What are the key advantages of Kaspersky Endpoint Detection and Response Expert Base Plus?
Central console – One platform manages every endpoint agent and policy.
Advanced detection – LoA rules and MITRE ATT&CK mapping per incident.
Built-in sandbox – Detonates suspicious files in managed virtual machines.
Remote response – Isolate hosts, terminate processes, collect forensic evidence.
Patch management – Vulnerability assessment plus third-party and operating system patching.
Important note – No email, cloud or SIEM telemetry included.
Endpoint protection platform – Multi-layered anti-malware, behaviour detection and exploit prevention per agent.
Advanced EDR telemetry – Endpoint data collection with IoA rules and MITRE ATT&CK mapping.
Built-in advanced sandbox – Detonates suspicious files inside managed virtual machine templates.
Hunting and forensics – YARA rules, IoC search, memory dumps and disc images.
Patch and encryption management – Vulnerability assessment, third-party patching and central encryption policies.
Important – No email, cloud or SIEM telemetry; endpoint sources only.
This is the enterprise EDR tier of the Kaspersky Next line, managed centrally from the Open Single Management Platform console, which can run cloud-based or as an offline console in air-gapped environments. The Kaspersky Next line replaced the earlier Kaspersky Endpoint Security for Business editions, and in certain markets the same solution is sold under the name Kaspersky Symphony EDR Expert.
Single agent – One agent delivers prevention, telemetry and response actions.
Root cause analysis – Reconstructs the attack chain instead of isolated alert cards.
Remote response actions – Isolate hosts, terminate processes and execute commands centrally.
Swiss data processing – European threat data is processed in two Zurich data centres.
Retrospective analysis – Re-checks stored telemetry when new indicators become known.
Open platform integration – Exports events and connects through documented API workflows.
The deciding factor is not headcount but whether someone in the organisation reads alerts. Kaspersky positions this tier for organisations with internal IT security expertise or a security operations function, because the sandbox verdicts, IoA detections and forensic artefacts only produce value if a person triages them.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Own analysts to triage detections | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure, not to every company. Since 1 April 2025 the revised Information Security Act (ISG) requires these operators to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. This product supports that deadline in one concrete way: endpoint telemetry, root cause analysis and MITRE ATT&CK mapping give you the attack chain, the affected hosts and the time of first execution, which is what a report needs, rather than a single alert without context. What it does not do is judge whether an incident is reportable, write the report, or see attack paths that never touch an endpoint, such as a compromised mailbox or a cloud account takeover. This text is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.
No product makes a company NIS 2 compliant, because the directive addresses governance, processes and risk management rather than tooling. NIS 2 requires in-scope entities to implement measures across risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, cryptography, human resources security, access control and asset management. This product contributes to incident handling through detection and response workflows, to vulnerability handling through vulnerability assessment and patch management, to cryptography through encryption management, and to asset management through hardware and software inventory. It contributes nothing to business continuity and crisis management, supply chain security, human resources security or staff awareness training, and the awareness platform available in lower Kaspersky Next tiers is not part of the Expert level. Reporting exists, but the log management and cross-correlation layer that auditors often ask for sits in Kaspersky Next XDR Expert rather than here.
In Switzerland, the Federal Office for Cybersecurity (BACS, previously NCSC) has issued no product warning. Its published position is that it does not make recommendations on the use of specific products, that it is aware of no misuse of Kaspersky software, and that it would inform the public if it had evidence. In Germany, the Federal Office for Information Security (BSI) issued a formal warning in March 2022 recommending replacement of Kaspersky antivirus products, and confirmed in 2026 that this warning still stands; Italy and the Netherlands have restricted government procurement only. None of these is a sales ban, and the products remain sold and updated in Switzerland, the European Union and the United Kingdom. In the United States the position differs: in June 2024 the Department of Commerce Bureau of Industry and Security issued a Final Determination prohibiting new sales from 20 July 2024 and signature and code-base updates to US customers from 29 September 2024. Kaspersky's stated position is that these decisions are political rather than the result of a technical assessment of its products, and it points to its Global Transparency Initiative, under which threat-related data from European users is processed in two data centres in Zurich. Independent test laboratories have continued to test and certify Kaspersky products throughout this period. In practice this matters most if you bid for public sector contracts, work under supply chain requirements that name product origin, or have US entities or US-based staff in scope; for a purely Swiss or EU commercial deployment there is no legal obstacle.
Yes, for the endpoint sections, and not at all for several others. It answers questions on endpoint threat detection and response capability, malware and ransomware prevention, host isolation and containment, vulnerability scanning and third-party patching cadence, disc and removable media encryption, application and device control, hardware and software asset inventory, and the availability of forensic artefacts after an incident. It does not answer questions on email filtering and phishing protection, cloud workload or container security, backup and restore capability, tested recovery times, centralised log retention periods, SIEM correlation, 24/7 monitoring coverage, or documented security awareness training for staff, because none of those components is included at this tier. It also will not answer questions about vendor origin and jurisdiction, which increasingly appear in supply chain sections and need a written company position rather than a product feature. To close the technical gaps, moving up to Kaspersky Next XDR Expert within the same family is usually cheaper and less disruptive than adding a second vendor, since it brings email security, hybrid cloud security, log management and correlation, and playbook-driven response into the same console; a separate backup product and a documented awareness programme still have to be sourced independently.
The single decisive difference is the data sources. EDR Expert sees endpoints and nothing else, while XDR Expert adds telemetry from email, hybrid cloud workloads and third-party systems, and correlates it centrally. Both tiers share the same endpoint agent, the same detection engines and the same built-in advanced sandbox, so the endpoint capability itself is not what you gain by moving up. What you gain is cross-source correlation, log management, formal case handling with service levels, and playbook automation instead of manually chained response tasks. If your analysts already spend their time pivoting between the endpoint console and a separate mail or cloud console, that is the signal to compare the two tiers seriously.
| Capability | Next EDR Expert | Next XDR Expert |
|---|---|---|
| Endpoint detection and response | ✓ | ✓ |
| Built-in advanced sandbox | ✓ | ✓ |
| Forensic toolkit | Windows only | Windows only |
| Email security | ✕ | ✓ |
| Hybrid cloud workload security | ✕ | ✓ |
| Log management and cross-correlation | ✕ | ✓ |
| Playbooks and case management | ✕ | ✓ |
| Third-party connectors | API and export | 250+ connectors |
Two of the most useful Expert-level capabilities are Windows-only: the forensic toolkit that collects process and memory dumps, disc images and registry keys, and YARA rule scanning. On Linux and macOS the agent protects, but the deep investigation surface is smaller and some response actions are unavailable, which matters if your crown-jewel workloads sit on Linux servers. Kaspersky also states that feature availability varies with the deployment method, so a cloud-managed rollout and an on-premises or air-gapped rollout will not expose an identical feature set, and this should be confirmed against your intended architecture before purchase. The managed detection service and the automated security awareness platform found in other Kaspersky Next tiers are not included at the Expert level and are the two most common follow-up purchases. On regional availability, the reverse of the usual pattern applies: the product is sold and updated normally in Switzerland, the European Union and the United Kingdom, but a United States prohibition means it cannot be supplied to US customers or US persons, which is a real constraint for groups with American subsidiaries.
This is a base licence, so it does not require an existing licence of the same product to be in place. Its functional scope is that of Kaspersky Next EDR Expert, which includes the endpoint protection platform rather than sitting on top of a separate one.
No. The 24/7 monitoring, threat hunting and investigation performed by Kaspersky's own security operations centre belong to the managed detection and response offering, which is licensed separately. At this tier your own team owns triage and response.
Kaspersky documents management from a cloud-based central platform and from an offline console for air-gapped environments, both built on the Open Single Management Platform. Air-gapped operation removes automatic access to cloud reputation services, so detection relies more heavily on locally delivered databases and your own rules.