Professional Services

IoT and OT security expertise — not only the Skans appliance.

Skans Labs professional services draw on deep, hands-on work across isolated camera estates, building automation, industrial control, and air-gapped networks — identity, segmentation, monitoring, firmware risk, and compliance evidence. We design and harden the island whether you adopt Skans, keep your existing stack, or mix both. The product is one tool in a broader practice; the engagement is about your enclave.

Skans console · NOC
The Skans NOC wall — fleet health, incidents, compliance and vulnerability posture for an isolated enclave

Breadth of practice

The whole island — cameras, BMS, plant floor, and the wire between them.

Our work sits where IT security playbooks stop: mixed-vintage IoT, controllers that cannot domain-join, networks that must stay offline, and operators who install cameras rather than run a SOC. That experience is broader than any single product.

Physical security & video estates

IP cameras, NVR/VMS, access control and intercoms on islanded LANs — onboarding reality, cert-capable vs limited gear, and security that ships with the integrator’s install.

Building automation & facilities

BMS, HVAC, lighting, elevators and metering (Siemens, Honeywell, JCI, Tridium and peers) — identity where the device supports it, segmentation and monitoring where it does not.

Industrial & process OT

PLCs, SCADA, OPC UA, historians and sensors — change windows, no surprise writes to live processes, NIST 800-82-style compensating controls for legacy.

Network architecture & containment

Enclave boundaries, jump hosts, 802.1X where viable, MAB/dynamic VLANs for limited devices, and honest designs for gear that will never hold a certificate.

Firmware, CVE & risk posture

How to assess software and firmware risk offline, prioritize what is actually exploited, and turn findings into operator-sized work — without a cloud scanner inside the island.

Operations, updates & evidence

Who installs what, how content reaches an air-gap, backup and break-glass, and technical evidence maps for NIST 800-171 / CMMC-style reviews — product-agnostic where it should be.

How we engage

From a one-day workshop to a multi-site program.

Scoped to the problem, not a forced software path. Typical shapes:

  • Discovery workshop (1–2 days) — inventory reality vs drawings, threat model for the island, prioritized backlog the site can actually execute — whatever stack you run today.
  • Architecture & design package — target enclave: identity lanes, network containment, monitoring, backup, and how updates or offline content enter the air-gap (Skans Update Service only if you choose Skans).
  • Hardening & evidence assist — walk-through against NIST 800-171 / CMMC-oriented technical controls, gap list, and an evidence map your assessor can follow.
  • Vendor & protocol navigation — help choosing and sequencing approaches across camera brands, BMS, PLCs and network gear — including when not to force a certificate or a rewrite of the plant.
  • Integrator enablement — train the field team so security posture ships with the camera or BMS job, not as a later specialist visit.
Skans console · Devices
Device inventory by capability tier — the kind of live picture a professional-services assessment builds toward

Independent of the box

Skans is optional. The enclave is not.

We built the Skans appliance because these problems needed a durable product — but professional services are not a thin sales wrapper around a license. Many clients need design, risk, and operator process first; some already have tools; some later adopt Skans. All three are valid outcomes.

  • Broad IoT/OT fluency — physical security, facilities, and plant-floor patterns, not a single vertical demo.
  • Stack-honest advice — we will not invent a requirement just to sell software, and we will not pretend a product certifies your whole ISMS.
  • Air-gap first — designs assume severed WAN, signed or controlled content import, and no dependency on a vendor cloud inside the island.
  • Same people as the engineering — you talk to practitioners who have lived the constraints of PLCs, cameras and BMS — not a partner farm reading a datasheet.
Skans console · Compliance
Compliance posture view — technical evidence planning is a common professional-services deliverable

Who engages us

Built for the people who own the island.

Security integrators & VMS partners

Add identity, admission and evidence to camera and access jobs — with a clear design even when the customer’s tools are not Skans.

Facilities & BMS owners

Harden building automation and shared OT networks where IT owns the WAN and the plant or building still needs to stay offline.

Compliance & security sponsors

A credible technical story for isolated CUI or sensitive enclaves — gaps, compensating controls, and evidence — without theater.

Plant / OT engineering

Contain legacy controllers and modern OPC UA gear with change windows, read-only monitoring, and no surprise writes to live processes.

Talk to us

Tell us about the island — not the product SKU.

Bring drawings, constraints, and the devices you actually have. We help with architecture, risk, and operator readiness across IoT and OT — Skans optional.