What are the key advantages of Kaspersky DDoS Protection Standard Level?
Cloud service – Managed centrally from the Kaspersky web portal.
Traffic scrubbing – Malicious packets filtered before reaching your server.
Layer coverage – Filtering across network, transport and application layers.
Attack capacity – Standard tier absorbs up to 10 Gbps.
Instant alerts – Notifications by SMS, email, Telegram or webhook.
Important note – No API access or load balancing at Standard.
Download: Kaspersky DDoS Protection Standard Level
Cloud traffic scrubbing – Filtering of L3, L4 and L7 attack traffic.
Always-On and On-Demand – Two modes, continuous filtering or redirection during attacks.
Reverse proxy – Your origin server IP address stays hidden from attackers.
Bot filtering – Automated requests checked by CAPTCHA and JS Challenge.
Attack notifications – Alerts sent by SMS, email, Telegram or webhook.
Important – Standard omits API access and traffic load balancing.
Kaspersky DDoS Protection Standard Level is the entry service tier of Kaspersky's cloud DDoS scrubbing platform, run from a web portal instead of being installed on your servers. Kaspersky sold a simplified variant of the same service as Kaspersky DDoS Protection Connect, a name buyers still search for.
No hardware purchase – Filtering happens in Kaspersky scrubbing centres, not on site.
Fast switch-over – DNS switching moves traffic without rebuilding your servers.
Origin address hidden – Attackers cannot reach the server behind the proxy.
Staffed monitoring – Kaspersky operates a security operations centre around the clock.
Availability checks – Service failures detected within sixty seconds and notified.
Free TLS certificate – Let's Encrypt certificate issued for the protected domain.
The deciding factor is not headcount but the size of attack your public services have to survive. Standard is scoped for one low-load resource, which fits a small company with a single website and starts to strain as soon as several domains or higher attack volumes are in play.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | ✓ | ✓ |
| Security questionnaire from large customers | Rarely | ✓ | ✓ |
| Attack volume above 10 Gbps expected | ✕ | Possible | ✓ |
| This product fits | ✓ | Limited | ✕ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, and since 1 April 2025 those operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. A DDoS attack that disrupts the operation of critical infrastructure falls inside that obligation, so the practical question is how fast you notice and how precisely you can describe what happened. Kaspersky DDoS Protection Standard Level supports the detection half of that: availability monitoring flags a service failure within sixty seconds, alerts go out by SMS, email, Telegram or webhook, and the personal account holds attack records you can use to fix the start time in your report. It does not support the rest, because it sees nothing on your endpoints or servers, so ransomware, data manipulation and extortion incidents stay outside its view, and at the Standard tier there is no API to feed events into your own logging. It also does not file the report for you and does not produce the fuller follow-up detail due within fourteen days; that work stays with your team. This text is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product makes an organisation NIS 2 compliant, because the directive addresses how an organisation manages risk rather than what it buys. NIS 2 sets out categories of measures that include incident handling, business continuity, supply chain security, network and information system security, access control and multi-factor authentication, cryptography, and cyber hygiene. Kaspersky DDoS Protection Standard Level maps onto two of them: business continuity, by keeping an internet-facing service reachable while it is being flooded, and incident handling, by detecting availability incidents and alerting on them. It contributes nothing to access control, multi-factor authentication, cryptography, vulnerability handling or staff training, and it produces no evidence about any of those areas. Supply chain security is the one category where this product becomes the question rather than the answer, because the service carries your production traffic and your own customers may ask where it is operated from.
Germany's Federal Office for Information Security (BSI) issued a warning on 15 March 2022 recommending that Kaspersky virus protection software be replaced with alternative products. The BSI states expressly that it made no assessment of other Kaspersky products, and this DDoS scrubbing service is not virus protection software. The warning is still in force, and since 6 December 2025 it has been anchored in Section 13 of the amended BSI Act following the German NIS 2 implementation. Separately, the United States Department of Commerce prohibited the sale of Kaspersky software and the supply of updates in the US market, with the restriction on updates and resale taking effect on 29 September 2024. Kaspersky's own position is that these decisions are political rather than technical, that it is a privately held company with no government ties, and that data processing for European customers was moved to Zurich in 2018 with source code available for inspection in its Transparency Centres. Independent laboratory scores from AV-TEST and AV-Comparatives concern Kaspersky's endpoint products and say nothing about this scrubbing service in either direction. One fact specific to this service belongs in the same picture: the operating company named on the Kaspersky DDoS Protection site is LLC Shield Mode, a wholly owned subsidiary of AO Kaspersky Lab registered in Moscow. In Switzerland and the European Union the product can be bought and used legally; the buyers actually affected are those bidding for public-sector contracts, supplying German federal bodies, or answering supply chain requirements from US-linked customers.
Partly, and only in one column of the questionnaire. It answers the availability items cleanly: yes, DDoS mitigation is in place at network, transport and application layer; yes, there is a stated availability figure of 97.5 percent at this tier; yes, monitoring is staffed around the clock; yes, incidents trigger automatic notification by SMS, email, Telegram or webhook. It answers nothing about endpoint protection, multi-factor authentication, encryption at rest, patch management, backup and restore testing, vulnerability management or security awareness training, and at the Standard tier the absence of API access means you cannot demonstrate automated log export into a SIEM. Questionnaires from regulated customers increasingly ask about vendor country of origin and sub-processor location, and this product does not give you a comfortable answer on that item. For the technical gaps, moving up to Business premium or Enterprise inside the same Kaspersky family is usually cheaper than adding a second scrubbing vendor, because it adds API access and a higher availability figure without a second integration. For the origin question, no tier changes the answer, so if that item is a hard requirement in your largest customer's questionnaire, settle it before you buy rather than after.
The single most decisive difference is API access, which Standard does not include and both higher tiers do. Everything else follows the same pattern: attack volume, availability figure and the number of domains you can put behind one resource all rise with the tier. The figures below are the ones Kaspersky publishes for the website protection line. The individual IP and services line uses its own Standard, Business and Premium naming with different numbers, starting at 3 Gbps filtration capacity over a DNS proxy connection, so confirm which line your quote refers to before comparing prices.
| Feature | Standard | Business premium | Enterprise |
|---|---|---|---|
| Resource availability | 97.5% | 99.5% | 99.9% |
| Attack volume | 10 Gbps | 100 Gbps | 500 Gbps |
| Domains per resource | 1 | 4 | 10 |
| API access | ✕ | ✓ | ✓ |
| Traffic load balancing | ✕ | 4 upstreams | 10 upstreams |
| CDN cache | 100 GB | 5 000 GB | 10 000 GB |
Standard is scoped for one low-load resource: a single domain with one subdomain, ten allow and deny list entries, no API access, no traffic load balancing, and an availability figure of 97.5 percent rather than the 99.5 or 99.9 percent of the higher tiers. The attack volume covered is 10 Gbps on the website protection line and 3 Gbps on the individual IP and services line, both of which sit below the size of many current volumetric attacks, so check the attack profile you actually need to survive before choosing this tier. On regional availability, the dedicated Kaspersky DDoS Protection site is published in English, Turkish, Vietnamese and Portuguese only, no German, French or Italian, the operating company is registered in Moscow, and the European scrubbing centres Kaspersky names date from its 2014 European launch in Frankfurt and Amsterdam, so ask in writing which scrubbing centre would carry Swiss traffic before you sign. This is not antivirus, endpoint or server protection: it defends the reachability of an internet-facing service and nothing else, and the Web Application Firewall is sold as a separate product rather than being part of this plan. The most common follow-up purchase is simply the next tier up, usually bought because someone needed the API.
No. It is a cloud service that filters attack traffic in Kaspersky scrubbing centres before that traffic reaches your infrastructure. It installs nothing on workstations or servers and detects no malware.
At Standard the protocol coverage is HTTP and HTTPS. Protecting mail, DNS, VPN or other TCP and UDP services means moving to a higher tier or to the individual IP and services line, where broader protocol support is listed.
For the standard cloud connection, no: you switch the DNS A record to an IP address issued by Kaspersky. An optional on-premise Sensor, running on an x86 server or virtual machine, is used for application-layer inspection when you cannot share a TLS certificate.