Industrial & OT

Give the plant floor an identity — without ever writing to a live controller.

PLCs, SCADA, OPC UA servers and sensors run on islanded plant and utility floors — no directory, no cloud, and zero tolerance for anything that writes to a running controller. Skans gives the gear that can hold one a real X.509 identity, and contains the gear that can't behind segmentation, an allow-list and read-only monitoring. Modern kit gets full identity; legacy gets NIST 800-82 compensating controls — all from one air-gapped appliance, nothing leaving the wire.

Skans console · Devices
The Skans device inventory — PLCs, controllers, switches and cameras sorted by capability tier, each with its certificate status and monitoring lane

We meet your gear where it is

Not every controller can hold a certificate. We plan for that.

Mixed-vintage estates are the norm on a plant floor. Skans discovers every device, sorts it into a capability tier, and applies the strongest control that device can actually support — full identity where the gear allows it, a driver-pushed certificate where it's limited, and containment where it's legacy.

Find it first

Multi-protocol discovery — ONVIF, network scan and native industrial probes — enumerates every PLC, drive, RTU, switch and sensor and auto-classifies it by device class and capability tier.

Tier A — cert-capable

Modern controllers, servers, network gear and OPC UA servers get full X.509 identity, 802.1X admission, encryption and patching.

Tier B — limited

Gear that can be identified but not enrolled gets a driver-pushed certificate, config backup, read-only monitoring and a RADIUS-assigned dynamic VLAN via MAB.

Tier C — legacy

Old PLCs, serial-over-Ethernet, BACnet MS/TP and raw Modbus can't hold a cert — so they get segmentation, a security gateway, an allow-list and read-only monitoring: NIST 800-82 compensating controls, never fake admission.

Full identity

Give modern controllers a real identity — and lock down their credentials.

Skans stands up one certificate authority the enclave owns and issues an X.509 identity to every device that can carry it — signed by your Skans Root, never a vendor cloud. Industrial gear gets identity over its own protocol: spec-correct OPC UA application-instance certificates from your own PKI, plus native cert lanes for the leading PLC and controller families — all from one console. And the admin passwords Skans rotates are sealed in a TPM-protected vault.

  • OPC UA application certificates — spec-correct application-instance certificates issued to Part 6 (the URI-SAN, key-usage and serverAuth+clientAuth profile OPC UA servers demand), from your own CA instead of permanent self-signed certs — built for enclave-wide distribution over OPC UA’s GDS Push model (Part 12 UpdateCertificate + ApplyChanges), trust list included.
  • Native cert lanes — Siemens S7 and S7-1200, Rockwell Stratix, Phoenix PLCnext, Beckhoff TwinCAT and WAGO, each issued and bound from one console.
  • Verified, never assumed — where a lane is proven, the driver reads the new certificate serial back off the device before it reports success, not “should work.”
  • LAPS for controllers — rotate the admin password on the gear that supports it (S7, S7-1200, WAGO, Stratix, PLCnext), audited on every reveal and copy.
Skans console · Passwords
The Skans credential vault — device logins and secrets encrypted and hardware-protected, with reveal and copy audited

The safest possible touch

See a PLC is alive and healthy — without ever writing to it.

The most important devices on a plant floor speak no SNMP and can never hold a certificate. Skans reaches them in the only language they speak — their native industrial protocol, sent strictly read-only. It asks “who are you, and are you running?” and reads the answer; it never writes a coil, a register or a config. Identity and run/fault state flow into the same correlated, per-device worklist as every other signal — bounded by device count, not raw event volume.

  • EtherNet/IP (CIP List Identity) — reads vendor, product, firmware, serial and run/fault state over udp/44818; it never touches the control program.
  • Modbus/TCP (Read Device Identification) — confirms reachability and vendor/product over tcp/502, and never writes a coil or a register.
  • OT-safe by construction — per-target maintenance windows, poll rate-limiting and a source-IP allow-list, so a controller is never flooded or probed mid-process.
  • Firmware for CVE-matching — the version Skans reads is matched offline against CVE and MITRE ATT&CK feeds, no internet required.
Skans console · NOC
The Skans NOC wall — fleet health, devices by tier, open vulnerabilities and RADIUS/NPS serving status across the enclave

Current, offline

Keep an air-gapped plant floor current — no internet on the wire.

Air-gapped estates fall behind because patching assumes a connection to the vendor. Skans holds a vetted, hash-verified firmware repository on the appliance and stages Windows updates in approval rings without WSUS — so the engineering workstations and jump hosts beside the line stay current while the OT segment never touches Microsoft Update or a vendor cloud. The one optional egress, the operator-controlled Skans Update Service, only pulls signed content down; it never sends your data out.

  • Firmware repository — camera, IoT and OT firmware, hash-verified before it lands and staged from the box rather than the internet.
  • Patch rings without WSUS — Microsoft-signature-gated updates promoted ring by ring, inside your maintenance window, reported per host.
  • Off-source backup + DR — encrypted backups of your switch, firewall and gateway configuration, databases and secrets, held off the source machine.
  • Air-gap-first — disconnected by default; a severed WAN changes nothing about your protection.
Skans console · Updates
The Skans updates view — signature-gated patch rings, a fleet patch-compliance chart and a hash-verified firmware repository

Contained and evidenced

Contain the gear that can't be hardened — and prove it to an assessor.

When a controller genuinely can't take a certificate, Skans never fakes it: the driver returns a clear error, and the platform secures the conduit instead — segment the device, put a security gateway in front of it, allow-list only the flows it needs, and monitor it read-only. Those are NIST 800-82 compensating controls, not pretend admission. Skans then maps what it measures to NIST 800-171 / CMMC control families and crosswalks to ISO 27001, so the technical evidence is already in place when the assessor arrives.

  • Secure the conduit — 802.1X on the switch, a security gateway and an allow-list stand in for the identity a legacy device can't hold.
  • NIST 800-82 aligned — the legacy-OT posture Skans applies is the compensating-control model the standard expects.
  • Evidence, not badges — live 800-171 / CMMC posture by control family, an ISO 27001 crosswalk and a signed evidence pack you hand straight over.
  • Responsibility, honestly drawn — Skans supplies the technical controls; organizational, people and physical controls stay yours via a control-responsibility matrix, with gaps tracked in a POA&M. It's your ISMS that gets certified, never a product.
Skans console · Compliance
The Skans compliance view — a NIST posture ring and per-control-family status cards for AC, AU, CM, IA, RA and SC

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.