<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Industrial CyberSecurity for Networks Standard Server?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Server component</strong> – Central node that collects and analyses mirrored industrial traffic.<br /> <strong>Web interface</strong> – Dashboard, asset list, network map and event table.<br /> <strong>Intrusion detection</strong> – Rule sets plus ARP spoofing, scan and brute-force detection.<br /> <strong>Deep packet inspection</strong> – Monitors process tag values against user-defined thresholds.<br /> <strong>Vulnerability detection</strong> – Matches discovered devices against the CVE database.<br /> <strong>Important</strong> – No endpoint protection; KICS for Nodes covers workstations and servers.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Industrial CyberSecurity for Networks Standard Server?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Industrial CyberSecurity for Networks is the network component of the Kaspersky Industrial CyberSecurity (KICS) platform and analyses copied OT traffic taken from switch SPAN ports, so it sends no packets into the process network. It is operated from its own web console and reports into Kaspersky Security Center, where several servers across sites can be monitored together.<br /><br /> <strong>Zero production impact</strong> – Monitoring is passive; TAP or SPAN feeds copied traffic.<br /> <strong>Learning mode</strong> – Builds a baseline of normal communication before raising alarms.<br /> <strong>Command control</strong> – Detects PLC start, stop and project download commands.<br /> <strong>Traffic evidence</strong> – Stores packet captures for selected event types.<br /> <strong>Distributed sites</strong> – Sensors feed one server; monitoring points cover several segments.<br /> <strong>Role-based access</strong> – Operator accounts see events without changing configuration.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Industrial CyberSecurity for Networks Standard Server suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether you run a process network with managed switches that can mirror traffic, and whether someone reviews the events. A workshop with unmanaged switches and no OT engineer cannot feed the product; a utility, plant or building automation operator with a documented network design can.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By exception</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Managed switches with SPAN ports</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often missing</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Standard Server meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act (ISG) has applied since 1 April 2025, and operators of critical infrastructure must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. Affected are organisations such as energy and water utilities, transport companies, listed hospitals, data centre and cloud providers, and cantonal and municipal administrations; the Cybersecurity Ordinance sets sector thresholds that exempt many smaller organisations. The product supports that deadline in one concrete way: the event table records the detection time, the asset entries name the affected devices, and the stored packet capture for the event type gives you the technical evidence, which is what turns a 24-hour deadline from a scramble into a form-filling exercise. What it does not do is decide whether the obligation applies to you, submit the report, or see anything outside the network segments you have connected to a monitoring point, and it registers nothing that happens on an endpoint unless a Kaspersky endpoint agent is installed and integrated. This text is general information and not legal advice; whether the reporting obligation applies to your organisation should be clarified with qualified counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Standard Server meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes an organisation NIS 2 compliant, because the directive addresses management responsibility and processes, not software. NIS 2 requires essential and important entities to implement risk analysis and security policies, incident handling, business continuity and backup, supply chain security, security in acquisition and maintenance, procedures to assess effectiveness, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This product contributes to three of those categories in a directly demonstrable way: asset management, through the automatic OT device inventory; incident detection and handling, through intrusion detection and command control events; and effectiveness assessment, through scheduled reports and recorded network sessions. It contributes nothing to backup and business continuity, cryptography, multi-factor authentication, secure acquisition and maintenance, training, or supplier risk assessment, and it does not protect a single endpoint. The evidence it produces still has to be carried into your incident process by people.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In Switzerland, the Federal Office for Cybersecurity (BACS) has issued no warning and no sales restriction concerning Kaspersky. BACS has stated that it does not use the software itself, that there is no internal directive prohibiting it, that no misuse in Switzerland has been reported to it, and that each organisation must make its own risk assessment. In Germany, the Federal Office for Information Security (BSI) issued a warning against Kaspersky products in March 2022; it has since confirmed that the warning remains in force because it does not regard the risk situation as having changed, and Kaspersky is the only manufacturer on that list. In January 2026 Kaspersky formally demanded the withdrawal of that warning and reserved the right to legal steps. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 that prohibited new sales from 20 July 2024 and prohibited updates and operation of the Kaspersky Security Network for US persons from 29 September 2024; three Kaspersky entities were added to the Entity List. Kaspersky denies the allegations, points to its data processing in Zurich and its Global Transparency Initiative, and has offered independent review of its code and update mechanisms. Independent technical assessments of this specific product are unaffected: Kaspersky Industrial CyberSecurity for Networks holds an IEC 62443-4-1 certification for its secure development lifecycle, assessed by TÜV AUSTRIA. In practice this matters most if you sell into public sector contracts, if you are part of a group with US entities, if a German parent applies BSI guidance internally, or if your customers ask about vendor country of origin in supplier questionnaires; for a Swiss plant with no such ties, it is a documentation point rather than a blocker.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A side-by-side look at detection results, system load and what the test labs actually measured.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Standard Server help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and it is worth knowing exactly which half. It answers the OT visibility block: you can show a maintained inventory of industrial devices, a network map of who talks to whom, continuous monitoring of the process network, intrusion detection with documented rule sets, identification of known vulnerabilities against the CVE database, role-based access to the console, and forwarding of security events to a SIEM by syslog. It answers none of the following: malware protection on endpoints, patch management, encryption of data at rest, multi-factor authentication, backup and recovery, awareness training, and documented incident response procedures, which is usually the largest section of the questionnaire. It also does not answer the item that increasingly appears in questionnaires from large industrial customers, namely the country of origin of your security vendors. To close the technical gaps, the cheaper route is normally to stay inside the same family rather than mixing vendors, because the components are pre-integrated: KICS for Nodes for endpoint protection and compliance audit, and the separately licensed Active Polling and Device Security Audit modules for detailed device data and rule-based audit scans. The process gaps cannot be bought and have to be written down by your own team.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains the backup and recovery questions that appear in supplier questionnaires and why monitoring alone does not answer them.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between KICS for Networks and KICS for Nodes?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is where each one sits: KICS for Networks watches the wire, KICS for Nodes watches the machine. This licence covers the network side only, so it will show you that an engineering workstation sent a project download to a PLC, but it will not stop malware running on that workstation. Most plants end up running both, because the two are designed to feed each other: KICS for Nodes can act as an endpoint sensor and enrich network alerts with host, process and user data. If you have to choose one first, network monitoring is the usual starting point in environments where installing agents on legacy control machines is restricted by the automation vendor.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KICS for Networks</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KICS for Nodes</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Protects</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">OT network traffic</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Windows and Linux hosts</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Installed on</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Dedicated Linux server</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Operator and engineering machines</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Malware protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Network map and asset inventory</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Feeds data only</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">PLC command detection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Included in this licence</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">There is a hard regional restriction: since the US Department of Commerce determination, Kaspersky may not sell to US persons and may not deliver updates or operate the Kaspersky Security Network there, so a group with US sites cannot standardise on this product across all locations. On platform coverage, the Server and sensors run on Linux only and there is no Windows installation, while the endpoints themselves stay unprotected unless you add KICS for Nodes. Two capabilities that buyers often assume are included require separate licence keys: Active Polling, which queries devices directly for complete configuration data, and Device Security Audit, which runs rule-based audit scans. Response is the third common follow-up cost: isolating a compromised host requires Kaspersky Endpoint Agent on that host plus additional licensing, and blocking at network level requires vendor-specific connectors configured against your existing switches. Finally, the Server itself accepts only a limited number of monitoring points, so covering more network segments means adding sensors, which are a separate product in the same family.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Why built-in protection leaves gaps on the workstations and servers that network monitoring cannot cover.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Industrial CyberSecurity for Networks Standard Server</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it be updated without an internet connection in the OT network?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Databases and modules can be updated directly from Kaspersky servers, from update files copied in manually, or from a Kaspersky Security Center repository. For isolated plants the usual route is the Kaspersky Update Utility on an internet-connected machine outside the OT environment, with the files carried across to the repository.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What if our switches cannot mirror traffic?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Where SPAN or port mirroring is unavailable, a hardware network TAP connected to the cable can supply the copied traffic instead. Kaspersky also documents an SD-WAN variant for small remote sites where installing dedicated sensor hardware is not economical.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it work with older control systems?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The KICS platform is stated by Kaspersky to be tested against more than 200 industrial control systems and devices, and the network side reads traffic rather than installing anything on the controllers, so obsolete equipment is monitored without being touched. Support for legacy operating systems is a documented design goal of the platform.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-console,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>