<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Anti Targeted Attack Platform Standard?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Central Node</strong> – Core server that stores verdicts and runs detection engines.<br /> <strong>Network Sensor</strong> – Receives mirrored SPAN traffic and scans it with IDS rules.<br /> <strong>Advanced Sandbox</strong> – Detonates suspicious objects in isolated virtual operating systems.<br /> <strong>URL reputation analysis</strong> – Checks files and links against the Kaspersky Security Network.<br /> <strong>Network guided response</strong> – Gateway-level blocking through ICAP integration with proxy servers.<br /> <strong>Important</strong> – EDR, endpoint protection and patch management are not included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Anti Targeted Attack Platform Standard?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Anti Targeted Attack Platform Standard is an on-premises anti-APT platform that analyses mirrored network traffic and detonates suspicious objects in a sandbox; Kaspersky now markets the line simply as Kaspersky Anti Targeted Attack, so older listings carrying the Platform suffix refer to the same family. Every component is administered from one self-hosted web console on the Central Node server, with no cloud tenant involved.<br /><br /> <strong>Sees unmanaged devices</strong> – Covers hosts where no endpoint agent can be installed.<br /> <strong>No cloud dependency</strong> – Runs fully on-premises with data staying in-house.<br /> <strong>Feeds existing SIEM</strong> – Publishes alerts over syslog and a REST API.<br /> <strong>Mail sensor integration</strong> – Secure Mail Gateway can act as a network sensor.<br /> <strong>Multitenancy for providers</strong> – Separates tenants across Primary and Secondary Central Nodes.<br /> <strong>Documented alert trail</strong> – Timestamped alerts usable as evidence in incident reports.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains which attack stages endpoint antivirus does not see, and why network-level detection is added on top.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Anti Targeted Attack Platform Standard suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The platform assumes someone reads the alerts. It fits organisations with a security team or an external SOC that already triages events daily; a company without that capacity will generate alerts nobody actions.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Analyst capacity to triage network alerts</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Anti Targeted Attack Platform Standard meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Since 1 April 2025 the revised Information Security Act (ISG) obliges operators of critical infrastructure in Switzerland to report significant cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. The obligation covers sectors such as energy, water supply, healthcare, finance, telecommunications, transport and cantonal and municipal administrations rather than every company, and since 1 October 2025 a failure to report can be sanctioned with a fine of up to CHF 100,000. Within that 24-hour window the platform contributes the detection side: timestamped IDS alerts, sandbox verdicts and the packet capture attached to an alert give the reporting team an approximate attack start time, the affected internal addresses and an object hash. It does not file the report, does not decide whether an incident crosses the reporting threshold, and in this tier does not store raw traffic for retrospective analysis, so anything older than the current alert has to be reconstructed from other logs. This text is buyer information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Anti Targeted Attack Platform Standard meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance, because the directive obliges organisations and their management, not software vendors. NIS 2 requires categories of measures including risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and maintenance, procedures to assess the effectiveness of measures, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This product maps to incident handling and to the detection part of network and information system security: it monitors mirrored traffic for intrusions, prioritises alerts and exports them by syslog so they can be correlated centrally. It contributes nothing to business continuity and backup, cryptography, access control, asset management or multi-factor authentication, and it does not cover endpoints unless a higher tier is licensed. Supply chain security is touched only indirectly, through visibility into traffic between your network and external connections.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">On 20 June 2024 the United States Department of Commerce issued a Final Determination under its ICTS supply chain authority prohibiting Kaspersky from entering new agreements with US persons from 20 July 2024, and from 29 September 2024 also prohibiting anti-virus signature and codebase updates, operation of the Kaspersky Security Network in the United States, and the resale, licensing or integration of Kaspersky cybersecurity software by US persons. Germany's Federal Office for Information Security has warned against the use of Kaspersky anti-virus software since 15 March 2022; that warning is still published and has been issued under Section 13 BSIG since 6 December 2025. Both measures remain in force. Switzerland has taken no comparable step: BACS has stated that no internal directive or prohibition on Kaspersky products exists and that it issues warnings only where it holds confirmed technical evidence of a security risk. Kaspersky rejects the assessments, describes the German warning as not based on an objective technical analysis of its software, and points to its transparency centres and third-party audits. Recognition of the product itself is a separate matter from the political assessment: Kaspersky was named a Leader in the QKS Group SPARK Matrix for Network Detection and Response in 2025. In practice the restrictions bite for buyers with a US parent company, US federal contracts, or customers whose supplier requirements exclude vendors subject to a national warning; a Swiss or EU company without that exposure faces no legal barrier to purchase, but should expect the question in audits and supplier questionnaires.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />Compares the detection performance of both vendors, useful if you are weighing an alternative supplier against the assessments above.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Anti Targeted Attack Platform Standard help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only on the network side. It answers directly whether network traffic is continuously monitored for intrusions, whether suspicious files are detonated in a sandbox before they reach users, whether alerts are timestamped and forwarded to a SIEM, and whether incident response has technical detection behind it. It answers none of the endpoint items — endpoint protection, EDR telemetry, device and application control, patch status, disk encryption, mobile device management — and nothing on backup, business continuity, identity or access management. In this tier it also cannot answer questions about retrospective traffic analysis or a complete network asset inventory, because raw traffic storage, the network session table and the inventory module belong to the NDR Enhanced tier. To close the endpoint gaps, moving up to KATA Ultra or adding Kaspersky Next EDR Expert from the same family is normally cheaper to run than pairing a network product from one vendor with an endpoint product from another, because the verdicts stay in a single console instead of being correlated by hand.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers the business continuity and backup questions this platform does not answer, which appear in nearly every supplier questionnaire.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the KATA, NDR Enhanced and Ultra editions?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is where detection happens. The base tier inspects north-south traffic passing the sensor, NDR Enhanced adds east-west traffic, deep packet inspection, a network map and an inventory module, and Ultra adds endpoint detection and response on top. The base tier stores no raw traffic, so once an alert has aged out there is nothing left to re-examine; anomaly detection and shadow IT detection also start at NDR Enhanced. Native XDR scenarios, where network and endpoint verdicts correlate automatically, exist only in Ultra. Kaspersky's own documentation names the three tiers KATA, KATA NDR Enhanced and KATA Ultra, so confirm which of the three a retail listing covers before ordering.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">KATA (base)</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">NDR Enhanced</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Ultra</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Advanced sandboxing</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">IDS on north-south traffic</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Gateway response via ICAP</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">IDS on east-west traffic and DPI</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Raw traffic storage and retrospective analysis</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Network map and inventory</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Anomaly and shadow IT detection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Endpoint detection and response</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Native XDR scenarios</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The regional restriction here runs the opposite way to the usual case: the software cannot be sold, resold, licensed or integrated into products for US persons, so a Swiss or EU group with US subsidiaries cannot standardise on it across all sites. The platform only sees traffic that actually reaches the sensor, which means SPAN, ERSPAN or RSPAN mirroring has to be configured on the switches first, and encrypted traffic is inspected only where SSL certificate replacement is already running on the proxy. There is no cloud console: Central Node, Sensor and Sandbox run on your own servers or virtual machines, which helps with data residency but costs administrative time for teams that do not want to operate appliances. The follow-up purchase that comes up most often is endpoint coverage, because alerts regularly point at a host this tier can neither examine nor isolate. Missing anomaly detection, shadow IT detection and retrospective packet analysis are the other common reasons buyers move up a tier shortly after deployment.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Anti Targeted Attack Platform Standard</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it run without sending data to Kaspersky cloud services?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Reputation lookups for files and URLs can be directed to Kaspersky Private Security Network (KPSN) instead of the public Kaspersky Security Network, which keeps the requests inside your own infrastructure. This is the usual setup for organisations that cannot send metadata to an external reputation service.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can a mail server act as a sensor?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Kaspersky Secure Mail Gateway and Kaspersky Security for Linux Mail Server can be configured as mail sensors and forward copies of messages to the Central Node for scanning and sandboxing. Integration with a mail server over POP3 is also supported.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,compliance-ch-isg,compliance-nis2" data-audience="b2b" data-count="3"> </div>