What are the key advantages of Kaspersky Endpoint Security Cloud Plus?
Cloud console – All devices managed from one browser console.
Ransomware rollback – Remediation Engine reverses malicious changes after attacks.
Patch management – Automates updates for vulnerable Windows applications.
Encryption management – Controls BitLocker and FileVault with stored recovery keys.
Cloud control – Blocks unwanted cloud services on Windows devices.
Important note – No on-premises console, management runs cloud-only.
Download: Kaspersky Endpoint Security Cloud Plus
Endpoint protection – File, web and mail protection with behaviour detection.
Ransomware rollback – Remediation Engine undoes malicious changes on Windows devices.
Patch management – Automated delivery of updates for vulnerable Windows applications.
Encryption management – Central BitLocker and FileVault control with recovery key storage.
Microsoft 365 protection – Scans Exchange Online, OneDrive and SharePoint Online content.
Important – Patch management and Cloud Discovery cover Windows devices only.
Kaspersky Endpoint Security Cloud Plus is the middle edition of the Kaspersky Endpoint Security Cloud line for small and medium businesses, managed entirely from a browser console that Kaspersky hosts and maintains. Kaspersky introduced the newer Kaspersky Next line in 2024, but the Endpoint Security Cloud editions remain a separate, documented product line.
No server needed – Kaspersky hosts the console, nothing installed on premises.
Predefined policies – Security profiles apply automatically to newly connected devices.
Shadow IT visibility – Cloud Discovery reports which cloud services staff use
Root-cause analysis – Visualised attack chain shows how an infection spread.
Mixed platform coverage – One console for Windows, macOS, Linux, Android and iOS.
Windows file servers – The workstation agent also protects Windows file servers.
This edition targets companies that have devices to protect but no dedicated security team. Everything is configured through predefined security profiles, and no administration server has to be installed or maintained. Once an organisation needs an on-premises console, dedicated mail or database server protection, or long-term event retention, it has outgrown this edition.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Central proof of patching and encryption | Optional | ✓ | ✓ |
| This product fits | ✓ | ✓ | ✕ |
The reporting obligation introduced by the revised Information Security Act (ISG) applies to operators of critical infrastructure, not to every Swiss company, and the Cybersecurity Ordinance exempts smaller organisations below the sector thresholds. Where it applies, a cyberattack must be reported to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. Kaspersky Endpoint Security Cloud Plus supports that deadline in one specific way: detections are raised centrally in the console, and the root-cause analysis view reconstructs how an infection reached a device, which is the information a first report has to contain. It does not detect an attack that never touches a managed endpoint, it keeps no long-term event archive for the follow-up report, and it neither writes nor submits the report itself. This text is general product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified specialist.
No software product makes a company NIS 2 compliant, because the directive requires organisational measures and management accountability that no licence can supply. NIS 2 sets out categories of measures including risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling and disclosure, cyber hygiene and training, cryptography, access control and multi-factor authentication. Kaspersky Endpoint Security Cloud Plus contributes concretely to three of them: vulnerability handling through vulnerability assessment and Windows patch management, cryptography through central BitLocker and FileVault control with stored recovery keys, and incident handling through central alerting and root-cause analysis. It contributes nothing to business continuity and backup, supply chain security, multi-factor authentication or staff training, and its reporting is designed for use in the console rather than as an audit evidence archive. Those gaps have to be closed with separate products and with written procedures.
On 20 June 2024 the US Department of Commerce Bureau of Industry and Security issued a Final Determination prohibiting Kaspersky from providing anti-virus software and cybersecurity products or services in the United States or to US persons, extending to its affiliates, subsidiaries and parent companies. New agreements were prohibited from 20 July 2024 and the supply of signature and codebase updates from 29 September 2024, and the determination remains in force. Germany's Federal Office for Information Security published a warning in March 2022 recommending that users replace Kaspersky products, which is guidance rather than a sales ban, while Italy and the Netherlands issued comparable guidance limited to public-sector and central government systems. Kaspersky rejects the allegations, states that the decision reflected the geopolitical situation rather than an evaluation of its products, and had proposed independent third-party verification of its software, updates and detection rules; the company moved data processing for European customers to Zurich in 2018 and offers source code review at its Transparency Centres. Neither Switzerland nor the European Union has issued a comparable sales prohibition, and the business products continue to be submitted to independent testing laboratories. In practice this affects you if you hold public-sector contracts, supply an organisation that does, have US entities or US persons in scope, or answer supply chain questionnaires that ask about vendor country of origin; for a purely domestic Swiss or EU company without those requirements it is a documentation question rather than an availability one.
Yes, for the endpoint section, and only for that section. It answers questions on malware protection of workstations and Windows file servers, ransomware rollback, centrally enforced security policies, vulnerability assessment, patching of third-party Windows applications, full-disk encryption with central key custody, removable device and web control, mobile device management for Android and iOS, and administrator role separation in the console. It does not answer questions on backup and restore testing, network segmentation, multi-factor authentication, email gateway filtering, penetration testing, secure development, long-term log retention or SIEM forwarding, or documented incident response procedures, and its reporting is built for console use rather than as an evidence archive an auditor can keep. The cheapest way to close the training and advanced response items is to move up within the same family to the Pro edition rather than adding a second vendor, since a mixed estate means two consoles and two sets of answers to maintain. Backup, multi-factor authentication and network questions have to be answered by separate products in any case, and the procedural items need written policies, not a licence.
The decisive difference is acting versus reporting. The base Cloud edition protects devices and tells you what it found; Cloud Plus adds the ability to do something about it, by patching vulnerable Windows applications, enforcing disk encryption, blocking cloud services instead of only listing them, and restricting removable devices and websites. Cloud Plus also adds protection for Microsoft 365 workloads. Cloud Pro sits above both and adds cybersecurity awareness training. If your only requirement is malware protection on managed devices, the base edition is enough; the moment a customer or auditor asks for patch and encryption evidence, Plus is the smallest edition that answers.
| Feature | Cloud | Cloud Plus | Cloud Pro |
|---|---|---|---|
| File, web and mail protection | ✓ | ✓ | ✓ |
| Vulnerability assessment | ✓ | ✓ | ✓ |
| Patch management | ✕ | Windows only | Windows only |
| Encryption management | ✕ | ✓ | ✓ |
| Web and device control | ✕ | ✓ | ✓ |
| Cloud Discovery | Monitor only | Monitor and block | Monitor and block |
| Microsoft 365 protection | ✕ | ✓ | ✓ |
| Awareness training | ✕ | ✕ | ✓ |
Patch management, Cloud Discovery and web control run on Windows devices only, so a macOS or Linux fleet is protected by this licence but not patched by it. The management console is cloud-only and hosted by Kaspersky, with no on-premises server option in this edition, and the workspace region follows the country entered at registration: companies in Switzerland and other countries not listed individually in Kaspersky's data centre table are hosted in the Ireland region, while registration is not available at all for the United States, where a US Department of Commerce prohibition applies. Server coverage means Windows file servers protected by the same agent as workstations, not dedicated protection for Exchange, database or Linux servers, which is the most common reason buyers later move to a Kaspersky Next edition or a Security Center-managed product. Backup and restore is not part of this product in any edition, so a separate backup solution is still required.
It protects Windows file servers using the same endpoint agent that runs on workstations, managed through the same security profiles. It is not a replacement for dedicated protection of Exchange, database or Linux servers.
Kaspersky assigns the data centre region from the country entered when the company workspace is registered on Kaspersky Business Hub. Companies in Switzerland and other countries not named individually in that table are hosted in the Ireland region, and the installation packages are hosted on the same servers.
Kaspersky introduced the Kaspersky Next line in 2024 with the editions EDR Foundations, EDR Optimum and XDR Expert, which offer a choice of cloud or on-premises console. Endpoint Security Cloud Plus remains a separately documented cloud-console line aimed at small and medium businesses, so buyers searching for either name will find related products.