What are the key advantages of Kaspersky Endpoint Detection and Response Optimum?
Central console – All devices managed from one cloud console.
Guided response –Isolate a host or block file execution.
Root cause – Visual threat chain shows how infection started.
IoC scanning – Scan all endpoints for known attack indicators.
Patch management – Closes Windows and third-party application vulnerabilities.
Important note – EDR response actions cover Windows devices only.
Endpoint protection – File, web, mail and network protection with behaviour detection.
EDR incident cards – One card per detection with threat development chain graph.
IoC scanning – Import indicators from external sources and scan managed devices.
Vulnerability and patch management – Finds and installs missing Windows and third-party patches.
Encryption management – Central control of BitLocker on Windows and FileVault on macOS.
Important – EDR detection and response actions run on Windows devices only.
Kaspersky Next EDR Optimum, still sold in retail channels under its earlier name Kaspersky Endpoint Detection and Response Optimum, adds essential EDR functions to Kaspersky's endpoint protection platform. It is managed from the Kaspersky Next cloud console, with an on-premises deployment option, and a single security profile covers Windows, macOS, Linux, Android and iOS devices.
Faster incident triage – Incident card collects device, user and detection data together.
Contained attacks – Network isolation stops lateral movement from an infected host.
Fewer follow-up tools – Patch and encryption management included, no separate purchase needed.
Shadow IT control – Blocks access to unwanted cloud services on Windows.
Microsoft 365 protection – Protects Microsoft 365 mailboxes, files and collaboration services.
Staff skill building – Built-in cybersecurity training for the IT team.
The product is built for organisations that have an IT team but no dedicated security operations centre. One administrator can run detection, patching and encryption from the same console, which is the workload model of a company with roughly 20 to 500 devices. Above that, alert volume usually exceeds what a part-time responder can process, and the XDR tier of the same family becomes the better fit.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Increasing | ✓ | ✓ |
| Own staff for alert triage | Rarely | Partial | ✓ |
| This product fits | ✓ | ✓ | ✕ |
The reporting obligation introduced by the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, and it has been in force since 1 April 2025. Affected organisations must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with the remaining details due within 14 days. The incident card and the threat development chain graph deliver exactly the material that first report needs: which device was affected, when the detection occurred, and which process started the chain, without an administrator having to reconstruct it from raw event logs. What the product does not do is decide whether your organisation is in scope, notify BACS for you, or maintain the tamper-evident long-term log archive that a 14-day follow-up report and any later audit will draw on; telemetry here is sized for investigating a single detection, not for months of retained evidence. It also covers only endpoints, so attacks that begin on a network device, a hosted application or a supplier system leave no trace in this console. This is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your legal advisers.
No software product creates NIS 2 compliance, because the Directive addresses the organisation and its management, not the tools it buys. The NIS 2 Directive requires risk management measures in defined categories, among them incident handling, vulnerability handling, access control and use of cryptography, together with incident reporting duties. This product supports several of those categories directly: vulnerability assessment and patch management for the vulnerability handling category, device and application control plus host intrusion prevention for access control, and central management of BitLocker and FileVault for the cryptography category. It does not cover business continuity and backup, supply chain security assessment, staff-wide security awareness beyond the IT team, or the governance documentation and management accountability that the Directive places at the centre. Buyers should treat it as evidence for the technical measures in a few categories and plan separately for the organisational ones.
Germany's Federal Office for Information Security has warned against the use of Kaspersky antivirus software since 15 March 2022 and recommends replacing it with alternative products. The warning is still in force and, since the German NIS 2 implementation act took effect on 6 December 2025, is regulated under Section 13 BSIG rather than Section 7. Separately, the US Department of Commerce issued a final determination on 20 June 2024 prohibiting Kaspersky from supplying cybersecurity products to US persons, and Kaspersky's own documentation confirms that update and Kaspersky Security Network functionality stopped being available in US territory in September 2024. Kaspersky rejects the German warning as not justified and states that it was not based on an objective technical analysis of its software; the company also points to its Global Transparency Initiative, under which threat-related data from European users has been processed in two data centres in Zurich since November 2018 and source code can be reviewed at the Zurich Transparency Center. Neither authority action rests on detection performance, and independent test laboratories continue to include Kaspersky business products in their evaluations. In practice this matters most to public sector bodies, suppliers to public sector bodies, and companies whose customers impose country-of-origin conditions in supplier questionnaires; for other buyers it is a risk judgement rather than a prohibition.
Yes, for the endpoint section of a questionnaire, and not much beyond it. It answers the recurring items on malware protection, behaviour-based detection, endpoint detection and response capability, host isolation, disk encryption on managed laptops, removable media control, application control and documented vulnerability and patch status for Windows. Those answers can be backed with console reports rather than a written assertion, which is what a reviewer usually asks for on the second pass. It does not answer items on backup and restore testing, network segmentation, identity and privileged access management, email security for on-premises mail servers, penetration testing, or log retention periods, and it produces no evidence for the governance items on policies, roles and incident response exercises. It also cannot answer questions about vendor country of origin in your favour if the questionnaire contains one, which is worth checking before you standardise on it. Where the gaps are technical, moving up to the XDR tier of the same family is usually cheaper and less work than adding a second vendor's console, because the agent, policies and reporting stay the same.
The decisive difference is the EDR component itself: Foundations detects and blocks, but gives no incident card, no IoC scanning and no guided response actions, so an administrator investigating a detection is back to reading local logs. Beyond that, Optimum adds the two management functions that most often trigger a follow-up purchase later, patch management and encryption management. Both editions share the same endpoint protection engine, the same cloud console and the same operating system coverage, so an upgrade does not mean redeploying agents. Adaptive anomaly control, Microsoft 365 protection and blocking of unwanted cloud services are also Optimum-only.
| Feature | Next EDR Foundations | Next EDR Optimum |
|---|---|---|
| Endpoint detection and response | ✕ | ✓ |
| Patch management | ✕ | ✓ |
| Encryption management | ✕ | ✓ |
| Adaptive anomaly control | ✕ | ✓ |
| Blocking of cloud services | ✕ | ✓ |
| Microsoft 365 protection | ✕ | ✓ |
The most important regional point is the reverse of the usual pattern: the software is not available in the United States, where updates and Kaspersky Security Network functionality were switched off in September 2024 under the US prohibition, so a Swiss or EU company with a US subsidiary cannot standardise on it across all sites. Platform coverage is uneven inside the product as well. Endpoint protection runs on Windows, macOS, Linux, Android and iOS, but the EDR functions, vulnerability and patch management and cloud service discovery apply to Windows devices only, and encryption management orchestrates BitLocker and FileVault rather than providing its own encryption engine, so Linux endpoints are protected but not investigable from the incident card. Mail protection covers Microsoft 365; an on-premises Exchange server needs a separate product. The two omissions that most often cause a follow-up purchase are a managed detection service, which belongs to higher tiers of the family, and backup, which is not part of this product at all.
No. The EDR functions run inside the Kaspersky endpoint protection application already installed on the Windows device, which is why there is no second agent to roll out and no additional load on the endpoint from a separate sensor.
Malicious and suspicious files that European users share with Kaspersky Security Network have been processed in two data centres in Zurich since 13 November 2018. Kaspersky also operates a Transparency Center in Zurich where authorised partners can review source code, software updates and detection rules.
Yes. The cloud console is the default and needs no server of your own, and Kaspersky also offers an on-premises installation for organisations that require the management data to stay inside their own infrastructure.