll themselves, so a self-signed default becomes a trusted, CA-issued identity.
  • OPC UA done right — application-instance certs carry the ApplicationUri in the URI-SAN with the correct key usage, which is the single most common reason an OPC UA server rejects a certificate.
  • Proven on cameras & IoT, extensible to any vendor — the camera and IoT drivers are hardware-validated; the BAS drivers are authored to each vendor's management API and spec-verified — pilot one controller first.
Skans console · Devices
The Skans device inventory listing BMS controllers, cameras and switches with certificate status, capability tier and management lane.

Meet the plant where it is

Not every controller can hold a certificate. We plan for that.

Mixed-vintage estates are the norm in a building — a new Desigo head-end beside a decade-old BACnet MS/TP trunk and a raw-Modbus meter. Skans sorts every device into a capability tier and applies the strongest control it can support: full identity where possible, a driver-pushed cert and a dynamic VLAN where the device is limited, and segmentation with a security gateway where it's legacy. That's NIST 800-82 compensating controls, not a rip-and-replace.

  • Tier A — cert-capable — modern controllers, servers and OPC UA gear get full identity, 802.1X admission, encryption and config backup.
  • Tier B — limited — a driver-pushed certificate plus a dynamic VLAN and monitoring for gear that can't speak 802.1X.
  • Tier C — legacy — BACnet MS/TP, serial-over-Ethernet and raw Modbus get segmentation, an allow-list and a security gateway.
  • Read-only by construction — native EtherNet/IP and Modbus/TCP identity probes read vendor, firmware and run/fault state where the protocol exposes it, and never write a coil or register; per-target maintenance windows and rate-limiting keep the touch safe on a production controller.
Skans console · Alerting
The Skans alerting view — correlated findings and alert rules by type and severity, with cooldowns and routing.

Why facilities teams pick Skans

Built for the way buildings actually run.

Islanded by design, commissioned by trades, audited like IT. Skans fits that reality instead of fighting it.

One root of trust

Your CA, your identities, your keys — issued and rotated on-box for every building system, never parked on a vendor cloud.

OT-safe touch

Legacy controllers are segmented, allow-listed and read only. Identity probes ask 'who are you, are you running?' — they never write to the device.

Air-gapped by default

Disconnected out of the box. Threat feeds, firmware and patches sync offline; a severed WAN changes nothing about your protection.

Run by the commissioning tech

The Setup Wizard is a few plain questions and one button. The operator sees outcomes — 'controllers encrypted · 2 certs expiring' — never PKI internals.

Patch, firmware & backup

Keep an offline building current — and recoverable.

Air-gapped estates fall behind because there's no clean way to get signed content in. Skans keeps a vetted, hash-verified firmware repository for controllers and IoT gear, and staged patch rings for the Windows head-ends and workstations that run the BMS — no internet, no WSUS. Configs, secrets and firmware are versioned and held off the source machine, so a bricked panel or a bad commissioning change is recoverable.

  • Firmware repository — vetted and SHA-256-hash-verified before it ever reaches a controller; air-gapped sites stay current.
  • Patch rings without WSUS — the BMS servers and workstations patch on staged, approved rings via the Authenticode-signed endpoint agent (deployed by GPO or signed install).
  • Config & secret vault — controller, PLC and network configs versioned and change-detected, encrypted off the source box.
  • One optional egress — the operator-controlled Skans Update Service only pulls signed content down; it never sends your building's data out.
Skans console · Updates
The Skans updates and patch-rings view — signature-gated updates, per-ring approval, a fleet patch-compliance chart and a firmware repository.

Evidence, not badges

The evidence a facilities audit actually asks for.

Skans maps its technical controls to NIST 800-171 and CMMC control families from the start, with an ISO 27001 crosswalk and read-only OT guidance from NIST 800-82 for the gear that can't be hardened directly. It hands the assessor a signed, per-control evidence pack — not a compliance badge, and never a claim that a product made you compliant.

  • Mapped by control family — Access Control, Configuration Management, Risk Assessment and System & Information Integrity, evidenced from live measurement.
  • OT compensating controls — legacy segmentation and read-only monitoring documented against NIST 800-82 for gear that can't hold a cert.
  • Signed evidence pack — per-control, with a three-way responsibility matrix and a cryptographically tamper-evident manifest.
  • Honest by design — Skans supplies the technical evidence; organizational, people and physical controls stay yours, with gaps tracked in a POA&M. Your ISMS gets certified, never a product.
Skans console · Compliance
The Skans compliance view — a NIST 800-171 posture ring and per-control-family status cards for AC, AU, CM, CP, IA, RA and SC.

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.