What are the core benefits of Kaspersky Endpoint Security Cloud?
Central console – Managed from a cloud console, no server needed.
Five platforms – Windows, macOS, Linux, Android and iOS covered.
Ransomware protection – Behaviour blocking rolls back malicious changes on Windows.
Vulnerability assessment – Finds Windows and third-party application vulnerabilities.
Instant protection – Default security profile applies as soon as installed.
Important note – EDR, patch and encryption management need higher editions.
Download: Kaspersky Endpoint Security Cloud
Cloud management console – Browser-based console, no on-premises management server to install.
Core threat protection – File, mail, web and network threat protection plus firewall.
Ransomware behaviour blocking – Behavior Detection, Exploit Prevention and Remediation Engine reverse changes.
Five platform coverage – One security profile for Windows, macOS, Linux, Android, iOS.
Vulnerability assessment – Detects operating system and third-party application flaws on Windows.
Important – EDR, patch management, encryption and device control need higher editions.
Kaspersky Endpoint Security Cloud is an endpoint protection platform for small and mid-sized companies, managed entirely from a browser-based console on Kaspersky Business Hub with no management server on site. Kaspersky sells it alongside the newer Kaspersky Next line, which has its own console and its own edition names, so the two are not the same product.
No server infrastructure – The console is hosted by Kaspersky and reached by browser.
Single security profile – One profile holds settings for all five operating systems.
Protection from installation – A default profile applies automatically once the agent connects.
Link-based deployment – One email link detects the operating system and downloads.
European data processing – Threat data from European users is processed in Zurich.
Server and mobile – Windows servers, Android and iOS devices join the same console.
The product is built for companies that have no dedicated security team and no server room for a management console. The decisive question is not headcount but whether anyone in the company is expected to investigate an incident afterwards. If that duty exists, the base edition is too small, because the detection and response records live in the Pro edition.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | ✓ |
| NIS 2 in the European Union | Rare | By sector | ✓ |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Attack analysis and response records needed | ✕ | ✓ | ✓ |
| This product fits | ✓ | Partial | ✕ |
The Swiss reporting obligation applies to operators of critical infrastructure named in the revised Information Security Act, in force since 1 April 2025, which includes energy and water supply, transport operators, hospitals above the defined thresholds, and cantonal and communal administrations. Those organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, with a further 14 days to complete the report. Kaspersky Endpoint Security Cloud supports the first half of that duty in a concrete way: every detection appears in the console with a device and a time stamp, which is what an administrator needs in order to notice an incident at all and start the 24-hour clock. It does not support the second half in this edition, because Root-Cause Analysis and Endpoint Detection and Response are not included, so there is no reconstructed attack chain to draw on when the report has to be completed. Most small and mid-sized companies are not operators of critical infrastructure and are not subject to the obligation, although they are increasingly asked about it by customers who are. This description is a product description and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.
No software product makes an organisation compliant with the NIS 2 Directive, because the obligations fall on the entity and its processes, not on a tool. NIS 2 requires measures in categories that include risk analysis and information security policies, incident handling, business continuity and backup management, supply chain security, vulnerability handling, basic cyber hygiene and security training, cryptography and encryption policies, and access control. Kaspersky Endpoint Security Cloud contributes directly to two of these: incident handling, because detections across all managed devices are visible in one place, and vulnerability handling, because Vulnerability Assessment identifies operating system and third-party application flaws on Windows devices. It contributes nothing to business continuity and backup, it enforces no encryption in this edition, it provides no multi-factor authentication for your own business applications, and it includes no security awareness training. Buyers who want the encryption and training measures inside the same product family have to move up to Cloud Plus or Cloud Pro rather than adding a second vendor.
In March 2022 the German Federal Office for Information Security (BSI) recommended replacing Kaspersky products with alternatives on national security grounds rather than on the basis of a technical defect found in the software, and confirmed in 2024 that this recommendation still stood; it was a recommendation, not a sales ban. In June 2024 the US Department of Commerce, through its Bureau of Industry and Security, issued a final determination prohibiting new sales of Kaspersky software to US persons from 20 July 2024, and prohibiting signature and codebase updates as well as operation of the Kaspersky Security Network in the United States from 29 September 2024. Kaspersky rejects both assessments, describes them as decisions taken on geopolitical rather than technical grounds, and points to its Global Transparency Initiative, under which threat data from European users has been processed in Zurich since 2018 and source code can be reviewed in its Transparency Centres. There is no comparable Swiss or EU-wide sales restriction: the product is sold and updated normally in Switzerland and in the European Union, and Kaspersky products continue to appear in the test cycles of independent European laboratories. In practice this affects a defined group of buyers: companies with US operations or US persons on their systems, bidders for public sector contracts in countries that restrict Russian-origin software in procurement, and suppliers whose large customers exclude Russian-origin software by contract. For a Swiss or EU company with no public-sector and no US exposure, no restriction applies, and whether the vendor's origin is acceptable remains the buyer's decision.
Partly, and only for the endpoint section. With a console report you can answer whether endpoint protection is deployed on every company device, whether it is centrally managed rather than configured per machine, whether real-time malware and ransomware protection is active, whether devices are scanned for known vulnerabilities, and whether mobile devices are included. In this edition you cannot answer, in the same detail, whether missing patches are actually deployed, whether disks are encrypted and recovery keys held centrally, whether removable media are restricted, whether detections are retained together with a reconstructed attack chain, whether staff receive security awareness training, or whether backups exist and are tested. The cheapest way to close most of those items is Cloud Plus, which adds patch management, encryption management and device control inside the same console and therefore the same report, while Cloud Pro adds the detection and response records and the training. Backup is not part of any edition in this family and has to be procured separately whichever edition you choose.
The single most decisive difference is that Endpoint Detection and Response exists only in Cloud Pro, so if anyone in your organisation is expected to explain after an incident how an attacker got in, the base edition will not carry you. The second most decisive is the split at Cloud Plus, which is where patch management, encryption management, device control and web control begin. All three editions share the same protection engine, the same console and the same platform coverage, so the difference is scope rather than detection quality. The base edition also runs Mail and Web Threat Protection on workstations only, while both higher editions extend those components further.
| Feature | Cloud | Cloud Plus | Cloud Pro |
|---|---|---|---|
| File and network threat protection, firewall | ✓ | ✓ | ✓ |
| Mail and Web Threat Protection | Workstations only | ✓ | ✓ |
| Vulnerability Assessment | ✓ | ✓ | ✓ |
| Patch Management | ✕ | ✓ | ✓ |
| Encryption Management | ✕ | ✓ | ✓ |
| Device Control and Web Control | ✕ | ✓ | ✓ |
| Root-Cause Analysis | ✕ | ✓ | ✓ |
| Endpoint Detection and Response | ✕ | ✕ | ✓ |
| Application Control and Adaptive Anomaly Control | ✕ | ✕ | ✓ |
| Microsoft 365 protection | ✕ | ✓ | ✓ |
| Cybersecurity training | ✕ | ✕ | ✓ |
This is the smallest of the three editions, and the components most often assumed to be included are not: Endpoint Detection and Response, Root-Cause Analysis, patch management, encryption management, device control, web control and Microsoft 365 protection all sit in Cloud Plus or Cloud Pro, which is the most common reason for a follow-up purchase within the first months. In the base edition, Mail Threat Protection and Web Threat Protection run on workstations only, which matters if you expected identical protection layers on a Windows file server. There is a regional restriction that European buyers with international sites should check first: following the US Department of Commerce determination, the product cannot be sold or updated to US persons and the Kaspersky Security Network cannot operate in the United States, so US locations cannot be covered under the same rollout. The data centre region for your workspace follows the country entered when the company is registered on Kaspersky Business Hub rather than being freely selectable afterwards, and importing users from Microsoft Entra ID requires a Kaspersky Next licence, not a Kaspersky Endpoint Security Cloud licence. No edition of this family includes backup, so ransomware recovery beyond the automatic rollback of malicious changes has to be solved with a separate product.
Yes. Windows servers are managed from the same console as workstations, and Kaspersky Endpoint Security for Windows has provided ransomware protection for Windows file servers since version 11. Linux devices are covered through Kaspersky Endpoint Security for Linux, whose installation package is prepared in the console. In the base edition, however, Mail and Web Threat Protection apply to workstations only.
Yes. Kaspersky documents both a manual and an automated migration path from Kaspersky Security Center to Kaspersky Endpoint Security Cloud. The cloud console is the simpler of the two management models by design, so plan the move around the policies you actually use rather than expecting a one-to-one transfer.
Kaspersky Next is a separate, newer business line with its own editions and its own documentation, not a rename of Kaspersky Endpoint Security Cloud, which continues to be sold in its three editions. Some console capabilities, such as importing users from a Microsoft Entra ID tenant, are tied to a Kaspersky Next licence and are unavailable under a Kaspersky Endpoint Security Cloud licence.