What are the key advantages of Kaspersky DDoS Protection Additional Sensor Option?
Vendor operated – Kaspersky monitors and mitigates, no admin console.
Additional sensor – Adds one more detection point to your deployment.
Non-inline monitoring – Watches traffic without sitting in the path.
EU scrubbing – Cleaning centres in Amsterdam and Frankfurt.
Flexible hosting – Runs on x86 server or virtual machine.
Important note – Add-on only, requires the base service..
Additional detection sensor – Extends an existing Kaspersky DDoS Protection deployment with one more sensor.
Non-inline traffic analysis – Monitors traffic continuously without sitting in the data path.
Runs on standard hardware – Installs on an x86 server or a virtual machine.
On-demand detection – On-site sensor is needed for on-demand attack detection mode.
EU cleaning centres – Redirected traffic is scrubbed in Amsterdam and Frankfurt.
Important – Add-on only, requires the base Kaspersky DDoS Protection service.
This option adds a further sensor to an existing Kaspersky DDoS Protection installation, so a second site, uplink or protected subnet is watched by its own detection point. The service itself is operated by Kaspersky: traffic monitoring, attack confirmation and scrubbing run on the vendor side, so there is no on-premises management console for you to administer.
Second monitoring point – Covers an additional site or uplink for anomaly detection.
Faster attack confirmation – More traffic visibility shortens the time before redirection begins.
No inline dependency – A sensor failure does not interrupt production traffic flow.
Separate internet channel – Keeps sending data when the main link is saturated.
Post-attack reporting – Kaspersky provides written analysis after each mitigated attack.
No content access – Kaspersky states the sensor does not inspect traffic payloads.
The deciding factor is not headcount but how your public services are routed. An organisation that announces its own IP range and can redirect traffic by BGP, or move service records by DNS, can use this add-on. An organisation whose website sits on shared hosting cannot, because there is nothing to redirect and no place to install a sensor.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own IP range with BGP or DNS redirection | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The reporting obligation under the revised Information Security Act has applied since 1 April 2025 and affects operators of critical infrastructure, including energy and drinking water supply, transport companies, listed hospitals, cloud and data centre providers, and cantonal and communal administrations. Affected organisations must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. An additional sensor supports that deadline in one narrow way: it records when the traffic anomaly began and how it developed, and Kaspersky supplies post-attack analysis, which is the material a first report needs when the incident is a volumetric attack. It does not help with any other reportable incident type, because it sees network traffic only and produces no record of ransomware, data manipulation or unauthorised data outflow, and it does not submit the report for you. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, risk processes and documented measures rather than software features. NIS 2 requires measure categories including risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, cryptography, access control and multi-factor authentication, and staff security training. This add-on contributes to exactly two of them: business continuity, by keeping public services reachable during a volumetric attack, and incident handling, by detecting the attack and triggering a defined mitigation path with a named response team. It contributes nothing to cryptography, access control, multi-factor authentication, supply chain security, staff training or asset management, and the sensor itself produces no evidence for those areas. Buyers who need the remaining categories must cover them with separate products and documented internal processes.
On 20 June 2024 the US Department of Commerce, through its Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from selling its software in the United States or to US persons. New sales stopped on 20 July 2024, and from 29 September 2024 the resale of Kaspersky software, its integration into other products and services, the delivery of updates, and the operation of the Kaspersky Security Network in the United States were also prohibited. Germany's Federal Office for Information Security issued an advisory in March 2022 recommending that Kaspersky antivirus products be replaced; it is a recommendation rather than a sales ban, and the office confirmed after the US measure that it remains in place. Both measures are still in force. Switzerland has not published a comparable sales ban, and the products remain available in Switzerland and the European Union. Kaspersky rejects the allegations, states that the decisions were taken on geopolitical rather than technical grounds, and points to its Global Transparency Initiative, which includes a transparency centre and data processing facility in Zurich and independent source code review. Independent laboratory results from AV-TEST and AV-Comparatives concern Kaspersky's endpoint products and are not affected by these measures, but there is no equivalent public independent benchmark for this DDoS service, so those results say nothing about it either way. In practice this matters most to three groups: organisations with a US entity or US staff, who are covered by the prohibition; bidders for public sector contracts in countries that restrict Kaspersky in procurement; and suppliers whose large customers exclude Russian-headquartered vendors by contract.
Partly, and only in the availability section. It answers the questions on DDoS mitigation capability, on whether a third-party scrubbing provider is contracted, on detection and escalation for volumetric attacks, and on where mitigation traffic is processed, which is Amsterdam and Frankfurt and therefore inside the European Union. It answers none of the questions on endpoint protection, patch management, encryption of laptops and removable media, multi-factor authentication, backup and restore testing, central log retention or SIEM export, and access control, because the product has no function in those areas. It also does not help with the vendor questionnaire items that ask about the country of origin and ownership of your security suppliers, and on those items adding further Kaspersky products makes the answer harder rather than easier. Where the gaps are technical rather than jurisdictional, covering them within one vendor family is usually cheaper than mixing suppliers, so a higher Kaspersky Next tier is the route to check first; where a customer contract excludes Russian-headquartered vendors, no edition change solves it and a different supplier is the only answer.
This is an add-on and does nothing on its own: without an active Kaspersky DDoS Protection service there is nothing for the sensor to report to. Cleaning centres are located in Amsterdam and Frankfurt, so there is no scrubbing location outside the European Union, and the product cannot be sold to or used by US persons under the US prohibition described above. The sensor needs a separate internet channel of its own, otherwise it stops delivering data at exactly the moment the main uplink saturates, and that channel is a recurring cost buyers frequently overlook at the quotation stage. The sensor detects traffic anomalies and nothing else: ransomware, phishing, credential theft and data exfiltration pass it unnoticed, so endpoint and mail protection remain separate purchases. Finally, in on-demand mode the decision to switch traffic to the redirected route stays with you, which means someone in your organisation has to be reachable and authorised around the clock.
Yes. Kaspersky states that the sensor software runs on a standard x86 server or on a virtual machine, and the virtual machine has to meet the minimum performance figures Kaspersky specifies. No proprietary appliance is involved.
Yes. The vendor dropped the Lab suffix from its brand, so older datasheets, tender documents and forum posts refer to Kaspersky Lab DDoS Protection while the current name is Kaspersky DDoS Protection. The service is the same one.
According to Kaspersky, neither the sensor nor its engineers access the specific content of the traffic; the sensor builds statistical and behavioural profiles to identify anomalies. Confirm this against your own data protection assessment before deployment, particularly for regulated data.
In always-on mode traffic passes through the system continuously and filtering activates automatically, so on-site detection is less critical. The on-site sensor is mandatory for on-demand mode, where the attack has to be detected before traffic is redirected.