What are the key advantages of Kaspersky Anti Targeted Attack Platform Enterprise EDR Edition?
Central console – On-premises web interface for network and endpoint alerts.
Network analysis – Inspects mirrored SPAN traffic for intrusion signs.
Built-in sandbox – Detonates suspicious files in isolated virtual machines.
Endpoint EDR – Agent ships inside Kaspersky Endpoint Security for Windows.
Private intelligence – Optional Kaspersky Private Security Network keeps data internal.
Important note – Endpoint protection licences are not included here.
Central Node server – On-premises core that stores alerts and runs analysis.
Network traffic analysis – Inspects mirrored SPAN, ERSPAN and RSPAN traffic using IDS rules.
Advanced sandbox – Detonates files and URLs in configurable Windows virtual machines.
KEDR endpoint block – Endpoint telemetry, IOC scanning and remote response actions.
Threat intelligence feeds – KSN or Private Security Network reputation data, MITRE ATT&CK mapping.
Important – Endpoint protection licences are not included; buy Kaspersky Endpoint Security separately.
This is an on-premises anti-APT platform that combines network traffic analysis, sandboxing and endpoint detection and response in one self-hosted web console. The endpoint side is the KEDR functional block, marketed earlier as Kaspersky EDR Expert, a name still found in older documentation and partner listings.
One alert queue – Network and endpoint detections land in the same console.
No cloud dependency – Runs inside your own data centre, not a vendor tenant.
Unmanaged device visibility – Network sensors see hosts that carry no agent.
Faster containment – Isolate a host or block a file from the console.
Reusable investigation evidence – Alert reports and session tables export for incident files.
Third-party EPP support – EDR Agent runs alongside another vendor endpoint suite.
Kaspersky positions this platform for large enterprises with a security operations team and for mid-sized organisations that keep threat data inside their own infrastructure for regulatory or privacy reasons. The deciding factor is not headcount but whether someone reviews alerts daily: the platform raises detections and offers response actions, it does not triage on your behalf.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | By sector |
| NIS 2 in the European Union | Rare | By sector | By sector |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Own staff to triage alerts daily | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The reporting obligation introduced by the revised Information Security Act applies to operators of critical infrastructure, for example energy and drinking water suppliers, transport companies, listed hospitals, data centre and cloud providers, and cantonal and municipal administrations, not to every Swiss company. Those operators must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with missing details permitted afterwards. What this platform contributes is the detection and the substance of that first report: an alert names the affected hosts, the network sessions involved and the mapped MITRE ATT&CK technique, and alert reports can be exported and attached to the incident file. What it does not do is judge whether an incident meets the reporting threshold, submit anything to BACS, or supply the organisational side, so you still need a named responsible person, an escalation path that runs outside office hours, and a written record of the reportability decision. It also has no bearing on the separate data protection notification duty, which follows its own criteria. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with legal counsel or directly with BACS.
No security product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, processes and evidence rather than tooling. NIS 2 requires measures in defined categories: risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and maintenance including vulnerability handling, procedures to assess whether measures work, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication or secured communications. This platform maps onto incident handling and detection, and it feeds the effectiveness-assessment category because alerts, network session tables and response actions are logged and exportable to a SIEM. It contributes nothing to cryptography, multi-factor authentication, access control, training, business continuity or supply chain assessment, and it does not perform vulnerability scanning or patching, so those categories must be covered by other tools and by documented process.
The US Department of Commerce, Bureau of Industry and Security, announced a Final Determination on 20 June 2024 that prohibits Kaspersky from entering new agreements with US persons from 20 July 2024 and, from 29 September 2024, from supplying signature or codebase updates, operating the Kaspersky Security Network in the United States, or having its software resold or integrated by third parties. Three Kaspersky entities were added to the Entity List, and the US Treasury designated members of the company leadership on 21 June 2024. In Germany, the Federal Office for Information Security issued a warning in March 2022 recommending that Kaspersky products be replaced, and confirmed after the US announcement that the warning still stands; Germany did not impose a sales ban. Italy and the Netherlands have restricted Kaspersky in government procurement rather than in general trade, and Switzerland has issued no sales ban or purchase restriction, so the products are sold and updated normally here and across the European Union. Kaspersky rejects the US determination as a geopolitical rather than a technical assessment and has pursued legal avenues; it points to its Global Transparency Initiative, under which threat data shared by European users is processed in two data centres in Zurich and source code can be reviewed in its Transparency Centres. In practice this matters if you hold US public sector contracts, operate US entities, bid for public tenders in countries with procurement restrictions, or answer supplier questionnaires that ask about vendor country of origin; for a Swiss private-sector buyer with no US nexus, no restriction currently applies.
Yes, for the detection and response block, and not much beyond it. It answers items on endpoint detection and response coverage, network intrusion detection, malware sandboxing, threat intelligence enrichment, log export to a SIEM in common event format, documented response actions such as host isolation, and asset visibility, since the network map and shadow IT detection surface devices that carry no agent. It answers none of the following: patch management, disk and removable media encryption, multi-factor authentication, backup and restore, vulnerability scanning, access management, security awareness training, and round-the-clock monitoring coverage, because the platform detects but nobody is watching it outside your own working hours. Within the Kaspersky range those gaps close through Kaspersky Endpoint Security for Business for patch and encryption management and Kaspersky MDR for continuous monitoring, and staying with one vendor keeps a single console and one export format for evidence, which is usually the cheaper route compared with adding a second management stack.
The single decisive difference is whether the endpoint block is licensed at all: only the top tier includes endpoint detection and response, and without it you get network-level detection with no agent telemetry and no endpoint response actions. Kaspersky currently describes three tiers, with the network sandbox present in all of them and the NDR feature set stepping up in the middle tier. Retail listings still carry the older edition ladder, and the Enterprise EDR Edition name refers to the configuration in which both the KATA network block and the KEDR endpoint block are active. All tiers are deployed on your own infrastructure; none of them is a cloud-hosted service.
| Capability | KATA | KATA NDR Enhanced | KATA Ultra |
|---|---|---|---|
| Network sandbox | ✓ | ✓ | ✓ |
| NDR feature set | Essential | Advanced | Advanced |
| Endpoint EDR block | ✕ | ✕ | ✓ |
| Endpoint response actions | ✕ | ✕ | ✓ |
| Deployment | On-premises | On-premises | On-premises |
The most consequential restriction is regional: following the US Bureau of Industry and Security determination, Kaspersky software cannot be newly sold to US persons and has received no signature or codebase updates in the United States since 29 September 2024, so a Swiss or European group with US entities cannot standardise on this platform across the whole organisation, and retail listings are additionally sold as region-specific editions. Platform coverage is uneven: the endpoint agent is built into Kaspersky Endpoint Security for Windows and Linux, the standalone EDR Agent configuration that coexists with a third-party endpoint suite is a Windows feature, and mobile devices are not covered at all. Deployment is a network engineering task rather than a software install, because the platform needs traffic mirrored to it from a switch, packet broker or network tap before it detects anything on the network side. The EDR Agent configuration carries no protection or control components, so prevention still comes from Kaspersky Endpoint Security or another endpoint suite. The follow-up purchases that catch buyers out most often are endpoint protection licences, patch and encryption management, and a managed service if alerts need to be watched outside working hours.
No. The endpoint agent collects telemetry and executes response tasks, and in the standalone EDR Agent configuration it has no protection or control components at all. Blocking, device control and application control still come from a full endpoint suite.
Yes. The EDR Agent configuration is designed to coexist with a third-party endpoint protection platform, which lets you add detection and response without replacing an existing vendor. The agent is deployed and integrated through the Kaspersky Security Center console and requires the Network Agent on the target computer.
Threat-related data shared by European users with the Kaspersky Security Network is processed in two data centres in Zurich. Organisations that cannot send anything outside their own infrastructure can use Kaspersky Private Security Network instead, which keeps the reputation database local.