What are the key advantages of Kaspersky Endpoint Security Cloud Pro?
Cloud console – All devices managed centrally from one browser.
Built-in EDR – Root cause analysis, host isolation, IoC scanning.
Patch management – Closes operating system and application gaps automatically.
Encryption control – Manages BitLocker and FileVault from the console.
Microsoft 365 – Scans Exchange Online, OneDrive, SharePoint and Teams.
Important note – No Linux agent in this product line.
Download: Kaspersky Endpoint Security Cloud Pro
Cloud management console – Kaspersky hosts the console, so no administration server is needed.
Endpoint Detection and Response – Root cause analysis, host isolation and IoC scanning.
Vulnerability and patch management – Finds and closes gaps in operating systems and applications.
Encryption management – Controls BitLocker on Windows and FileVault on macOS.
Microsoft 365 protection – Scans Exchange Online, OneDrive, SharePoint Online and Teams.
Important – No Linux agent exists in the Endpoint Security Cloud line.
Kaspersky Endpoint Security Cloud Pro is the top edition of the Endpoint Security Cloud line and is managed from a browser console that Kaspersky operates, so nothing has to be installed in your own data centre. Kaspersky has since moved this capability level into the Kaspersky Next line, where Kaspersky Next EDR Optimum is the closest current counterpart.
No own server – Kaspersky runs the console, you need a browser.
Faster incident triage – Root cause analysis shows the full process chain.
Fleet-wide IoC sweep – Check every managed device against one published indicator.
One-click isolation – Cuts a suspect device off the network remotely.
Patching without scripting – Replaces manual update rounds on every single workstation.
Built-in admin training – The CITO course runs from the same console.
The product is built for companies that have one IT generalist rather than a dedicated security team. Larger organisations usually outgrow it at the point where they need log retention, SIEM export or Linux server coverage, which the Cloud line does not provide.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | By sector |
| NIS 2 in the European Union | Rare | By sector | ✓ |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Guided detection and response without a security team | ✓ | ✓ | Limited |
| This product fits | ✓ | ✓ | ✕ |
The revised Information Security Act has obliged operators of critical infrastructure in Switzerland to report significant cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery since 1 April 2025, with a detailed follow-up report due within 14 days. Most small companies are not operators of critical infrastructure and are therefore not subject to this obligation, but many of them supply organisations that are. Kaspersky Endpoint Security Cloud Pro supports the reporting workflow in three concrete ways: the console timestamps the detection, root cause analysis reconstructs which process started the attack and which files and devices it touched, and the IoC scan shows whether the same indicator appears elsewhere in the fleet, which is exactly the scope information the 14-day report asks for. It does not decide whether your organisation is in scope, does not classify an incident as reportable, does not file anything with BACS, and keeps no long-term log archive for later forensic work, so the reporting process itself has to be documented separately. This is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No security product makes a company compliant with the NIS 2 Directive, because the directive addresses management responsibility, risk processes and governance, not software features. NIS 2 requires measures in defined categories, among them incident handling, business continuity and backup, supply chain security, vulnerability handling and disclosure, cryptography and encryption, cyber hygiene and security training, and access control including multi-factor authentication. Kaspersky Endpoint Security Cloud Pro contributes directly to four of these: incident handling through EDR and automated response, vulnerability handling through vulnerability assessment and patch management, cryptography through BitLocker and FileVault management, and security training through the built-in course for IT staff. It contributes nothing to business continuity and backup, nothing to supply chain security, and nothing to multi-factor authentication, and its risk reporting is designed for an administrator rather than for a board-level review. Those categories have to be covered by separate products and by written processes.
In Switzerland there is no ban and no formal warning. The Federal Office for Cybersecurity has stated that it has no internal directive against Kaspersky products and that it has received no report of misuse, while also noting that federal offices no longer use the software. In Germany, the Federal Office for Information Security (BSI) has warned against Kaspersky antivirus software since 15 March 2022 under the warning provision of the BSI Act, and confirmed in 2026 that the warning stands and that its reasoning has not changed. In the United States, the Department of Commerce issued a final determination in June 2024 that prohibits Kaspersky from selling to US persons and, since 29 September 2024, from delivering signature and codebase updates there; that prohibition is still in force and Kaspersky has wound down its US operations. Kaspersky rejects the assessments, points to its data processing in Zurich and its transparency centres, has publicly demanded that the BSI withdraw the warning, and is pursuing damages. Independent testing has continued regardless: Kaspersky business products were still included and certified in the AV-Comparatives Business Main-Test Series in 2026. In practice this matters most if you bid for public sector contracts, supply German or EU public bodies, have US-linked group companies, or answer supply chain questionnaires that ask about vendor country of origin; for a purely domestic Swiss company with no such ties it is a risk judgement rather than a legal obstacle.
Yes, for the endpoint section of a questionnaire, and not much beyond it. It answers the items on malware protection on workstations and servers, centrally enforced policy, device and application control, disk encryption on notebooks, patch status of operating systems and third-party applications, detection and response capability, and security awareness of the IT staff, and the console produces status reports you can attach as evidence. It does not answer the items on backup and restore testing, multi-factor authentication, identity and access management, network segmentation, log retention periods, SIEM monitoring, penetration testing or supplier risk management, and it will not answer anything about Linux systems because the Cloud line has no Linux agent. If the gaps that block you are detection depth and log retention, moving up within the same family to Kaspersky Next XDR Optimum is usually cheaper and faster than adding a second vendor, because the policies, agents and reporting stay in one place. Backup and multi-factor authentication, by contrast, always need separate products, whichever endpoint vendor you choose.
The single decisive difference is the response capability: Cloud Plus lets you see an attack, Cloud Pro lets you act on it across the fleet. Cloud Plus already includes web and device control, patch management, encryption management, Microsoft 365 protection and root cause analysis. Cloud Pro adds the EDR component with IoC scanning, one-click host isolation and automated response, plus application control, Adaptive Anomaly Control, remote data wipe and the built-in training course for IT staff. The entry-level Cloud edition below both sits at protection only and has neither encryption nor patch management. If nobody in the company will ever act on an alert, the extra Pro capabilities stay unused.
| Capability | Cloud Plus | Cloud Pro |
|---|---|---|
| Web, device and encryption control | ✓ | ✓ |
| Vulnerability and patch management | ✓ | ✓ |
| Microsoft 365 protection and Data Discovery | ✓ | ✓ |
| Root cause analysis | ✓ | ✓ |
| EDR with IoC scan and host isolation | ✕ | ✓ |
| Application control | ✕ | ✓ |
| Adaptive Anomaly Control | ✕ | ✓ |
| Remote data wipe | ✕ | ✓ |
| Cybersecurity training for IT staff | ✕ | ✓ |
The clearest regional restriction is the United States: since the Commerce Department determination the product cannot be sold to or updated for US persons, so any group with a US entity has to plan a different solution there. The platform gap is Linux, which the Endpoint Security Cloud line does not cover at all, while the newer Kaspersky Next tiers do; Windows, macOS, Android, iOS and Windows Server file servers are covered. The Microsoft 365 protection is included but runs as its own workspace, so day-to-day work means two browser tabs rather than one console. Kaspersky assigns your data centre region from the country you enter when the workspace is first created, which is worth getting right the first time. The follow-up purchases this product most often triggers are backup software and a multi-factor authentication service, neither of which is part of any Endpoint Security Cloud edition.
It is a base product and the highest of the three Endpoint Security Cloud editions. It does not require another Kaspersky product underneath it, and the EDR functions are part of the edition rather than a separately installed add-on component.
Yes. File servers running Windows Server are protected by the same agent and appear in the same console as workstations and notebooks. Linux servers are not covered, and there is no protection component for an on-premises Exchange server.
Yes, the Kaspersky agent takes over as the active protection layer on Windows. The practical reason to switch is central policy enforcement and response across all devices, which Defender only provides once you move to the paid Microsoft management tiers.