← Back to Protect Critical Machines and DevicesOption 2 · Faction Outpost

A Faction Outpost, ready to adopt

Easily secure access to all your OT, IoT and ICS machines and devices with flexible hardware options. Minimal IT staff required, and no rip-and-replace of existing hardware or network infrastructure.

What it is

Faction Network security, on curated 3rd party hardware we prepare and ship. A Faction Outpost is a qualified OEM alternative to a Pod or Portal: a screened third-party router that Faction curates, configures, tests and ships, sitting at your local network boundary. It takes the machines and devices behind it off the Internet and onto your Faction Network.

Once prepared, the Outpost can only connect to your Faction Network, and any machine or device behind it is unreachable from the public Internet. You keep local admin access to the router.

Why it's different

Faction Outposts sit behind your existing modem, router or other upstream gateway, which are never trusted. Every connection is authorized by keys you control, and the Outpost's only route for that equipment is the encrypted tunnel to your Faction Network.

That mitigates the threats from vulnerable or compromised foreign-made routers and smart hardware already inside your networks. No additional firewall to deploy or configure, no software agents on endpoint devices, no rip-and-replace of existing hardware or network infrastructure.

What you get

Owner-controlled keys

Your keys are created by you at adoption, generated on the device, and distributed only to authorized members. Faction prepares the unit for you to adopt locally, and never has access to your keys.

Full local control

You keep full local administration of the router. Faction manages only what it set, and the Faction app is designed to tell you if the device has been changed outside it.

Simplicity

Manage Faction Outposts and all the machines and devices connected to them in your Faction app. Use Faction Groups to segment access and permissions with ease.

Turn-key

It arrives as a Faction Outpost, configured and tested. Plug it in and adopt it on your local network: nothing to install or configure, and we support it. Where hardware assurance matters most, choose Faction Pods & Portals.

How it works
01

Plug it in

Behind your existing modem or router, by Ethernet or Wi-Fi.

02

Open the Faction application

A desktop application or command-line tool, on the same local network.

03

Adopt it

It joins your Faction Network on your local network, and your own keys are generated on the device.

04

Connect your equipment

Behind it. Nothing is installed on the equipment.

You still need a router doing the routing

A Faction Outpost has no direct internet access, so it sits behind your existing modem or router rather than replacing it. Nothing about your current internet connection changes, and nothing you connect behind it needs a change to its hardware or software.

What your Faction Network guarantees
  • Owner-controlled keys. Keys and certificates are controlled and issued by the Network Owner, and distributed only to authorized members. Faction never has access to them.
  • Off the public Internet. Equipment behind the Faction Outpost has no path to the Internet, and is reachable only from inside your Faction Network.
  • Out-of-band authentication. A direct key exchange that isn't exposed to external observation or attack.
  • Nothing on the equipment. No agent, no software and no changes to the machines you protect.
  • Zero knowledge of content. Faction never has access to your keys, so it can never read your data. It sees only the routing metadata of encrypted traffic crossing your Faction Network.
  • Zero anonymity of action. Every action on your network is tied to a verified device or user, and that record is under your control.
  • Contained by design. A compromised machine or device behind it can't reach the Internet or call home, and Faction Groups limit what it can reach.
Same Faction Network Security · Different Hardware Provenance and Assurance

Pre-screened

  • OEMs and models are selected based on testing and consultation with our Cyber Assurance partners to ensure that our implementation is secure.

FCC-certified

  • FCC-authorized for sale in the US, and not on the FCC Covered List. The model's own firmware is not changed.

Tested and supported

Each model is tested against the four criteria below at a stated firmware version before it ships.

  • A secure tunnel for the encrypted Faction connection.
  • Local access only, with vendor cloud access restricted or off.
  • A firewall that denies by default.
  • NAT for the network behind it.
Why you need to act now

Nation-state threats

Nation-state and ransomware actors increasingly target OT, IoT, ICS and the hardware supply chain — not just data for users and applications.

Rob Joyce — China's cyber explosives are in place

FCC Router Mandate

The FCC's Covered List stops new foreign-produced routers from being authorized, but does nothing about the ones already deployed. Faction contains the risk from those already inside your networks, with no rip-and-replace.

FCC Covered List — foreign-made routersEvery FCC Covered List action in 2026

AI and technical debt

AI is amplifying attacker capability exponentially, against equipment that already carries decades of unpatched technical debt.

AI meets decades of technical debt
Other options for OT, IoT & ICS protection

Faction Pods & Portals

Faction purpose built. Faction hardware running Faction firmware: Purpose Built, Assembled in USA, ORION Assured.

See Faction Pods & Portals

Faction Canopy

Customer owned. Keep your hardware. Faction enablement and configuration for compatible hardware you already own.

See Faction Canopy

Get your OT, IOT and ICS off the Internet

Order a Pod, Portal or Outpost ready to adopt or bring hardware you already own under Faction protection with Canopy. Same Faction Network, same owner-controlled keys.