Find it first
Multi-protocol discovery — ONVIF, network scan and native industrial probes — enumerates every PLC, drive, RTU, switch and sensor and auto-classifies it by device class and capability tier.
Industrial & OT
PLCs, SCADA, OPC UA servers and sensors run on islanded plant and utility floors — no directory, no cloud, and zero tolerance for anything that writes to a running controller. Skans gives the gear that can hold one a real X.509 identity, and contains the gear that can't behind segmentation, an allow-list and read-only monitoring. Modern kit gets full identity; legacy gets NIST 800-82 compensating controls — all from one air-gapped appliance, nothing leaving the wire.

We meet your gear where it is
Mixed-vintage estates are the norm on a plant floor. Skans discovers every device, sorts it into a capability tier, and applies the strongest control that device can actually support — full identity where the gear allows it, a driver-pushed certificate where it's limited, and containment where it's legacy.
Multi-protocol discovery — ONVIF, network scan and native industrial probes — enumerates every PLC, drive, RTU, switch and sensor and auto-classifies it by device class and capability tier.
Modern controllers, servers, network gear and OPC UA servers get full X.509 identity, 802.1X admission, encryption and patching.
Gear that can be identified but not enrolled gets a driver-pushed certificate, config backup, read-only monitoring and a RADIUS-assigned dynamic VLAN via MAB.
Old PLCs, serial-over-Ethernet, BACnet MS/TP and raw Modbus can't hold a cert — so they get segmentation, a security gateway, an allow-list and read-only monitoring: NIST 800-82 compensating controls, never fake admission.
Full identity
Skans stands up one certificate authority the enclave owns and issues an X.509 identity to every device that can carry it — signed by your Skans Root, never a vendor cloud. Industrial gear gets identity over its own protocol: spec-correct OPC UA application-instance certificates from your own PKI, plus native cert lanes for the leading PLC and controller families — all from one console. And the admin passwords Skans rotates are sealed in a TPM-protected vault.

The safest possible touch
The most important devices on a plant floor speak no SNMP and can never hold a certificate. Skans reaches them in the only language they speak — their native industrial protocol, sent strictly read-only. It asks “who are you, and are you running?” and reads the answer; it never writes a coil, a register or a config. Identity and run/fault state flow into the same correlated, per-device worklist as every other signal — bounded by device count, not raw event volume.

Current, offline
Air-gapped estates fall behind because patching assumes a connection to the vendor. Skans holds a vetted, hash-verified firmware repository on the appliance and stages Windows updates in approval rings without WSUS — so the engineering workstations and jump hosts beside the line stay current while the OT segment never touches Microsoft Update or a vendor cloud. The one optional egress, the operator-controlled Skans Update Service, only pulls signed content down; it never sends your data out.

Contained and evidenced
When a controller genuinely can't take a certificate, Skans never fakes it: the driver returns a clear error, and the platform secures the conduit instead — segment the device, put a security gateway in front of it, allow-list only the flows it needs, and monitor it read-only. Those are NIST 800-82 compensating controls, not pretend admission. Skans then maps what it measures to NIST 800-171 / CMMC control families and crosswalks to ISO 27001, so the technical evidence is already in place when the assessor arrives.

Talk to us
Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.