What are the key advantages of Kaspersky DDoS Protection Ultimate Level?
Vendor managed – Kaspersky runs detection and mitigation, you get no console.
EU scrubbing – Attack traffic is filtered in Amsterdam and Frankfurt.
Two modes – Redirection always on or only during attacks.
Non-inline sensor – Watches traffic without sitting in its path.
Attack reports – Dated post-attack analysis for your incident documentation.
Important note – No endpoint, server or mailbox protection included.
Download: Kaspersky DDoS Protection Ultimate Level
Traffic sensor – Runs in your own network or in Kaspersky's cloud.
EU scrubbing centres – Filtering nodes in Amsterdam and Frankfurt remove attack traffic.
Always-On and On-Demand – Traffic is redirected permanently or only during an attack.
Emergency Response Team – Kaspersky specialists monitor anomalies and mitigate attacks around the clock.
Post-attack reporting – Written analysis after each attack for your incident documentation.
Important – No endpoint, server or mailbox protection is included here.
Kaspersky DDoS Protection is a managed cloud service that keeps public-facing services reachable during a denial-of-service attack, and Kaspersky runs detection and mitigation from its own Security Operations Centre, so there is no administration console on your side. Ultimate Level designates the licensed capacity tier, while the redirection scheme is selected separately as KDP Connect, KDP Control or KDP Connect+.
No dedicated appliance – The sensor runs on a standard x86 server or virtual machine.
European scrubbing path – Attack traffic is filtered in Amsterdam and Frankfurt, not overseas.
Managed mitigation – Kaspersky engineers start and tune filtering during the attack.
Non-inline detection – The sensor watches traffic without sitting in its path.
Two redirection routes – DNS-based or BGP-based redirection, chosen to fit your network.
Documented attack history – Post-attack reports record what was filtered and when.
The deciding factor is not headcount but whether you operate public services that lose money or trigger a reporting duty the moment they go offline. A company with a brochure website does not need scrubbing capacity; an online shop, a customer portal, a payment interface or a hosted API does. BGP-based redirection additionally requires your own IP range, which most small businesses do not have.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own IP range for BGP redirection | ✕ | Sometimes | ✓ |
| This product fits | ✕ | Partly | ✓ |
The revised Information Security Act (ISG) has obliged operators of critical infrastructure to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery since 1 April 2025, with 14 days to complete a report that was incomplete at first. This affects energy and water supply, transport, hospitals, finance, telecommunications, cloud and data centre providers, and cantonal and communal administrations, subject to the exemption thresholds in the Cybersecurity Ordinance. Kaspersky DDoS Protection supports that duty in one concrete way: the sensor timestamps the onset of an anomaly and the post-attack report states what was filtered, which gives you the attack type, timing and countermeasures that the report form asks for. It does not support the rest of the obligation, because it sees only network traffic to the protected resources and therefore cannot tell you whether data was manipulated or exfiltrated, whether the attack was accompanied by extortion, or whether an intrusion went undetected elsewhere in your environment. The duty also attaches to the organisation, not the software, so someone must be assigned to file within 24 hours regardless of which tools are in place. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product makes a company NIS 2 compliant, because the directive addresses organisational measures and management accountability rather than software features. NIS 2 requires entities in scope to maintain risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, security in the acquisition and maintenance of network and information systems, procedures to assess whether measures work, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. Kaspersky DDoS Protection maps to three of these: it is a network availability measure, it contributes to business continuity by keeping services reachable during volumetric and application-layer attacks, and its post-attack reports feed incident handling documentation. It contributes nothing to cryptography, access control, asset management, multi-factor authentication, staff training, or vulnerability handling on endpoints and servers, and it is itself a supply chain entry that your own risk assessment must cover. Buyers in scope should treat this licence as one measure inside a wider programme, not as a compliance building block on its own.
Two official measures concerning the vendor are in force and are relevant to a purchase decision. The German Federal Office for Information Security (BSI) issued a warning about Kaspersky antivirus software on 15 March 2022; it remains published and, following the German NIS 2 implementation act that took effect on 6 December 2025, now sits under section 13 of the BSI Act rather than section 7. The US Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from supplying cybersecurity and antivirus products and services to US persons, with the full prohibition effective 29 September 2024, and added AO Kaspersky Lab, OOO Kaspersky Group and Kaspersky Labs Limited to the Entity List. Kaspersky's own position is that it considers the BSI warning unjustified and not based on an objective technical analysis of its software, and points to its transparency and audit programme. Both measures are worded around antivirus and cybersecurity software rather than around this scrubbing service specifically, and neither authority has published a technical finding about Kaspersky DDoS Protection as such; procurement rules, however, are usually written at vendor level and will not make that distinction for you. In practice this matters most if you bid for public-sector contracts, supply the German federal administration or its suppliers, employ US persons or run US subsidiaries, or answer supply chain questionnaires that screen vendor country of origin. If none of those apply to you, the measures may have no operational effect on your organisation; that assessment is yours to make.
Partly, and it will also create one new question you have to answer. It covers the availability and resilience block directly: you can state that public services sit behind a managed scrubbing service, that detection runs 24/7 from a vendor SOC, that mitigation is either automatic or triggered on your instruction depending on the scheme, and that filtering takes place in EU facilities in Amsterdam and Frankfurt, which answers the data-location question that follows. Post-attack reports give you dated evidence rather than an assertion, which is what most questionnaires actually want. It answers nothing in the endpoint, identity or data blocks: no antimalware coverage, no patch status, no encryption, no multi-factor authentication, no privileged access control, no backup, no awareness training, and no asset inventory. It will also trigger the vendor origin and sanctions screening question in questionnaires from customers with US exposure or public-sector obligations. For the endpoint and management gaps, staying inside the Kaspersky business range is normally the cheaper route than mixing vendors, since one console and one support contract cost less to run than two; the vendor origin question, by contrast, is not solved by any edition change and has to be answered on its merits.
The decisive difference is who starts mitigation and how quickly traffic can move: with Connect and Connect+ mitigation begins automatically when the SOC detects an attack, while with Control you decide when filtering starts, which suits organisations whose change policy does not allow automated rerouting. The second difference is the redirection method, DNS-based for Connect and BGP-based for Control and Connect+, and BGP announcement requires you to control your own IP range. Note that these three are deployment schemes, not capacity tiers; Ultimate Level describes the licensed scrubbing capacity and is selected alongside the scheme, and the reserved bandwidth attached to each Level should be confirmed against the current price list for your region rather than assumed from listings written for other markets.
| Property | KDP Connect | KDP Control | KDP Connect+ |
|---|---|---|---|
| Traffic mode | Always-On | On-Demand | Always-On |
| Redirection method | DNS | BGP | BGP |
| Clean traffic delivery | Proxy or GRE | GRE | GRE |
| Mitigation start | Automatic | You decide | Automatic |
| Own IP range required | ✕ | ✓ | ✓ |
The service is not available to US persons: the Commerce Department prohibition covers US citizens and residents wherever they are located, so a Swiss or EU group with a US subsidiary or US-based staff has to check its own exposure before signing. Kaspersky operates its cleaning centres in Amsterdam and Frankfurt, so there is no scrubbing facility in Switzerland and Swiss traffic is filtered inside the EU during an attack, which is the point most Swiss data protection reviews raise first. The protection scope stops at the network edge: everything on your endpoints, servers and mailboxes is out of scope, so a ransomware infection or a compromised administrator account is unaffected by this licence. Kaspersky lists WAF, bot protection and caching as separate technologies within the DDoS Protection line, and whether they are part of your specific package should be confirmed in writing with the distributor rather than inferred from the product page. The most common follow-up purchases are endpoint protection and a WAF, in that order.
Not necessarily. Kaspersky offers filtering of HTTPS traffic without disclosure of the SSL certificate, and where certificate sharing is not possible the alternative is an on-premises sensor in your own infrastructure with traffic returned via GRE tunnels or dedicated lines. Clarify which of the two applies to your setup before the contract is signed, because it determines what your security review has to approve.
No. The sensor is non-inline: it observes traffic and builds behavioural profiles without intercepting it, so a sensor failure does not take your services down the way an inline appliance can. It runs on a standard x86 server or a virtual machine, or alternatively inside Kaspersky's DDoS Protection cloud.