<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Industrial CyberSecurity for Nodes Workstation Enterprise Base?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Real-Time File Protection</strong> – Scans files on access, with Anti-Cryptor against remote encryption.<br /> <strong>Applications Launch Control</strong> – Default deny rules limit which executables may start.<br /> <strong>Device Control</strong> – Regulates USB and other external devices per policy.<br /> <strong>PLC Project Integrity Check</strong> – Verifies controller projects against a stored reference state.<br /> <strong>System Inspection</strong> – File Integrity Monitor, Registry Access Monitor and Log Inspection.<br /> <strong>Important</strong> – EDR is a separate KICS for Nodes licence tier.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Industrial CyberSecurity for Nodes Workstation Enterprise Base?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Industrial CyberSecurity for Nodes is the Windows endpoint agent of the KICS platform, and the Workstation licence covers operator stations, HMIs and engineering workstations rather than SCADA servers. It is managed centrally from Kaspersky Security Center, the same on-premises console used for other Kaspersky business products, and Base means a new licence rather than a Renewal or Cross-grade of an existing one.<br /><br /> <strong>Legacy Windows support</strong> – Covers embedded and IoT builds still running production lines.<br /> <strong>ICS compatibility</strong> – Designed for use alongside SCADA, PLC and DCS.<br /> <strong>Portable Scanner</strong> – Inspects isolated nodes from a prepared removable drive.<br /> <strong>Network Attack Blocker</strong> – Stops port scans, brute force and exploit traffic.<br /> <strong>Windows Firewall management</strong> – Enforces host firewall rules and blocks local changes.<br /> <strong>SCADA status reporting</strong> – Kaspersky Security Gateway forwards protection status to SCADA.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains which gaps the built-in Windows protection leaves open and why dedicated endpoint software is used in addition.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Industrial CyberSecurity for Nodes Workstation Enterprise Base suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether you operate Windows-based control room or engineering workstations that a standard office endpoint product cannot be installed on without risking the process. Small workshops with a single unmanaged HMI usually cannot justify the management console; from a handful of nodes upwards, central policy control becomes the reason to buy.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Increasing</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Windows HMI or engineering nodes on site</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partly</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Nodes Workstation Enterprise Base meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No security product on its own satisfies the revised Information Security Act, because the obligations attach to the organisation and not to the software. The reporting obligation applies to designated operators of critical infrastructure, who must submit an initial report of a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the practical question is whether you would notice an incident on a control room workstation in time to report it. Kaspersky Industrial CyberSecurity for Nodes supports that in three concrete ways: File Integrity Monitor and Registry Access Monitor record unauthorised changes on the node, Log Inspection evaluates Windows event logs, and every detection is written to Kaspersky Security Center, where it can be retrieved as a dated report for the reporting file. What it does not do is produce the report, establish an incident response process, monitor OT network traffic between controllers, or cover Linux nodes and the network layer, all of which need additional products and internal procedures. Determining whether your organisation falls under the reporting obligation at all is a legal question, and this text is not legal advice.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Nodes Workstation Enterprise Base meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance, because the directive requires risk management measures at organisational level and holds management accountable for them. The measure categories it names include risk analysis and information system security policies, incident handling, business continuity and backup, supply chain security, security in acquisition and maintenance, cyber hygiene and training, access control and asset management, and multi-factor authentication. This product contributes to a defined subset: malware protection and application control on industrial endpoints, control of removable media, integrity monitoring of files, registry and PLC projects, and central evidence of policy enforcement. It contributes nothing to business continuity and backup, supplier assessment, staff training, cryptography, identity management or multi-factor authentication, and it does not monitor the industrial network itself. Buyers in listed sectors should treat it as one measure within a management system, not as a substitute for one.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two official positions are relevant and both are still in force. The German Federal Office for Information Security has warned against the use of Kaspersky antivirus software since 15 March 2022; the warning is a recommendation, not a sales ban, and since 6 December 2025 it has been issued under Section 13 of the amended BSI Act. In the United States, the Department of Commerce Bureau of Industry and Security issued a Final Determination in June 2024 that has prohibited the sale and resale of Kaspersky software, the delivery of signature and codebase updates, and the operation of the Kaspersky Security Network on US systems since 29 September 2024. Kaspersky rejects both assessments as not based on technical evidence, points to its Global Transparency Initiative, its Zurich Transparency Center and the relocation of threat data processing for European users to two data centres in Switzerland, and has publicly pressed for the German warning to be withdrawn. In Switzerland, BACS has issued no warning and has stated that no misuse of Kaspersky software has been reported to it, while also confirming that federal offices no longer use the software; independent test institutes have continued to include Kaspersky endpoint products in comparative testing, although those tests cover the office endpoint range rather than the industrial product. In practice this matters most for public sector tenders, for companies with a German parent or German operations, for supply chains with US touchpoints, and for anyone whose customer contracts contain vendor origin clauses; for a privately held Swiss manufacturer with no such clauses it may not matter at all.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection?</strong><br />Compares the detection performance and functional scope of both vendors, useful if the vendor question is part of your decision.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Industrial CyberSecurity for Nodes Workstation Enterprise Base help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for the endpoint section, and not for most of the rest. It answers questions on malware protection of industrial endpoints, application whitelisting, removable media and USB control, host firewall enforcement, integrity monitoring of files and registry keys, and central policy management with role-based access, and Kaspersky Security Center can produce dated reports as evidence rather than a written assurance. It does not answer questions on patch status of third-party software, disk encryption, backup and restore testing, multi-factor authentication, mobile devices, email security, OT network monitoring, or log retention beyond what your console is configured to keep. It also does not help with the vendor origin question, which increasingly appears in questionnaires from customers with public sector or US exposure. Where the gaps matter, the cheaper route is usually to stay inside the same family: KICS for Networks covers the OT network layer, the EDR licence tier covers detection and response evidence, and Kaspersky Endpoint Security for Business covers patch and encryption management on the office side, all under the same console.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the Workstation, Server and EDR licences of KICS for Nodes?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is detection and response: neither the Workstation nor the Server licence includes EDR, which is a separate licence tier of the same product. The Workstation and Server licences differ in the node type they cover, so a SCADA or historian server needs a Server licence even though the agent and the components are the same. All three are managed from Kaspersky Security Center, and the agent is the same installation package in each case. Buying Workstation licences for servers is the most common ordering mistake in this family.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Workstation</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Server</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">EDR tier</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Covers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">HMI and engineering nodes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">SCADA and industrial servers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Nodes plus EDR</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Protection and control components</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">PLC Project Integrity Check</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Root-cause analysis and response actions</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Managed in Kaspersky Security Center</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Regional availability is the first thing to check: the US Department of Commerce prohibition has blocked the sale, resale and updating of Kaspersky software and the operation of the Kaspersky Security Network in the United States since 29 September 2024, so a Swiss or EU parent company cannot roll this out to a US plant, while sale and updates in Switzerland and the European Union are unaffected. Platform coverage is Windows only; industrial Linux nodes require Kaspersky Industrial CyberSecurity for Linux Nodes, which is a separate product with its own licence, and server nodes require the Server licence rather than this one. The product covers the endpoint, not the network, so switch traffic, PLC-to-PLC communication and passive asset discovery need KICS for Networks alongside it. Three functions that buyers regularly assume are included and are not: third-party patch management, disk encryption management, and backup or restore of the node itself, which in an OT environment is usually the component that actually determines how long a line stays down after an incident.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers why a working backup and restore routine decides the length of an outage, the gap that endpoint protection does not close.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Industrial CyberSecurity for Nodes Workstation Enterprise Base</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Do I need Kaspersky Security Center to use it?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">For central operation, yes. The agent has a local Application Console for single-node configuration, but group tasks and group policies can only be created and applied through Kaspersky Security Center, which you install on-premises yourself.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it run on older Windows versions still used in production?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, and that is one of the main reasons it exists as a separate product. Supported systems include Windows XP SP2 and SP3, Windows 7 Embedded POSReady, Windows 8 and 8.1 Embedded Industry Professional and Windows 10 IoT Enterprise, although the oldest systems require specific Network Agent versions and some functions, such as blocking network sessions, are restricted on Windows XP SP2.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it replace Kaspersky Endpoint Security for Business on office computers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. This is the industrial node product and is licensed per protected industrial node; office desktops, laptops and mail servers belong under Kaspersky Endpoint Security for Business, which shares the same management console.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Where is threat data from the agent processed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Suspicious and unknown files voluntarily submitted to the Kaspersky Security Network by European users are processed in two data centres in Zurich, Switzerland, as part of the Global Transparency Initiative. Participation in the Kaspersky Security Network is a policy setting and can be switched off entirely for isolated networks.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-endpoint,sec-console,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>