<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Industrial CyberSecurity for Networks Additional Sensor?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Additional sensor licence</strong> – Adds one more sensor node to an existing deployment.<br /> <strong>Database and module updates</strong> – Keeps traffic analysis and detection rules current.<br /> <strong>Manufacturer technical support</strong> – Support entitlement at the Enterprise product level.<br /> <strong>Passive traffic analysis</strong> – Reads mirrored OT traffic without touching the process network.<br /> <strong>Monitoring point capacity</strong> – Up to eight monitoring points per sensor node.<br /> <strong>Important</strong> – No management console of its own; the server holds it.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Industrial CyberSecurity for Networks Additional Sensor?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is an add-on licence for one further sensor node in an existing Kaspersky Industrial CyberSecurity for Networks system, which analyses a copy of industrial network traffic to detect device activity, system commands to controllers and deviations in process parameters. Sensors have no console of their own: they forward analysis results to the single KICS for Networks Server, which is monitored through the Kaspersky Security Center web console.<br /> <br /> <strong>Remote segment coverage</strong> – Reaches OT segments the central server cannot see.<br /> <strong>No process interference</strong> – Analyses copied traffic, so controllers and PLCs stay untouched.<br /> <strong>Automatic asset discovery</strong> – Devices on the new segment appear in the network map.<br /> <strong>PLC project tracking</strong> – Records controller project reads and writes for later comparison.<br /> <strong>One policy set</strong> – All sensors stay under the same server configuration.<br /> <strong>Traffic kept as evidence</strong> – Stores the traffic belonging to registered events.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Industrial CyberSecurity for Networks Additional Sensor suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but topology: this licence only makes sense if an OT network already exists, a KICS for Networks Server is already licensed, and there is at least one production segment whose traffic cannot physically reach that server. A single-site workshop with one switch does not need a second sensor. A plant with separate lines, a substation, a pumping station or a remote utility area does.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">OT segments unreachable by the server</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Additional Sensor meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In Switzerland the reporting duty under the revised Information Security Act applies to operators of critical infrastructure, not to every company that runs an industrial network, so the first question is whether your organisation falls into one of the named sectors at all. Operators who are covered must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. The sensor supports that deadline in one concrete way: it registers events with timestamps and stores the traffic belonging to them, so the initial report can name the affected segment and the observed activity instead of describing a suspicion. What it does not deliver is the organisational half of the obligation, namely a defined incident response process, named reporting roles, the assessment of whether an incident is reportable, and evidence from workstations and servers, which would require an endpoint product. It also produces no report template and no legal classification of the event. This text is informational and does not constitute legal advice.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Additional Sensor meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance, because the directive addresses entities and their management processes rather than software. NIS 2 requires risk analysis and security policies, incident handling, business continuity, supply chain security, security in network and information systems including vulnerability handling, access control and asset management, cryptography, and human resources security. This add-on contributes to two of those categories: security in network and information systems, through continuous analysis of industrial traffic on the additional segment, and asset management, through automatic discovery of the devices communicating there. It contributes nothing to business continuity, cryptography, access control across the organisation, human resources security or supplier assessment. Incident reporting under the directive also stays organisational, since the sensor supplies the technical evidence but not the decision to report, the deadlines or the recipients.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Germany's Federal Office for Information Security has warned against the use of Kaspersky virus protection software since 15 March 2022. The warning remains in force; it was archived after six months, which does not invalidate it, and the office has stated it sees no reason to change it. Its wording refers to antivirus software, and the office has not publicly clarified whether OT monitoring products are covered. In the United States, the Department of Commerce issued a Final Determination in June 2024: Kaspersky has been prohibited from new sales to US persons since 20 July 2024 and from supplying signature and database updates since 29 September 2024, and that prohibition is still in force. Kaspersky rejects the assessments as political rather than technical, points to its Global Transparency Initiative including data processing in Switzerland, and has publicly demanded that the German warning be withdrawn. The assessments concern the manufacturer's country of origin and legal jurisdiction, not a published technical defect in the products. In Switzerland, the Federal Office for Cybersecurity has issued no warning and has stated that it does not issue recommendations on the use of individual products. In practice this matters most for public sector tenders, for organisations with a German parent company or German customers, for group structures with a US entity, and for supplier questionnaires that ask about vendor origin.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A direct comparison of the two vendors and how their protection technologies differ in practice.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Additional Sensor help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only for the network section. It answers questions about whether OT traffic is monitored continuously, whether an inventory of industrial devices exists, whether communication between controllers is checked against defined rules, whether anomalies in process parameters are detected, whether events are logged with the associated traffic retained, and whether events can be forwarded to a central system. It answers none of the following: malware protection and detection and response on OT hosts, patch and vulnerability status of endpoints, backup and restore testing, encryption of data at rest or in transit, multi-factor authentication and privileged access management, security awareness training, and the assessment of your own suppliers. It also cannot be used to prove that a control is enforced, since it observes rather than blocks. The cheapest route to closing the endpoint gap is usually to stay inside the same family and add Kaspersky Industrial CyberSecurity for Nodes, which delivers protection and response on industrial workstations and servers and feeds its data back into the same server, rather than introducing a second vendor and a second console.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains the backup and recovery questions that appear in every customer questionnaire and that monitoring alone cannot answer.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the KICS for Networks Server and the Additional Sensor?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is that only one server exists per deployment, while sensors are the part you scale. The server receives, processes and stores data and provides it to users; a sensor receives and analyses traffic from the network interfaces of its own node and forwards the results to that server. A sensor cannot be installed on a node that performs server functions, so each additional sensor occupies a separate node. This listing is the sensor licence, not the server.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Property</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Standard Server</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Additional Sensor</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Role in the deployment</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Central server</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Traffic collector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Number per deployment</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">One only</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Several</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Monitoring points per node</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Up to 4</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Up to 8</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Stores events and device data</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Contained in this listing</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most important regional limitation is the United States: since the Final Determination of the US Department of Commerce, Kaspersky may not sell to US persons and may not deliver database updates there, so a US site inside an international group cannot be covered by this licence and needs a different product. This is an add-on and does nothing on its own, because sensors are managed by the server and forward their analysis results to it. It detects rather than prevents, so it will register an unauthorised command to a controller but will not stop it, and any response on the endpoints requires Kaspersky Industrial CyberSecurity for Nodes. Traffic also has to physically reach the sensor through port mirroring or a network tap, and a segment without that infrastructure stays invisible no matter how many licences are purchased. Finally, when events are transmitted to recipient systems other than Kaspersky Security Center, the application does not guarantee the security of that transfer, so a protected path to a SIEM has to be provided separately.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Shows why network-side monitoring and endpoint protection cover different gaps and why one does not replace the other.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Industrial CyberSecurity for Networks Additional Sensor</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the sensor run on the same machine as the KICS for Networks Server?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. A sensor cannot be installed on a node that performs server functions, so every additional sensor occupies its own node. Plan the node before ordering the licence.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between a Base and a Renewal licence?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Base is the licence for a sensor that is not yet covered, which is the variant listed here. Renewal continues an existing entitlement for the same product and is the wrong choice if you are adding a sensor for the first time.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the sensor block attacks on the industrial network?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. It analyses a copy of the traffic for signs of attacks without affecting the industrial network, registers events and saves the associated traffic. Blocking has to come from network controls or from endpoint protection.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-console,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>