<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Industrial CyberSecurity for Networks Standard Server Upd&amp;Sup Security Audit Enterprise Base?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Server licence</strong> – The licensed unit is the KICS for Networks Server node.<br /> <strong>Asset management</strong> – Automatic OT device discovery from analysed network traffic.<br /> <strong>Security audit</strong> – Active polling of devices against defined security standards.<br /> <strong>Intrusion detection</strong> – Rule-based detection of network attacks and traffic anomalies.<br /> <strong>Updates and support</strong> – Database and module updates plus vendor technical support.<br /> <strong>Important</strong> – Endpoint anti-malware and extra sensors are licensed separately.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Industrial CyberSecurity for Networks Standard Server Upd&amp;Sup Security Audit Enterprise Base?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Industrial CyberSecurity for Networks, listed by the vendor and by resellers under the short form KICS for Networks, analyses industrial network traffic to detect attacks, deviations in process parameters and changes to device state, and acts as the site-level central server of the Kaspersky Industrial CyberSecurity platform. It is operated through its own web interface, with optional central administration through Kaspersky Security Center using the KICS for Networks administration plug-in.<br /> <br /> <strong>No process impact</strong> – Reads mirrored traffic, never sits inline.<br /> <strong>Complete asset list</strong> – Builds an OT inventory from observed network packets.<br /> <strong>Audit without agents</strong> – Polls devices actively and checks them against standards.<br /> <strong>Controller command visibility</strong> – Logs read and write operations on programmable controllers.<br /> <strong>SIEM handover</strong> – Forwards registered events to SIEM systems for correlation.<br /> <strong>Evidence for auditors</strong> – Reports on device status, security and audit results.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Industrial CyberSecurity for Networks Standard Server Upd&amp;Sup Security Audit Enterprise Base suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is an OT product, so the deciding factor is not headcount but whether a separate production network exists with managed switches that can mirror traffic. A workshop with a flat office network cannot deploy it; a mid-sized water utility or plant builder usually can.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Separate OT network with mirror-capable switches</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partly</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Standard Server Upd&amp;Sup Security Audit Enterprise Base meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act (ISG) has applied since 1 April 2025 and covers operators of critical infrastructure such as energy and drinking water supply, transport companies, listed hospitals, data centre and cloud providers, and cantonal and communal administrations, while the Cybersecurity Ordinance exempts smaller organisations below the sector thresholds. Those affected must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery and have 14 days to complete the report. This product supports that duty on the content side: registered events are timestamped, the stored traffic can be exported as PCAP files for a chosen node, protocol and time range, and the asset table shows which controllers, HMIs and engineering stations were involved. What it does not do is decide whether an incident is reportable, submit the report, or see anything that never crosses a monitored network segment. It also delivers no host-level forensics on its own, because process and user data from an endpoint only arrive when KICS for Nodes is licensed separately and used as an endpoint sensor. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Standard Server Upd&amp;Sup Security Audit Enterprise Base meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product creates NIS 2 compliance, because the directive places its duties on the organisation and its management, not on a tool. NIS 2 requires measure categories including risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and maintenance including vulnerability handling, procedures to assess whether measures work, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. Against that list, this product contributes to asset management through automatic OT device discovery, to incident handling through detection and event forwarding, to vulnerability handling through the active security audit, and to the effectiveness assessment through its device and audit reports. It contributes nothing to cryptography, multi-factor authentication, staff training, business continuity planning or backup. Supply chain security is supported only indirectly, by making visible which external devices and remote connections exist inside the OT segment.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The German Federal Office for Information Security (BSI) published a warning against the use of Kaspersky antivirus software in March 2022. The warning is still in force in 2026 and now rests on § 13 BSIG after the amendment that entered into force on 6 December 2025. In 2024 the US Department of Commerce prohibited the sale of Kaspersky products and the supply of updates in the United States. In Switzerland the situation differs: the Federal Office for Cybersecurity (BACS) has issued no warning, has stated that no misuse has been reported to it and that there is no internal directive against the products, while noting that federal offices no longer use them. Kaspersky rejects the assessment, describes the BSI decision as political rather than technical, states that it has no ties to any government, points to the processing of European customer data in its Zurich data centre operating since 2020, and announced in early 2026 that it would take legal steps if the BSI warning were not withdrawn. In practice this matters most for public-sector tenders, for German critical infrastructure operators, and for suppliers whose customers apply country-of-origin rules to their supply chain; a Swiss plant operator without German public-sector business is in a different position from a supplier to a German utility. Note also that the BSI warning names antivirus software, whereas procurement questionnaires usually ask about the vendor rather than the individual product.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A direct comparison of both vendors covering detection performance, system load and the practical arguments for and against each.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Standard Server Upd&amp;Sup Security Audit Enterprise Base help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for the OT visibility and detection items, and not for the rest. It answers questions on asset inventory of the production network, on network monitoring and intrusion detection in OT, on logging and event forwarding to a SIEM, on user activity auditing inside the tool, and on regular technical security checks of devices, because the audit results and device reports can be exported as evidence. It does not answer questions on endpoint anti-malware, on patch deployment, on disk or removable media encryption, on multi-factor authentication, on backup and restore, or on mobile device management, since none of these functions exist in the product. It also does not answer organisational questions on policies, training records or supplier management. Where those gaps are blocking a contract, the cheaper route is usually to stay inside the same family and add KICS for Nodes for endpoint protection and endpoint telemetry rather than to introduce a second vendor into an OT network that then needs two sets of exclusions and two consoles.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains why detection alone does not restore production and how a backup strategy closes the recovery gap that monitoring tools leave open.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the Standard Server licences and the Additional Sensor licence?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is that only the Security Audit variant covers the active side of the product, meaning the polling of devices through connectors and the check of those devices against security standards; the plain Updates and Support variant stays with passive traffic analysis. The second difference is the licensed unit: Standard Server licences apply to a Server node, while the Additional Sensor licence applies to a sensor node that collects traffic at a further location and reports back to a Server. A sensor is therefore an extension of an existing installation and not a standalone product. All three are sold as Base, Renewal and Cross-grade variants, and this listing is the Base variant, which is the one to choose when no licence of the same product exists yet.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Standard Server, Upd&amp;Sup</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Standard Server, Upd&amp;Sup, Security Audit</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Additional Sensor</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Passive traffic analysis</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Asset management and intrusion detection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Via Server</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Active polling and device security audit</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Runs without another KICS licence</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint anti-malware</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The product detects and reports, it does not block: monitoring points must be connected to the industrial network in a way that excludes any possibility of influencing it, so nothing here stops a malicious controller write in progress. Deployment depends on infrastructure you may not have, because traffic has to reach the Server or a sensor through port mirroring, and the vendor documents this for Cisco, Hirschmann, Siemens SCALANCE and Siemens RUGGEDCOM switches; unmanaged switches leave blind segments. Coverage is limited to what crosses a monitored segment, which means serial links, USB transfers and engineering laptops connected directly to a controller stay invisible. The two most common follow-up purchases are additional sensors for further plant locations and KICS for Nodes for endpoint protection and endpoint telemetry, and both are separate licences. Note finally that this is a Base licence, so it is the wrong choice if a licence for the same product already exists and a Renewal or Cross-grade applies.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Sets out where built-in protection stops and which additional security layers an environment needs beyond it.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Industrial CyberSecurity for Networks Standard Server Upd&amp;Sup Security Audit Enterprise Base</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which industrial protocols does it analyse?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The vendor documents handling of IEC 60870-5-101 and IEC 60870-5-104, including supported ASDU types, and of IEC 61850 with loading and management of device and tag configurations. In addition the application can identify individual application-layer protocols from the contents of network packets for network control and event registration.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the events be sent to an existing SIEM?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Registered event types can be configured for transmission to recipient systems such as a SIEM and to Kaspersky Security Center, and the vendor documents the verification of event forwarding using an ArcSight system as a worked example. An API is also available to retrieve event and tag data from external applications.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is Kaspersky Security Center required to run it?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. The application has its own web interface for assets, events, process parameters and configuration. Kaspersky Security Center with the KICS for Networks administration plug-in is the option for organisations that want several Servers and locations administered centrally.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-server,compliance-ch-isg,compliance-nis2" data-audience="b2b" data-count="3"> </div>