LUCIDTextjet - Print logo

Kaspersky Industrial CyberSecurity EDR Integration Agent Enterprise Base

Short Description

Open HTML

What are the key advantages of Kaspersky Industrial CyberSecurity EDR Integration Agent Enterprise Base?
Centrally managed – Policies and settings from Kaspersky Security Center.
Endpoint telemetry – Process, network and file activity from OT nodes.
Traffic control – Exclusions limit telemetry volume on constrained industrial links.
Flexible configuration – Console, web console or command line setup.
OT focus – Built for SCADA and operator workstation environments.
Important note – Telemetry only, no response actions or protection engine.

Long Description

Open HTML

What is included in Kaspersky Industrial CyberSecurity EDR Integration Agent Enterprise Base?

EDR endpoint sensor – Collects process, network and file events on industrial Windows nodes.
KICS for Networks link – Forwards node telemetry to the KICS for Networks server.
Telemetry exclusions – Filter process, network and file events before they are sent.
Central policy management – Configured through Kaspersky Security Center Administration Console or Web Console.
Command line control – Integration settings can be set locally on each node.
Important – No protection engine; response actions are not part of this integration.

What are the main benefits of Kaspersky Industrial CyberSecurity EDR Integration Agent Enterprise Base?

This is the endpoint sensor licence of the Kaspersky Industrial CyberSecurity platform, installed on industrial Windows nodes that already run KICS for Nodes and managed centrally from Kaspersky Security Center. The function is delivered by the application Kaspersky Endpoint Agent, the name under which many OT teams still know it.

Faster root cause – Shows how an alert reached a SCADA workstation.
Network and host merged – Enriches KICS for Networks alerts with host process data.
Bandwidth discipline – Exclusions keep telemetry off saturated plant network links.
Evidence for reporting – Timestamped event records support incident write-ups after a breach.
One console – OT sensor policies sit beside existing Kaspersky endpoint policies.
Local configuration option – Settings can be applied on isolated nodes without console access.

Best antivirus? Why Windows Defender alone is not enough
Explains why the protection built into Windows leaves detection gaps that a dedicated sensor and detection platform are meant to close.

Which company size is Kaspersky Industrial CyberSecurity EDR Integration Agent Enterprise Base suitable for?

This licence only makes sense where a Kaspersky Industrial CyberSecurity platform is already running, because the agent sends telemetry to a KICS for Networks server rather than analysing it. That normally rules out small businesses without an OT security team and points at plants and utilities with an existing OT monitoring setup.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland By sector By sector Often yes
NIS 2 in the European Union Mostly exempt By sector By sector
Security questionnaire from large customers Increasing ✓ ✓
KICS platform already in operation ✕ Partial ✓
This product fits ✕ Partial ✓

Does Kaspersky Industrial CyberSecurity EDR Integration Agent Enterprise Base meet the requirements of Swiss cybersecurity legislation?

The Swiss reporting obligation applies to operators of critical infrastructure, not to every company: energy and drinking water supply, transport, listed hospitals, telecommunications, data centre and cloud providers, and cantonal and communal administrations fall under the revised Information Security Act (ISG), in force since 1 April 2025. Affected organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. The agent supports that deadline in one specific way: it records process starts, network connections and file changes on SCADA machines and operator workstations, so an initial report can state when the activity began and which nodes were touched rather than that the scope is unknown. What it does not do is judge whether an incident is reportable, write the report, or notify BACS, and it produces nothing usable on its own, because the telemetry has to be analysed on a KICS for Networks or Kaspersky detection back end. Organisational duties such as an on-call rota, a defined escalation path and a named contact for BACS stay entirely with you. This text is a product description and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.

Does Kaspersky Industrial CyberSecurity EDR Integration Agent Enterprise Base meet the requirements of European cybersecurity legislation?

No software product makes a company compliant with the NIS 2 Directive, because the directive requires management measures and processes and a product can only be evidence that some of them work. NIS 2 requires entities in scope to put in place risk analysis and information security policies, incident handling, business continuity and crisis management, supply chain security, security in the acquisition, development and maintenance of systems including vulnerability handling, procedures to assess whether the measures are effective, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication or secured communications, alongside a staged incident notification duty. The agent contributes to two of those categories: incident handling, by supplying the endpoint detection data an analyst needs to reconstruct an attack path, and asset-level visibility for industrial Windows nodes. It contributes nothing to business continuity, supply chain security, cryptography, access control, multi-factor authentication or staff training, and it does not assess the effectiveness of any measure. Because it forwards telemetry rather than acting on it, even the incident handling contribution depends entirely on the detection platform running behind it.

What should you know about official assessments of Kaspersky?

The United States Department of Commerce, Bureau of Industry and Security, announced a Final Determination on 20 June 2024 prohibiting Kaspersky from supplying anti-virus software and related cybersecurity services in the United States or to US persons. From 29 September 2024 the prohibition also covers signature and codebase updates, operation of the Kaspersky Security Network in the United States, and reselling, licensing for resale or integrating Kaspersky software into other products. It remains in force. In Germany, the Federal Office for Information Security (BSI) has recommended replacing Kaspersky products since 2022 and confirmed that the recommendation still stood after the US measures; it is a warning, not a sales ban. Kaspersky rejects the allegations, has proposed independent verification of its code, database updates and detection rules, and continues to run its Global Transparency Initiative. Independent laboratory testing has continued to include Kaspersky products, and the regulatory measures do not change those published results. In practice this affects buyers with US ownership or US customers, public sector contracts, and supply chains with clauses excluding vendors named by a government authority; in Switzerland and the European Union the product is sold and updated normally. Check the point against your own procurement rules before ordering.

Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?
A side-by-side look at how the two vendors perform in independent detection testing.

Does Kaspersky Industrial CyberSecurity EDR Integration Agent Enterprise Base help with security questionnaires from large customers?

Yes, but only for a narrow set of items. It answers whether endpoint detection covers your OT assets, whether process, network and file telemetry is collected from industrial workstations, whether that telemetry reaches a central detection platform, and whether the sensor is policy-managed from a console rather than configured machine by machine. It does not answer questions on malware protection at the node, patch management, disk encryption, multi-factor authentication, log retention periods, backup and restore testing, or monitoring coverage outside office hours, and it does not answer whether you can respond to a detected threat, because response actions are not part of this integration. The cheapest way to close those gaps is usually to stay inside the same platform: KICS for Nodes covers node protection, application and device control and integrity monitoring, KICS for Networks covers detection and analysis, and Kaspersky Managed Detection and Response covers the monitoring hours a plant team cannot staff itself. Adding a second vendor into an OT network normally means a second agent on machines where change windows are scarce, which is the more expensive answer.

What is the difference between the Base licence and the Renewal licence?

The decisive difference is what you must already own: Renewal requires an existing licence for the same product, Base does not. Both deliver identical agent functionality, so the choice is a purchasing question rather than a feature question. If your plant has never run the EDR Integration Agent before, Base is the correct variant; ordering Renewal without a prior licence of the same product leaves you unable to use it.

CriterionBaseRenewal
Intended for First licence Existing licence
Requires prior licence of same product ✕ ✓
Agent functionality Identical Identical

Which limitations should you know before buying?

The agent has no protection engine of its own: it observes and forwards, and blocking malware on an industrial node remains the job of KICS for Nodes. Kaspersky documents that within the integration with KICS for Networks the agent transmits telemetry only, and that response actions, network isolation and IOC scanning are not available on that path, which is the most common surprise for buyers who expect full EDR response from the product name. Scope is Microsoft Windows industrial nodes, while Linux industrial nodes are handled by the separate Kaspersky Industrial CyberSecurity for Linux Nodes line, and the ICS features OT teams often ask about, such as PLC project integrity checks, the portable USB scanner and file integrity monitoring, belong to KICS for Nodes rather than to this licence. Kaspersky has also been consolidating this function into the endpoint products themselves, with KICS for Nodes 4.5 introducing a built-in agent for the EDR Optimum solution and a unified MDR agent, so confirm with your Kaspersky partner which agent your installed version expects before ordering. On regional availability, the product is sold and updated normally in Switzerland and the European Union, while the United States prohibition described above blocks sale, resale and integration there.

Test: Best antivirus programs for Windows 2025
Useful if you still need the protection layer this sensor deliberately leaves out.

Frequently asked questions about Kaspersky Industrial CyberSecurity EDR Integration Agent Enterprise Base

Can the telemetry be sent to a SIEM system?

Yes. Alongside the connection to the KICS for Networks server, the agent supports integration with a SIEM system, configured from the same policy in Kaspersky Security Center.

Does the agent work with Kaspersky Managed Detection and Response?

Yes. The agent can send its telemetry to a server running Kaspersky Managed Detection and Response or a Kaspersky Anti Targeted Attack Platform Central Node instead of, or in addition to, KICS for Networks. The managed service itself is a separate purchase.

Which servers do I need on the back end?

Two roles. Kaspersky Security Center handles policies, deployment and settings for the agent, while a KICS for Networks server, a KATA Central Node or a Kaspersky Managed Detection and Response server receives and analyses the telemetry the agent produces.

 

Meta Description

EDR telemetry sensor for Kaspersky Industrial CyberSecurity. Sends data from Windows OT nodes to KICS for Networks. Needs an existing KICS setup.

Keywords

Kaspersky Industrial CyberSecurity EDR Integration Agent, Kaspersky, KICS, Kaspersky Endpoint Agent, OT security, EDR sensor, industrial control systems, endpoint telemetry, SCADA monitoring

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree