What are the core benefits of Kaspersky DDoS Protection Ultimate+ Level?
Fully managed – Kaspersky operates detection and mitigation, no customer console.
Clean traffic – Up to 2 Gbit/s reserved for legitimate traffic.
EU scrubbing – Cleaning centres in Amsterdam and Frankfurt.
Flexible redirection – Always-on or only during a confirmed attack.
Incident reports – Attack and resource reports document each mitigation.
Important note – No endpoint, server or email protection included.
Managed scrubbing service – Kaspersky filters attack traffic in its own cleaning centres.
Clean traffic reserve – Up to 2 Gbit/s of legitimate traffic is covered.
European cleaning centres – Scrubbing runs in Amsterdam and Frankfurt, inside the EU.
Always-On and On-Demand – Redirect traffic permanently or only during a confirmed attack.
Emergency Response Team – Kaspersky engineers confirm attacks and adjust filters around the clock.
Important – No endpoint, email or server protection is included here.
Kaspersky DDoS Protection Ultimate+ Level is a managed mitigation service rather than software you install and administer: Kaspersky runs the detection sensor, the scrubbing infrastructure and the response desk, and there is no console for your team to operate. Ultimate+ is the highest of three service levels, and what separates it from Standard and Ultimate is the volume of clean traffic reserved for you and the service level attached to it.
No filtering appliance – You avoid buying and running on-premises scrubbing hardware.
Headroom for peaks – The 2 Gbit/s reserve suits busy public-facing services.
Redirection stays your call – On-Demand mode leaves normal routing untouched until you switch.
Longer post-attack window – Filtering continues 36 hours after the attack stops.
Reports as evidence – Attack and resource reports document timing, scale and response.
Staffed detection desk – Your admins are not the ones watching traffic.
This is a top-tier service level built around a 2 Gbit/s clean-traffic reserve. That capacity only earns its cost when a public-facing service carries real sustained traffic and an outage has a measurable price, which in practice means larger organisations and availability-critical mid-sized ones. Kaspersky positions the solution for financial services, insurance, retail, government, telecommunications and e-commerce.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Clean traffic above 300 Mbit/s | ✕ | Rarely | ✓ |
| This product fits | ✕ | Partial | ✓ |
The reporting obligation in the revised Information Security Act (ISG) has applied since 1 April 2025, and it covers operators of critical infrastructure — energy and drinking water supply, transport, listed hospitals, data centre and cloud providers, cantonal and communal administrations — not every Swiss company. Affected organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the notification. A DDoS attack falls under this when it threatens the operating capability of the critical infrastructure or comes with an extortion demand, which is the usual pattern in ransom DDoS. Ultimate+ supports the notification concretely: the attack and resource reports supply the detection time, the attack type, the affected resources and the mitigation applied, which are the fields the notification asks for. It does not tell you whether you are in scope, does not detect data outflow or manipulation, covers nothing that does not arrive as network traffic, and does not file anything on your behalf — the 24-hour clock and the internal escalation path stay with you. This text is product information and not legal advice; whether your organisation is subject to the reporting obligation should be clarified with qualified legal counsel.
No product makes an organisation NIS 2 compliant, because the directive obliges the entity and its management, not the software it buys. The measure categories NIS 2 requires span risk management and security policies, incident handling, business continuity including backup and crisis management, supply chain security, vulnerability handling, cryptography, access control and multi-factor authentication. Ultimate+ contributes to two of them: incident handling for a single attack class, and the continued availability of internet-facing services during a volumetric or protocol attack. It plays no part in backup and restore, vulnerability handling, access control, multi-factor authentication, cryptography, asset management or staff training, and it produces no evidence about any of those. The directive also expects entities to notify significant incidents and to show that measures were taken; the reports document one mitigated DDoS incident and say nothing about the rest of your environment.
Germany's Federal Office for Information Security (BSI) issued a public warning against the use of Kaspersky antivirus software in March 2022; it is the only product warning of its kind the BSI has published, it was moved to Section 13 of the amended BSI Act on 6 December 2025, and the BSI confirmed in 2026 that it is maintaining it. The US Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from providing cybersecurity and antivirus products or services to US persons, with new transactions barred from 20 July 2024 and updates, resale and integration from 29 September 2024. In Switzerland the position differs: BACS does not issue recommendations on the use of individual products, has stated that no misuse of Kaspersky software has been reported to it, and there is no ban or federal directive; a Swiss purchase is therefore not restricted by law. Kaspersky rejects the BSI assessment as political rather than technical, has demanded its withdrawal and reserved legal steps, and points to its transparency programme, including data processing in Switzerland and a Transparency Center in Zurich. Two practical notes: the BSI warning is worded against antivirus software, a category this network-level scrubbing service does not belong to, and the independent test results usually cited for Kaspersky come from endpoint antivirus laboratories, which do not test DDoS mitigation services — so no comparable independent results exist for this product either way. In practice this matters most for public sector tenders, suppliers to German public bodies, organisations with US entities or US-facing services, and anyone whose customers ask about vendor country of origin in supply chain questionnaires; buyers outside those groups face a commercial and reputational decision rather than a legal one.
For a narrow set of items, yes, and clearly. It lets you answer that DDoS mitigation is in place through a named external provider, that scrubbing takes place in Amsterdam and Frankfurt within the EU, that detection and mitigation are staffed 24/7 by the provider rather than by your own on-call rota, that clean-traffic capacity of up to 2 Gbit/s is reserved, and that per-incident attack and resource reports exist as documentation. It answers nothing else. Questions on endpoint protection and EDR, patch management, encryption at rest and in transit, multi-factor authentication, privileged access control, backup and tested restore, vulnerability management, asset inventory, awareness training and your own certification status all remain open, and a questionnaire that scores those sections will not improve because this service is in place. There is no higher edition in this family to close those gaps — Ultimate+ is already the top service level, and the family covers DDoS mitigation only — so the endpoint and identity sections need a separate product, from Kaspersky's own endpoint range or elsewhere. One item worth checking before you commit: a growing number of enterprise questionnaires now ask directly about vendor jurisdiction, and a Kaspersky entry in your supplier list can turn into a follow-up question even where no legal restriction applies.
The decisive difference is the reserved clean-traffic bandwidth: Standard covers up to 100 Mbit/s, Ultimate up to 300 Mbit/s, and Ultimate+ up to 2 Gbit/s. The second difference is how long traffic may run through the cleaning centres. Standard limits this to 72 hours per month during attacks, while Ultimate and Ultimate+ have no monthly cap, which matters if you are targeted repeatedly rather than once. The window after an attack ends also widens across the levels, and the per-resource report is not part of Standard. Note that the reserve describes your legitimate traffic, not the size of attack the cleaning centres can absorb.
| Service level | Standard | Ultimate | Ultimate+ |
|---|---|---|---|
| Reserved clean traffic | Up to 100 Mbit/s | Up to 300 Mbit/s | Up to 2 Gbit/s |
| Scrubbing during an attack | 72 hours per month | Unlimited | Unlimited |
| Scrubbing after the attack ends | 12 hours | 24 hours | 36 hours |
| Per-resource report | ✕ | ✓ | ✓ |
Redirection is not a switch Kaspersky flips alone: you change the DNS A record to the address allocated to you at setup, clean traffic returns through GRE tunnels, and your internet provider has to block traffic to your original address except from Kaspersky's infrastructure — so the ISP has to be brought in before you ever need the service, not during the attack. On-Demand mode also assumes someone on your side is reachable to trigger the switch, and Kaspersky's own description of the on-demand option expects dedicated staff available around the clock, which is why Always-On tends to be the realistic choice for smaller teams. On regional availability the picture is favourable for this shop's markets but not universal: the cleaning centres sit in Amsterdam and Frankfurt, yet the service cannot be supplied to US persons following the US Commerce Department prohibition, so a Swiss or EU group with US entities or US-facing services cannot place those behind it. The reserve figure refers to your legitimate traffic volume, not to the attack size the infrastructure can absorb, so it is not a headline mitigation-capacity number. Finally, protection stops at the network edge — endpoints, mailboxes, file servers and data are untouched by it, and a DDoS event used as cover for a second intrusion will not be caught here.
No. The sensor can be placed either in Kaspersky's DDoS Protection Cloud or on your own premises. Cloud placement removes the on-site component entirely, which is the usual choice for organisations without staff to look after another local system.
In monitoring mode your traffic is delivered directly to your normal addresses and nothing passes through the cleaning centres. The sensor keeps analysing traffic 24/7 to build behavioural profiles of your typical visitors, which is what makes an anomaly recognisable later.
The sensor flags the anomaly and Kaspersky's Emergency Response Team confirms it before you are alerted, so the first judgement call is not made by your administrator at three in the morning. Whether traffic is then redirected remains your decision in On-Demand mode.