<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Industrial CyberSecurity for Nodes Server EDR Enterprise Base?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Industrial endpoint protection</strong> – Real-time file protection for ICS and SCADA server nodes.<br /> <strong>Endpoint detection and response</strong> – IoC scanning, telemetry collection and attack spread path analysis.<br /> <strong>Response actions</strong> – Quarantine files, terminate processes, block execution, isolate the node.<br /> <strong>Local activity control</strong> – Application launch control, device control and Wi-Fi control.<br /> <strong>PLC project integrity check</strong> – Detects changes in Siemens, Schneider Electric and CODESYS projects.<br /> <strong>Important</strong> – Kaspersky Security Center and Network Agent are not included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Industrial CyberSecurity for Nodes Server EDR Enterprise Base?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Industrial CyberSecurity for Nodes, commonly shortened to KICS for Nodes, is industrial-grade endpoint protection with detection and response for the server-class machines in an automation network: SCADA servers, historian servers, gateways and OT application servers. This variant is managed centrally from an on-premises Kaspersky Security Center rather than from a cloud console, so policies, events and telemetry stay inside the plant network.<br /> <br /> <strong>New licence</strong> – Base is a new licence, not a renewal or cross-grade.<br /> <strong>On-premises console</strong> – Policies and events stay inside the plant network.<br /> <strong>Legacy Windows support</strong> – Protects old Windows Server builds still running production lines.<br /> <strong>Low process impact</strong> – Tunable resource use and non-intrusive default settings.<br /> <strong>OVAL compliance audit</strong> – Vulnerability and configuration checks against published OVAL definitions.<br /> <strong>Automation vendor compatibility</strong> – Over 200 compatibility certificates with automation vendor solutions.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Why Windows Defender alone is not enough</strong><br />Explains where the protection built into Windows stops and what a dedicated security agent adds on top of it.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Industrial CyberSecurity for Nodes Server EDR Enterprise Base suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is an OT product, so the deciding factor is not headcount but whether you run an automation network with server-class nodes and already operate a Kaspersky Security Center. The table shows how often each factor applies to a company of that size.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Kaspersky Security Center already operated</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Nodes Server EDR Enterprise Base meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Information Security Act (ISG) has been in force since 1 January 2024, and the supplementary provisions on the reporting duty took effect on 1 April 2025; they apply to operators of critical infrastructure such as energy suppliers, water utilities, transport operators and hospitals, not to every industrial company. Affected operators must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which in practice means being able to say within one day what was hit and how far it spread. The EDR component supports exactly that part: it collects endpoint telemetry, reconstructs the attack spread path and timestamps the detection chain, so the first report is based on recorded events rather than on an operator recollection. What it does not cover is the reporting act itself, the OT network side of the picture, which requires KICS for Networks, and the organisational duty to decide whether an incident is significant enough to be reportable. This description is not legal advice; whether the reporting obligation applies to your organisation should be clarified with a qualified specialist.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Nodes Server EDR Enterprise Base meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No security product creates NIS 2 compliance, because the Directive addresses the organisation and its management, not a piece of software. The NIS 2 Directive requires measures in categories including risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, basic cyber hygiene and training, cryptography, access control, and multi-factor authentication. This product contributes to two of those categories in a concrete way: incident handling, through detection, telemetry and response actions on server nodes, and vulnerability handling, through the OVAL-based audit that checks node configuration and known vulnerabilities. It contributes nothing to business continuity and backup, cryptography, multi-factor authentication, staff training or supply chain governance, all of which need separate products or processes. Treat it as evidence for the endpoint layer of the incident-handling requirement, not as coverage of the requirement set.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two official measures concerning the vendor are currently in force. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022 and recommends replacing it with alternative products; the BSI states that it made no assessment of Kaspersky products outside that antivirus portfolio, and the warning was still in force and being contested by Kaspersky in 2026. In the United States, the Department of Commerce issued a final determination on 20 June 2024 that barred new agreements with US persons from 20 July 2024 and, from 29 September 2024, prohibited signature and codebase updates as well as operation of the Kaspersky Security Network on US systems. Kaspersky's own position is that the German warning is not justified and was not based on an objective technical analysis of the risks of using its software. Verified independent facts are unaffected by these measures: threat data submitted by European users is processed in two data centres in Zurich, the information security management system covering that infrastructure is certified to ISO/IEC 27001:2022, and the vendor holds over 200 compatibility certificates with automation vendors. Practically, this matters most if you supply the German or US public sector, if your group has US entities, or if customer supply chain requirements exclude vendors subject to a national authority warning; for a purely Swiss industrial operator with no such exposure it is a documentation point rather than a blocker.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Nodes Server EDR Enterprise Base help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for the endpoint and OT-node sections, and not at all for several others. It answers questions on malware protection of production servers, application allowlisting, removable-media and device control, host firewall management, file integrity and registry monitoring, endpoint detection and response coverage, incident response actions available to the security team, and vulnerability and configuration auditing against OVAL definitions. It does not answer questions on backup and restore, disaster recovery testing, disk or file encryption, multi-factor authentication, third-party patch management, mobile device management, email security, or OT network traffic monitoring, and it does not produce an attestation about the vendor's country of origin, which is increasingly its own questionnaire item. The cheapest way to close the OT-side gaps is usually to stay in the same family and add KICS for Networks for the network layer rather than introducing a second vendor with a second console; backup, encryption and patching, however, have no counterpart in this family and must be sourced separately.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: how backups help you avoid outages</strong><br />Covers the backup and recovery side that endpoint protection does not address and that questionnaires regularly ask about.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between KICS for Nodes Server Enterprise and KICS for Nodes Server EDR Enterprise?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The single decisive difference is investigation: the EDR variant turns the agent into an endpoint sensor that stores telemetry, scans for indicators of compromise and reconstructs how an incident spread, while the plain variant blocks and reports but leaves you without that history afterwards. Both variants protect the same server nodes with the same protection and control components, and both are managed from the same console, so this is not a protection-strength decision. Choose the EDR variant if you have to explain an incident after the fact, whether to an authority, an insurer or a customer auditor. Choose the plain variant if malware blocking on the node is all you need and no one will ask you to reconstruct a timeline. Note that the EDR capability is delivered inside the same agent and needs no additional appliance on the plant floor.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Server Enterprise</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Server EDR Enterprise</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Real-time file protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Application and device control</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">PLC project integrity check</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Telemetry and IoC scanning</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Attack spread path analysis</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Cross-endpoint response actions</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Available to US persons</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">There is a hard regional limitation: since 29 September 2024 the vendor may not supply signature or codebase updates to US persons, and the Kaspersky Security Network may not operate on US systems, so this product is not a viable choice for a plant in the United States or for a group whose OT security is administered from there. Coverage is also narrower than the family name suggests in three ways: it licenses server-class nodes only, so HMIs and engineering workstations need the Workstation variant; it is a Windows application, so industrial Linux nodes need the separate KICS for Linux Nodes product; and it secures the node, not the wire, so OT network traffic analysis requires KICS for Networks. The most common follow-up purchase is the management infrastructure itself, because Kaspersky Security Center and its Network Agent are deployed separately and the Network Agent is not part of this distribution kit. Finally, there is no backup, no disk encryption and no third-party patch management in this product, which is where buyers coming from a general IT endpoint suite are most often caught out.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-server-2025-vs-2022-vs-2019"><strong>Windows Server 2025 vs. 2022 vs. 2019: is the upgrade worth it?</strong><br />Useful when deciding whether to keep protecting an ageing server node or to migrate it to a supported Windows Server release first.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Industrial CyberSecurity for Nodes Server EDR Enterprise Base</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it protect legacy systems that cannot be migrated?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, and this is one of the main reasons the product exists. Nodes running as far back as Windows XP SP2 and Windows Server 2003 can be managed through Kaspersky Security Center, although those particular systems require an older Network Agent build rather than the current one.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which controllers does the PLC project integrity check support?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The vendor names Siemens SIMATIC S7-300, S7-400, S7-400H, S7-1200 and S7-1500, SIPROTEC 4, Schneider Electric Modicon M340 and M580, CODESYS V3 devices, and Fastwel CPM723-01. If your controllers are not on that list, the rest of the protection still applies but the project integrity check will not.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Where is threat data from European users processed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Suspicious and malicious files that products submit to the Kaspersky Security Network from European users are processed in two data centres in Zurich, Switzerland. The information security management system covering that infrastructure is certified to ISO/IEC 27001:2022, which is a point worth recording when a customer audit asks where security telemetry leaves the country.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-server,sec-endpoint" data-audience="b2b" data-count="3"> </div>