<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Anti Targeted Attack Platform Enterprise?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Network traffic analysis</strong> – Monitors mirrored SPAN traffic for signs of intrusion using IDS rules.<br /> <strong>Advanced sandbox</strong> – Detonates suspicious objects in isolated virtual machines and returns verdicts.<br /> <strong>Central Node console</strong> – On-premises web interface for alerts, tasks and configuration.<br /> <strong>Threat intelligence</strong> – Alerts enriched with KSN reputation data and MITRE ATT&amp;CK mapping.<br /> <strong>SIEM export</strong> – Alerts published over Syslog, plus a REST API integration.<br /> <strong>Important</strong> – Endpoint protection agents and EDR are not part of KATA.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Anti Targeted Attack Platform Enterprise?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Anti Targeted Attack Platform Enterprise is an on-premises anti-APT solution that combines network detection and response with an integrated sandbox, operated from its own Central Node web console rather than a vendor-hosted cloud portal. Kaspersky now markets the product as Kaspersky Anti Targeted Attack (KATA), so older documentation and retail listings still carry the longer Platform name.<br /><br /> <strong>Encrypted traffic triage</strong> – TLS fingerprinting flags suspicious sessions without breaking encryption.<br /> <strong>Gateway level blocking</strong> – ICAP integration stops flagged objects at the web proxy.<br /> <strong>Alert evidence capture</strong> – A PCAP is stored with each intrusion detection alert.<br /> <strong>SOC tool integration</strong> – Syslog and REST API feed your existing SIEM workflows.<br /> <strong>Private reputation lookups</strong> – KPSN keeps file and URL reputation checks on premises.<br /> <strong>Multi-tenant operation</strong> – Service providers separate customer data across distributed Central Nodes.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains which attack techniques built-in endpoint protection does not reliably surface, and where an additional detection layer earns its keep.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Anti Targeted Attack Platform Enterprise suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">KATA is designed to be operated, not just installed: alerts have to be triaged, sandbox verdicts read, and network sessions investigated. Organisations without at least a part-time security analyst usually get more value from a managed service than from a self-run NDR platform.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Staff available to triage network alerts</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Anti Targeted Attack Platform Enterprise meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Swiss reporting obligation does not apply to companies in general, but to the operators of critical infrastructure named in the revised Information Security Act (ISG): energy and water suppliers, transport companies, listed hospitals, cloud and data centre providers, and cantonal and municipal administrations. Since 1 April 2025 these organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. KATA supports that deadline in one concrete way: every intrusion detection alert is timestamped and stored with its associated PCAP, and alerts can be pushed to a SIEM over Syslog, so the first report can be assembled from one evidence source instead of reconstructed from switch logs. What it does not do is decide anything for you – it does not file the report, does not judge whether an incident crosses the ISG threshold, and covers none of the organisational duties such as naming a responsible contact or documenting the escalation path. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Anti Targeted Attack Platform Enterprise meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product creates NIS 2 compliance, because the directive addresses management responsibility and process, not tooling. NIS 2 requires risk management measures across several categories: incident handling, business continuity and backup, supply chain security, vulnerability handling, cryptography, access control and multi-factor authentication, cyber hygiene and training, and policies to assess whether the measures actually work. KATA maps to one of these categories in depth – incident handling – through network monitoring, sandbox analysis, alert prioritisation and both automated and manual response actions, and its reporting output can serve as evidence when effectiveness is assessed. It contributes nothing to backup and continuity, vulnerability and patch management, encryption, identity and access control, multi-factor authentication, or staff training, all of which need separate products and processes. Whether an entity is in scope at all depends on the sector and size thresholds set by the directive itself.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In March 2022 the German Federal Office for Information Security (BSI) issued a public warning against the use of Kaspersky virus protection software and recommended replacing it with alternative products; the warning is now governed by Section 13 BSIG and the BSI confirmed in 2026 that it is maintained. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from supplying cybersecurity and anti-virus products to US persons; since 29 September 2024 resale, licensing and integration by US persons are prohibited and Kaspersky Security Network may not operate on US persons' systems. In Switzerland there is no comparable measure: BACS, formerly the NCSC, states that it does not issue recommendations on the use of individual products and warns only where it has confirmed technical evidence of a security risk, and it has reported none for Kaspersky. Kaspersky's own position is that these decisions are political rather than the result of a technical evaluation, and it points to its transparency programme, data processing for European customers in Zurich, source code and SBOM review, and external audits. On the technical side, Kaspersky was named a Leader in the SPARK Matrix Network Detection and Response report 2025. In practice this matters most to public sector tenders, suppliers to German public bodies, organisations with US entities or US-person staff, and companies whose large customers exclude software of Russian origin in their supply chain requirements; for private companies in Switzerland and the EU there is no legal restriction on purchase or use.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />Compares detection results and product scope of the two vendors, useful if country of origin is one of several criteria in your decision.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Anti Targeted Attack Platform Enterprise help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and the split is predictable. It answers the questions about network-level monitoring, intrusion detection coverage, malware analysis in an isolated environment, central log collection with Syslog and REST export to a SIEM, role-based access for security officers, and where data is processed – since KATA runs on your own servers, the data residency question can be answered with your own location rather than a vendor region. It answers none of the questions about endpoint protection deployment and coverage, patch and vulnerability management, disk encryption on notebooks, multi-factor authentication, backup and recovery testing, mobile device management, or security awareness training, and it does not by itself prove 24/7 coverage, because the platform is a tool your team operates during your team's hours. The cheaper route to closing those gaps is usually to stay inside the same family: the Ultra level adds endpoint EDR and native XDR scenarios, and Kaspersky MDR covers the round-the-clock monitoring question, whereas mixing vendors means answering integration and interoperability questions on top of the original ones. Expect one further question that no product feature answers: several questionnaires now ask directly about official authority warnings concerning your suppliers, and that answer has to be prepared in writing rather than technically.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between KATA, KATA NDR Enhanced and KATA Ultra?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The single decisive difference is endpoint coverage: EDR capability and native XDR scenarios exist only in the Ultra level, so the two lower levels see the network but not what happens inside the hosts. The second most costly difference in practice is east-west visibility – deep packet inspection, IDS rules for internal traffic, the network session table and the inventory module all start at NDR Enhanced, which is what you need to detect lateral movement rather than only perimeter crossings. Retrospective work also depends on the level: only NDR Enhanced and Ultra store raw traffic for later analysis, while the base level keeps a PCAP tied to each IDS alert. Sandboxing, threat intelligence enrichment and MITRE ATT&amp;CK mapping are present at every level.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KATA</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KATA NDR Enhanced</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KATA Ultra</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Advanced sandbox</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">IDS north-south traffic</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">IDS east-west traffic and DPI</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Network map and inventory</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Raw traffic storage and retrospective analysis</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Per alert</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Shadow IT and anomaly detection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint EDR and native XDR</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Sale and resale in the United States</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Prohibited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Prohibited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Prohibited</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most important regional restriction is the United States: since 29 September 2024, resale, licensing and integration of Kaspersky cybersecurity software by US persons is prohibited and Kaspersky Security Network may not run on US persons' systems, which matters for any Swiss or European group with US subsidiaries or US-person staff. The platform is on-premises only – there is no vendor-hosted cloud console, so you provide, run and maintain the Central Node, Sandbox and Sensor machines yourself, and the operating effort is a real part of the total cost. Endpoint protection is not included and is the follow-up purchase that surprises buyers most often: KATA analyses network traffic, while endpoint telemetry requires Kaspersky Endpoint Security agents, and full endpoint detection and response only exists in the Ultra level. There is no patch management, no encryption management and no mobile device coverage in this product at all. One naming point deserves a check before you order: the vendor currently publishes three levels named KATA, KATA NDR Enhanced and KATA Ultra, while retail packaging still uses older labels such as Standard and Enterprise, so confirm with the supplier which of the three capability sets your package actually covers.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>We help you decide. Test: Antivirus program: Best antivirus programs for Windows 2025</strong><br />Reviews current endpoint protection options for Windows, which is the component you still have to buy separately alongside a network detection platform.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Anti Targeted Attack Platform Enterprise</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the platform run without a connection to the vendor cloud?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Instead of the cloud-based Kaspersky Security Network, you can operate Kaspersky Private Security Network, which holds the file and URL reputation database on a server inside your own network. Sandbox verdicts can then be published to that local reputation database rather than leaving the environment.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can existing mail and web gateways act as sensors?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. A server running Kaspersky Secure Mail Gateway or Kaspersky Security for Linux Mail Server can be used as a mail sensor, and Kaspersky Web Traffic Security integrates on the web side, so mail and web objects reach the sandbox without a second network tap.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is round-the-clock monitoring part of the product?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. KATA is a platform your own analysts operate, and alerts are only acted on when someone is watching the console. Continuous monitoring by an external team is Kaspersky MDR, a separate service.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-console,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>