What are the key advantages of Kaspersky Endpoint Security for Business Select?
Centrally managed – Kaspersky Security Center console, cloud or on-premises.
Multi-platform coverage – Windows, Linux, Mac, Android and iOS.
Automatic rollback – Remediation Engine reverses most malicious changes.
Vulnerability assessment – Finds unpatched software across all managed endpoints.
Device control – Blocks USB storage and removable media centrally.
Important note – No EDR, patch management or encryption management.
Kaspersky Security Center – Central console, deployable in the cloud or on premises.
Endpoint Security for Windows – Protects workstations and Windows file servers with one agent.
Endpoint Security for Linux – Covers Linux workstations and servers from the same console.
Endpoint Security for Mac – Protects macOS devices on Intel and Apple silicon.
Kaspersky Security for Mobile – Mobile Threat Defense for Android and iOS devices.
Important – No EDR component, patch management or encryption management included.
Kaspersky Endpoint Security for Business Select is the entry tier of the Endpoint Security for Business family, managed centrally through Kaspersky Security Center as a cloud console or on premises. Kaspersky has since introduced Kaspersky Next EDR Foundations as the successor tier, so buyers still searching for the Select name are looking at the older of two closely related products.
Rollback after infection – Remediation Engine undoes most malicious changes automatically.
One agent – Same agent covers Windows, Linux, Mac and mobile.
Vulnerability assessment – Finds unpatched software before an exploit reaches it.
Device control – Blocks USB storage and other removable media centrally.
Syslog export – Sends events to an existing SIEM or RMM.
Directory integration – Active Directory structure drives policy and role assignment.
Select fits organisations that need one console, one agent and consistent policies across mixed operating systems, but that do not yet have anyone whose job is to investigate alerts. Once a company has a defined security role and is asked for incident evidence, the missing EDR component becomes the deciding factor rather than the protection quality.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Needs EDR and response actions | ✕ | Partial | ✓ |
| This product fits | ✓ | Partial | ✕ |
The reporting obligation under the revised Information Security Act (ISG) has applied since 1 April 2025 and affects operators of critical infrastructure such as energy and water utilities, transport companies and cantonal and communal administrations, not Swiss companies in general. Affected organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. Select supports this in two concrete ways: Behavior Detection and the Remediation Engine identify and roll back malicious changes on the endpoint, and Kaspersky Security Center collects the resulting events centrally and exports them by syslog to a SIEM, which is where most of the reportable detail is assembled. What it does not support is the reconstruction the report itself asks for, namely the type and execution of the attack, because Select contains no EDR component and therefore offers no root-cause timeline, no host isolation and no cross-endpoint indicator scan. It also cannot evidence patch status or disk encryption, both of which are commonly asked about once an incident is being reviewed. This is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No software product makes a company NIS 2 compliant, because the directive addresses organisational risk management rather than a list of tools. NIS 2 requires measures in categories including incident handling, business continuity and backup management, supply chain security, vulnerability handling and disclosure, policies on cryptography and encryption, and multi-factor authentication. Select maps to some of these directly: vulnerability assessment covers the detection half of vulnerability handling, application, web and device controls reduce attack surface, and centrally logged detections feed incident handling. The gaps are equally concrete, because Select includes no backup, no encryption management, no multi-factor authentication and no patch deployment, so business continuity, cryptography and the remediation half of vulnerability handling have to come from elsewhere. Treat this mapping as the starting point for your own gap analysis rather than as a checklist.
In Switzerland, the national cybersecurity authority has not issued a warning against Kaspersky products. When the topic was raised in 2022 it stated that it does not issue recommendations on individual products, that no misuse of Kaspersky software had been reported in Switzerland, and that the choice of product and the associated risk assessment rest with the organisation. In Germany, the BSI issued a warning under section 7 of the BSI Act in March 2022 advising organisations to replace Kaspersky antivirus software, and that warning has not been withdrawn. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting the supply of Kaspersky cybersecurity products to US persons, with new sales stopping on 20 July 2024 and software updates on 29 September 2024, and three Kaspersky entities were added to the Entity List. Kaspersky rejects the allegation of government influence, points to its Global Transparency Initiative, processes threat-related data from European users in Zurich, and holds ISO/IEC 27001:2022 certification and a SOC 2 Type II audit covering that infrastructure. Both the German and US decisions rest on jurisdiction and vendor trust rather than on measured detection failures, and independent laboratory testing has continued. In practice this matters most if you bid for public sector contracts, supply an organisation with US ownership, or answer supply chain questionnaires that ask about vendor country of origin, and much less if you are an independent Swiss company buying protection for your own devices.
Partly, and the split is predictable. Select lets you answer yes to centrally managed endpoint protection on workstations and file servers, coverage of Windows, Linux, macOS, Android and iOS, policy enforcement with role-based access and Active Directory integration, control of removable media and USB storage, recurring vulnerability scanning, and event export to a SIEM by syslog. It forces you to answer no to full disk encryption and central key management, patch deployment and remediation, endpoint detection and response with an investigable incident timeline, host isolation, any managed detection service, and protection at the mail server or web gateway. Vendor country of origin is a further question that Select cannot answer favourably for every buyer, as covered in the section above. To close the encryption, patch management and terminal server gaps, upgrading to Endpoint Security for Business Advanced is usually cheaper and simpler than adding a second vendor, because it uses the same agent and the same console; if the gap is EDR specifically, Kaspersky Next EDR Foundations is the successor line to look at rather than a bolt-on.
The single most decisive difference is that Advanced adds patch management and encryption management, which are the two capabilities most often demanded by insurers and auditors and most often bought as a follow-up purchase after Select. Advanced also extends protection to application and terminal servers, which Select does not cover even though it protects Windows file servers. Both tiers share the same agent, the same Kaspersky Security Center console and the same detection technologies, so moving up is a licence change rather than a migration. Neither tier includes mail server or gateway protection, which sits in Total Security for Business.
| Capability | Select | Advanced |
|---|---|---|
| Windows, Linux, Mac, Android, iOS | ✓ | ✓ |
| Application and terminal servers | ✕ | ✓ |
| Patch management | ✕ | ✓ |
| Encryption management | ✕ | ✓ |
| Advanced SIEM integration | ✕ | ✓ |
| Mail server and gateway protection | ✕ | ✕ |
| Available to US customers | ✕ | ✕ |
The clearest regional limitation is the United States, where Kaspersky cybersecurity products may not be supplied to US persons and have received no updates since 29 September 2024; this affects US subsidiaries and US-owned group companies, not deployments in Switzerland or the European Union. On platform coverage, Select protects Windows file servers through the same agent as workstations but does not cover application or terminal servers, and offers no protection at the mail server or web gateway at any point. The three omissions that most often trigger a follow-up purchase are patch management, encryption management and the EDR component itself, all of which sit one tier higher or in the successor line rather than in Select. Kaspersky Security Center is included, but the on-premises deployment requires a server you administer yourself, so the cloud console is usually the lower-effort option for companies without dedicated IT staff.
Threat-related data submitted by users in Europe to the Kaspersky Security Network is processed and stored on servers in Zurich, Switzerland. Kaspersky holds ISO/IEC 27001:2022 certification covering its Zurich data centres and operates a Transparency Center in the city where partners and government stakeholders can review source code and threat detection rules.
Yes. Kaspersky Security Center is available as a cloud console, which removes the need to run and maintain a management server yourself. If you prefer to keep management in your own environment, the on-premises console can also be deployed in AWS or Azure rather than on local hardware.
No. Mail server and gateway protection, inbound and outbound content filtering and anti-spam at gateway level are not part of Select or of Advanced. These components are only in Kaspersky Total Security for Business.