What are the key advantages of Kaspersky Endpoint Detection and Response Optimum Add-on?
Console managed – Runs in Kaspersky Security Center Web Console.
Guided response – Isolate the host and block file execution.
IoC scanning – Import custom indicators and scan all endpoints.
Root cause – Shows how the threat reached the device.
Automated actions – Response triggers automatically when an IoC matches.
Important note – Requires an existing Kaspersky Endpoint Security licence.
EDR Optimum component – Activates the EDR module inside Kaspersky Endpoint Security.
Alert details card – Collects the full picture of one detection for review.
IoC scan tasks – Search endpoints for OpenIOC indicators on a schedule.
Network isolation – Cuts all connections on a host except defined exclusions.
Execution prevention – Blocks a file by checksum or path mask.
Important – Contains no protection engine, the base licence stays required.
This add-on is a licence extension that switches on the EDR Optimum component inside an existing Kaspersky Endpoint Security installation and is managed from Kaspersky Security Center Web Console or Cloud Console. Kaspersky also sells the same functionality pre-bundled as Kaspersky Next EDR Optimum, and buyers still searching for Kaspersky Endpoint Security for Business will find that name on the base licence this add-on attaches to.
No second console – The EDR views appear in Kaspersky Security Center.
Keeps the existing agent – No separate sensor is deployed to the endpoints.
Faster triage – One card shows process origin, hashes and connections.
Retroactive hunting – Rescan the estate after a new hash becomes public.
Contain without travel – Isolate a remote branch device from the console.
Broad agent reach – Windows, Linux, macOS and Windows Server endpoints are covered.
The add-on is built for organisations that already run Kaspersky Endpoint Security and have at least one person who reads alerts, but no security operations centre. Below that level the guided response actions still work, but nobody is watching the queue. Above it, teams usually want the deeper telemetry and threat hunting of the Expert tier.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Existing Kaspersky Endpoint Security base licence | Required | Required | Required |
| This product fits | Limited | ✓ | Partial |
The obligation applies to operators of critical infrastructure, not to every company: since 1 April 2025 the revised Information Security Act requires them to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and failure to report has been sanctionable since 1 October 2025. This add-on supports that deadline in one narrow way, because the alert card gathers the process origin, file hashes and network connections of a single detection in one place, which is the substance a first report needs. An IoC scan across all managed endpoints then answers the second question every report raises, namely how far the incident spread. It does not cover the rest: it does not determine whether your organisation counts as an operator of critical infrastructure, it does not submit the report, it keeps no long-term event archive for the detailed follow-up due within 14 days, and it produces no evidence for anything outside the endpoint such as network or identity systems. This text is not legal advice, and whether the reporting obligation applies to your organisation should be clarified with qualified legal counsel.
No software product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational risk management and a tool can only support individual measures. NIS 2 names measure categories including incident handling, cyber hygiene, business continuity and backup management, supply chain security, cryptography, access control and multi-factor authentication. This add-on works inside the incident handling category: detection with root cause analysis, containment through network isolation of the affected host, and blocking further execution by checksum or path mask. It contributes nothing to business continuity and backup, supply chain security, cryptography or multi-factor authentication, and it does not produce the written policies and processes the directive expects around those measures. Entities in scope also need reporting timelines and documented management accountability that no endpoint tool generates on its own.
Two official assessments are relevant and both are still in force. Germany's Federal Office for Information Security (BSI) issued a warning against the use of Kaspersky antivirus software on 15 March 2022; the warning has been maintained and, since the amendment that took effect on 6 December 2025, is regulated under Section 13 of the BSI Act. Its reasoning concerns the reliability and authentic capacity to act of the manufacturer rather than a published finding of a technical defect in the code. Separately, the US Department of Commerce issued a final determination on 20 June 2024 prohibiting Kaspersky from new agreements with US persons from 20 July 2024 and from supplying signature and codebase updates or operating the Kaspersky Security Network in the United States from 29 September 2024. Kaspersky rejects the German warning as unjustified and not based on an objective technical analysis, and points to its Global Transparency Initiative, source code review and the relocation of threat data processing for European users to two data centres in Zurich. In Switzerland the Federal Office for Cybersecurity has issued neither a warning nor a sales prohibition and has stated that no misuse of the software has been reported to it. Practically, this affects three groups: any buyer with a US nexus, who cannot be supplied at all; public sector bodies and their suppliers in Germany, where the warning is treated as authoritative in risk assessments; and any company whose large customers apply country-of-origin clauses in supplier questionnaires. Everyone else makes their own risk decision.
Partly, and in a predictable set of places. It answers the items on endpoint detection capability beyond signature-based antivirus, on the ability to isolate a compromised host, on root cause analysis, on indicator-of-compromise sweeps across the estate, and on centralised management with role-based access through Kaspersky Security Center. It answers none of the items on backup and restore, on encryption of laptops and removable media, on patch status of third-party software, on multi-factor authentication, on mobile device management, or on log retention and SIEM export, because those functions sit outside this add-on. It also does not answer questionnaire items asking for 24x7 monitoring by named analysts, since there is no managed service included. To close those gaps, staying inside the same vendor family is usually cheaper than mixing suppliers: patch and encryption management come with the Kaspersky Next bundles, monitoring comes with the MDR add-on, and deeper telemetry with SIEM integration comes with the Expert tier. Expect the country-of-origin question in the same questionnaire and prepare an answer for it in advance.
The decisive difference is where you manage it: EDR Optimum runs in either the on-premises Kaspersky Security Center Web Console or the Cloud Console, while EDR Expert can only be managed from the Cloud Console. That single fact rules Expert out for organisations that must keep management on their own infrastructure. The second difference is combination: the EDR Optimum component can be licensed together with Managed Detection and Response through a combined add-on key, whereas the EDR Expert component is incompatible with the MDR component. The two EDR components are also mutually exclusive on the same endpoint, so this is a choice, not a stacking exercise.
| Property | EDR Optimum Add-on | EDR Expert Add-on |
|---|---|---|
| On-premises Web Console management | ✓ | ✕ |
| Cloud Console management | ✓ | ✓ |
| Can be combined with MDR | Combined key | ✕ |
| IoC scan and network isolation | ✓ | ✓ |
| Separate base EPP licence needed | Required | Required |
| Availability to US persons | Prohibited | Prohibited |
The clearest regional limitation is the United States: since the Commerce Department determination, Kaspersky cybersecurity products may not be supplied to US persons, which matters for Swiss and European companies with US subsidiaries or US-based staff. On the technical side, the EDR Optimum component cannot coexist with the EDR Expert component or with the Endpoint Detection and Response component of Kaspersky Anti Targeted Attack on the same endpoint, so an existing KATA deployment blocks this add-on. Management requires Kaspersky Security Center 13.2 or later and is not possible in the MMC Administration Console, and on endpoints still running Kaspersky Endpoint Security for Windows 11.6 or older the separate Kaspersky Endpoint Agent has to be installed first. The EDR component also depends on other protection components being active, including File Threat Protection, Behavior Detection, Exploit Prevention, Host Intrusion Prevention, Remediation Engine and Adaptive Anomaly Control, so a policy that disables them silently disables the detection quality this add-on relies on. The follow-up purchases that most often appear afterwards are patch management, encryption management and backup, because none of them are part of this licence.
Not on current builds. Endpoints running Kaspersky Endpoint Security for Windows 11.7 or later use the built-in EDR Optimum component, while devices on version 11.6 or earlier require Kaspersky Endpoint Agent to be installed before the response actions work.
Yes, but only with the right key. Kaspersky Endpoint Security accepts just one active key for MDR and EDR Optimum licensing, so both solutions together require the combined add-on key rather than two separate ones.
Suspicious and malicious files that European users voluntarily submit to the Kaspersky Security Network are processed and stored in two data centres in Zurich, Switzerland, following the relocation Kaspersky carried out under its Global Transparency Initiative.