What are the key advantages of Kaspersky EDR Optimum Base?
Central management – One cloud console for all protected devices.
Built-in EDR – IoC scanning, root cause analysis, guided response.
Patch management – Finds and installs missing Windows software updates.
Encryption management – Central BitLocker and FileVault control with key recovery.
Broad coverage – Windows, macOS, Linux, Android and iOS.
Important note – No managed service; your team handles response.
Endpoint protection platform – File, web, mail and network threat protection with firewall.
Endpoint Detection and Response – IoC scanning, root cause analysis and guided response actions.
Patch management – Detects and installs missing updates on Windows devices.
Encryption management – Central BitLocker and FileVault control with stored recovery keys.
Microsoft 365 protection – Cloud discovery, app blocking and sensitive data detection.
Important – No managed detection service; your own team responds.
Kaspersky EDR Optimum Base is a new licence for the tier Kaspersky now sells as Kaspersky Next EDR Optimum, previously named Kaspersky Endpoint Detection and Response Optimum. Devices are managed centrally from the Kaspersky Next cloud console, and an on-premises deployment is also offered.
Central console – One policy set covers Windows, macOS, Linux and mobile.
Root cause analysis – Shows the attack path without reading raw event logs.
Guided response – Isolate a host or block a file from the alert.
IoC scanning – Search every endpoint for a file hash after a warning.
Adaptive Anomaly Control – Hardens rules from observed behaviour instead of manual lists.
Fewer consoles – Patching and encryption are managed where protection is managed.
The tier is built for organisations that have IT staff but no dedicated security operations team. Below the reporting duty, an administrator is expected to read an alert card and decide; above it, the same person is usually already stretched across several roles.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | By sector |
| NIS 2 in the European Union | Rare | By sector | Usually |
| Security questionnaire from large customers | Occasional | Frequent | Standard |
| In-house capacity to triage an alert | Limited | Small IT team | Own SOC |
| This product fits | ✓ | ✓ | ✕ |
No software product meets these requirements on its own, and the duty applies to a defined group rather than to every company. Since 1 April 2025 the revised Information Security Act and the Cybersecurity Ordinance oblige operators of critical infrastructure to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, with a further 14 days to complete the report. The part this product supports is the detection and the first hours of the report: the alert card records what was executed, on which device and along which path, and IoC scanning tells you whether the same file appeared elsewhere in the estate, which is the question the report actually asks. What it does not supply is the organisational half — who is on call at 02:00, who decides that the threshold is met, who writes and submits the report, and how you show later that the process was followed. Neither does it cover systems outside the endpoint estate, such as network devices, industrial controllers or SaaS platforms, so an attack that never touches a managed endpoint may go unrecorded. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No product makes an organisation NIS 2 compliant, because the directive addresses management responsibility and processes rather than tooling. NIS 2 requires categories of measure that include risk analysis, incident handling, business continuity, supply chain security, vulnerability handling, cryptography and encryption, access control and staff training. This tier maps onto several of them directly: vulnerability assessment and patch management address vulnerability handling, encryption management addresses the cryptography category for laptops and desktops, device and application control address access control, and the built-in cybersecurity training addresses part of the training requirement for IT staff specifically. It does not address business continuity, because it contains no backup or recovery function, and it does not address supply chain security, which is a procurement and contract topic. Incident handling is supported only at the detection and containment stage; the reporting workflow, the decision chain and the evidence retention policy remain yours to define.
Two official measures are in force and both are relevant to procurement. Germany's Federal Office for Information Security has warned against the use of Kaspersky antivirus software since 15 March 2022; following the December 2025 amendment of the BSI Act the warning now sits under Section 13 BSIG, and it has not been withdrawn. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from supplying cybersecurity products to US persons, with the full prohibition on signature and codebase updates effective 29 September 2024; Kaspersky's own documentation reflects this by noting that update and Kaspersky Security Network functionality may not be available in the software in the US. Kaspersky rejects both assessments, states that neither is based on a technical analysis of its products, and has pursued legal remedies in Germany. In Switzerland the position differs: the Federal Office for Cybersecurity has issued no warning and no ban, stating that it warns only where it holds confirmed technical indications of a security risk, and Kaspersky processes threat-related data from European users in two data centres in Zurich alongside a source-code review facility in the same city. Independent testing has continued throughout: Kaspersky took part in the AV-Comparatives Business Security Test for the first half of 2026, and Kaspersky EDR Expert in its on-premises form was certified in the AV-Comparatives EDR Detection Validation Test 2026 — that certification covers the Expert product, not this tier. In practice this matters most if you sell into the German public sector, hold US federal or US-linked contracts, or answer supply-chain questionnaires that screen vendor country of origin; for a purely Swiss commercial buyer with no such exposure, it is a procurement question rather than a technical one.
Yes, for the endpoint section, and not for the rest. It answers with evidence the recurring items on malware protection, centrally enforced policy, device and application control, disk encryption with managed recovery keys, vulnerability and patch status for Windows, and the existence of a detection and response capability with recorded alerts you can export. It does not answer the items on 24/7 monitoring, mean time to respond, log retention periods, SIEM integration, network and cloud telemetry, backup and restore testing, mail gateway filtering, or multi-factor authentication — none of these are functions of this tier. It also cannot answer the vendor-risk section, which will ask about country of origin and about the assessments described above. If several of those gaps appear in the same questionnaire, moving up within the Kaspersky Next line to a tier that adds managed detection is normally cheaper and faster than adding a second vendor's agent, because the reviewer sees one console and one evidence trail rather than two; the exception is the vendor-risk section, which a higher tier of the same family does not change.
The decisive difference is the EDR component itself: Foundations offers only Root-Cause Analysis in limited form, while Optimum adds the full Endpoint Detection and Response feature with IoC scanning, execution prevention, network isolation and automated response. The second difference is the manageability set, because patch management and encryption management are absent from Foundations entirely — this is the reason most buyers move up, since it removes two separate tools rather than adding a security feature. Optimum also adds Adaptive Anomaly Control, Microsoft 365 protection, Data Discovery and the built-in cybersecurity training for IT staff. The core anti-malware engine is identical in both tiers, so the upgrade buys visibility and administration, not better detection of common threats.
| Feature | EDR Foundations | EDR Optimum |
|---|---|---|
| File, web, mail and network threat protection | ✓ | ✓ |
| Endpoint Detection and Response | ✕ | ✓ |
| Root-Cause Analysis | Limited | ✓ |
| Patch Management | ✕ | Windows only |
| Encryption Management | ✕ | ✓ |
| Adaptive Anomaly Control | ✕ | ✓ |
| Microsoft 365 protection and Data Discovery | ✕ | ✓ |
| Managed detection service | ✕ | ✕ |
Patch management covers applications on Windows devices only, so macOS and Linux machines are assessed for vulnerabilities but not patched from this console — this is the limitation that most often triggers a second purchase. The EDR component runs on Windows, Linux and macOS from Kaspersky Endpoint Security 12.2 for Mac onwards, but not on Android or iOS, so mobile devices are protected and policy-managed without producing detection telemetry. Encryption is orchestration of BitLocker and FileVault rather than an encryption engine of Kaspersky's own, which means the recovery path depends on Microsoft and Apple behaviour and the recovery keys are held in the Kaspersky Next infrastructure. There is a documented regional restriction: Kaspersky states that update functionality, including anti-malware signature and codebase updates, and Kaspersky Security Network functionality may not be available in the software in the United States, which matters if you operate US subsidiaries or US-based staff. Finally, this tier contains no backup, no mail gateway or Exchange-level filtering and no managed service, so ransomware rollback at endpoint level is your only recovery mechanism inside the product.
Base is Kaspersky's licence type for an initial licence, as opposed to a renewal of an existing one. It is a standalone base product and not an add-on, so it does not require another Kaspersky licence to work.
Kaspersky Endpoint Security for Windows supports the core protection components on Windows Server operating systems and can be used instead of a separate server product, including ransomware protection for Windows file servers. It is not a substitute for a dedicated Exchange or mail-server product, which is a separate purchase.
The standard deployment is the Kaspersky Next cloud console, which is what most buyers of this tier use. Kaspersky also documents an on-premises installation option for organisations that need to keep the management infrastructure in their own environment.