<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Industrial CyberSecurity for Networks Standard Server Upgrade?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Server component</strong> – Central site server that collects and correlates network events.<br /> <strong>Traffic analysis</strong> – Deep packet inspection of more than 50 industrial protocols.<br /> <strong>Intrusion detection</strong> – Rule sets covering more than 5000 known network attacks.<br /> <strong>Asset discovery</strong> – Passive monitoring plus active polling of OT devices.<br /> <strong>Web console and API</strong> – Browser interface plus REST API for external connectors.<br /> <strong>Important</strong> – Endpoint protection is not included, KICS for Nodes covers hosts.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Industrial CyberSecurity for Networks Standard Server Upgrade?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Industrial CyberSecurity for Networks is the OT network traffic analysis and detection component of the KICS platform, and it runs as a site-level server that operators work with through a browser console. Management is central from that console, and the server can also be connected to Kaspersky Security Center through the administration plug-in.<br /> <br /> <strong>No process impact</strong> – Analysis runs on mirrored traffic, not inline.<br /> <strong>Learning mode</strong> – Interaction rules are generated automatically from observed normal traffic.<br /> <strong>ATT&amp;CK mapping</strong> – Incidents are mapped to MITRE ATT&amp;CK for ICS techniques.<br /> <strong>Vulnerability visibility</strong> – Flags known weaknesses in identified equipment with mitigation advice.<br /> <strong>Existing tooling</strong> – Events are forwarded to the SIEM your SOC already runs.<br /> <strong>Tested compatibility</strong> – Checked against more than 200 industrial systems and devices.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Industrial CyberSecurity for Networks Standard Server Upgrade suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is a product for organisations that actually operate an industrial or building-automation network with mirrored traffic available, not for a general office network. The decisive question is not headcount but whether you have a SPAN or TAP feed from your OT switches and someone who will read the alerts.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Mirrored OT traffic available</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Standard Server Upgrade meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The obligation applies to operators of critical infrastructure named in the revised Information Security Act, including energy and drinking water suppliers, transport companies and cantonal and municipal administrations, and it has been in force since 1 April 2025. Those organisations must submit an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a cyberattack, with 14 days to complete missing details. Within that 24-hour window the product helps mainly with the facts you have to state: it records the detected network events with timestamps, shows which devices communicated with each other, and lets you export the event data to a SIEM so the incident can be reconstructed later. What it does not do is decide whether an incident is reportable, produce the report, cover attacks that never touch the monitored network segments, or give you host-level forensics from the affected workstation. It also does not replace the internal escalation process that has to move an alert from the control room to the person who signs the report. This text is not legal advice, and the responsibility for assessing your own reporting obligation remains with your organisation.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Standard Server Upgrade meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates compliance with the NIS 2 Directive, because the directive addresses the organisation and its processes rather than a single tool. NIS 2 requires measures in categories such as risk analysis and security policies, incident handling, business continuity and backup, supply chain security, network and information system security, procedures to assess whether the measures work, cyber hygiene and training, cryptography, and access control including multi-factor authentication. This product contributes to three of them in a concrete way: it delivers the asset inventory of the OT network, it provides continuous monitoring and intrusion detection as part of network and information system security, and it produces the detection and event data that incident handling depends on. It does not address backup and business continuity, cryptography, access control or multi-factor authentication, staff training, or supplier management, and it does not evaluate whether your own measures are effective. Those gaps have to be closed with separate tools and documented internal procedures.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two official positions are relevant and both are still in force. The German Federal Office for Information Security (BSI) issued a warning against the use of Kaspersky virus protection software on 15 March 2022 under section 13 of the BSI Act, and the BSI confirmed again in early 2026 that it maintains this warning. Separately, the US Department of Commerce issued a Final Determination on 20 June 2024 that barred new agreements with US persons from 20 July 2024 and stopped signature and codebase updates as well as operation of the Kaspersky Security Network in the United States from 29 September 2024. Kaspersky states that it is a privately held company with no ties to any government, describes the German decision as politically motivated, and points to its relocation of data processing for European users to two data centres in Zurich in 2018. Independent and third-party assessments of the technology itself are unaffected by these decisions: Kaspersky Industrial CyberSecurity for Networks holds a TÜV AUSTRIA certification against IEC 62443-4-1 for its secure development process, and Kaspersky holds ISO 27001 and SOC 2 Type II certifications. In practice the warnings matter most if you sell to or operate on behalf of public bodies, if you have a US parent company or US customers, or if your own customers pass supply-chain requirements down to you in contracts. For a purely private industrial operator in Switzerland or the European Union there is no sales restriction, but the vendor question will come up in procurement reviews and it is better to have an answer prepared than to be surprised by it.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A side-by-side look at detection results and product scope for both vendors, useful background if the vendor question is being discussed internally.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Networks Standard Server Upgrade help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, but only for the network and detection block of a typical questionnaire. It answers questions about whether you maintain an inventory of OT assets, whether industrial network traffic is monitored, whether you can detect unauthorised communication and known attack patterns, whether security events are logged and forwarded to a central system, and whether you have visibility of known vulnerabilities in your control equipment. It answers none of the following: malware protection on servers and operator workstations, patch management, encryption of devices, multi-factor authentication and access governance, backup and restore testing, security awareness training, and supplier risk management. The cheapest way to close the endpoint part of that list is usually KICS for Nodes from the same family, because it shares the management path and the reporting rather than adding a second console and a second support contact. Backup, access control and training will need separate answers regardless of which security vendor you use.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains the backup and restore questions that questionnaires ask about and that network monitoring does not answer.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most important regional point is that Kaspersky products may not be sold, updated or resold in the United States following the Final Determination described above, so this is not a workable choice for a group with US sites or US-based obligations. The product is passive by design: it analyses mirrored traffic and raises alerts, and although manual response actions and network access restriction exist, it is not an inline firewall and will not block an attack on its own. It needs a traffic feed, which means SPAN or TAP ports on your OT switches, and additional capture points in other segments are sold separately as Additional Sensor packages rather than being included with the server. Endpoint protection, patch management and encryption are outside its scope entirely. Finally, this article is the Upgrade variant of the Standard Server licence rather than a first-time base purchase, so confirm with the shop that your existing KICS for Networks deployment qualifies before you order.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Covers the endpoint protection layer that this network product does not include and that operator workstations still need.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Industrial CyberSecurity for Networks Standard Server Upgrade</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which industrial protocols are actually understood?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Deep packet inspection covers more than 50 industrial protocols. Verified examples include the IEC 60870-5-101 and IEC 60870-5-104 telecontrol standards, IEC 61850 for substation automation with support for loading device and tag configurations, and BACnet for building automation systems.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it run in an isolated or air-gapped network?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Kaspersky positions the platform for distributed, air-gapped and isolated environments, and the update functionality can be activated with a license key file without contacting Kaspersky activation servers. You should still plan how database and rule updates reach the isolated segment.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it work together with Kaspersky Security Center?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. An administration plug-in for Kaspersky Security Center is available, which lets you search devices and events in the databases of the KICS for Networks servers and receive updates through the Kaspersky Security Center Administration Server. This is useful when the same team already runs Kaspersky products on the IT side.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-console,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>