What are the core benefits of Kaspersky ICS Threat Data Feeds Vulnerability Feed?
No console – Data feed consumed by your existing SIEM or TIP.
ICS coverage – Vulnerabilities in ICS and connected IT systems.
CVE context – CVE identifiers, patch details and affected file hashes.
Vendor research – Compiled by the Kaspersky ICS CERT research team.
Standard formats – JSON, CSV, STIX and OpenIoC for integration.
Important note – No agent, no scanning and no protection included.
ICS vulnerability records – Flaws in industrial control systems and connected IT software.
CVE and patch context – CVE identifiers, timestamps and available patch information per entry.
File and exploit hashes – Hashes of affected files and related exploit samples.
Mitigation guidance – Recommended measures where a vendor patch is unavailable.
Machine-readable delivery – JSON, CSV, STIX and OpenIoC for automated ingestion.
Important – No console, no agent and no scanning engine included.
This is a threat intelligence data feed from the Kaspersky Threat Intelligence portfolio, listed in Kaspersky documentation under the name ICS Vulnerability Data Feed. It has no management console of its own: the data is ingested by a SIEM, a threat intelligence platform or Kaspersky CyberTrace, and the matching against your own asset and event data happens there.
Asset matching – Matches your OT asset list against known vulnerabilities.
Patch prioritisation – Severity and exploit data help order maintenance windows.
OT vendor coverage – Includes products from Siemens, Schneider Electric, Yokogawa and Emerson.
Kaspersky ICS CERT sourcing – Research team monitoring MITRE, NVD and vendor advisories.
Existing tool reuse – Works with QRadar, Splunk, MISP, Sentinel and others.
REST API access – Pulled through the Kaspersky Threat Intelligence REST API.
Company size is not the deciding factor here. What decides is whether you operate industrial control systems and whether you already run a SIEM or threat intelligence platform that can consume a feed. A small municipal water supplier can fall inside the Swiss reporting obligation while a large retailer stays outside it, so the sector matters more than the headcount.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | By sector | ✓ | ✓ |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| SIEM or TIP already in operation | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The reporting obligation under the revised Information Security Act has applied since 1 April 2025 and affects operators of critical infrastructure, including energy and water suppliers, transport operators and cantonal and communal administrations, with an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery and a completed report within 14 days. This feed supports the preparatory side of that obligation: it gives you a documented, dated source for known vulnerabilities in your ICS and connected IT software, which shortens the question of whether an incident relates to a flaw you already knew about. It does not detect the attack, does not produce the report and does not track the 24-hour deadline, so the detection and incident handling process has to come from your SIEM, your OT monitoring and your own runbook. It also does nothing for the 14-day follow-up report, which needs incident timeline and impact data the feed never sees. This text describes product capabilities and is not legal advice; whether your organisation falls within the scope of the reporting obligation should be clarified with your own legal or compliance function.
No product creates NIS 2 compliance, because the directive addresses organisational risk management measures rather than a specific tool. NIS 2 requires measure categories including risk analysis and security policies, incident handling, business continuity, supply chain security, security in the acquisition, development and maintenance of systems including vulnerability handling and disclosure, cyber hygiene and training, cryptography, access control and multi-factor authentication. This feed contributes to exactly one of those categories, vulnerability handling, by supplying a continuously updated and machine-readable record of known ICS flaws with CVE references and patch status. It contributes nothing to incident handling, business continuity, access control, cryptography, training or supplier assessment, and it produces no audit-ready report on its own, since any evidence has to be generated by the SIEM or platform that consumes the data.
Two official measures concerning the vendor are relevant and both are still in force. In March 2022 the German Federal Office for Information Security (BSI) issued a public warning against Kaspersky anti-virus software, the only public product warning of its kind that the authority has issued; it is now regulated under Section 13 BSIG and the BSI confirmed in 2026 that it is maintained. Kaspersky rejects the grounds, has formally demanded withdrawal of the warning and has reserved the right to take legal steps. Separately, the US Department of Commerce Bureau of Industry and Security issued a Final Determination in June 2024 prohibiting Kaspersky cybersecurity and anti-virus products in the United States, with the full prohibition effective from 29 September 2024; that determination explicitly does not apply to Kaspersky Threat Intelligence products and services, which is the portfolio this feed belongs to. In Switzerland, BACS has issued no warning and no restriction, states that no misuse has been reported to it, and refers organisations to their own risk analysis. In practice this affects buyers with German public sector contracts, buyers whose customers impose country-of-origin rules on suppliers, and groups with US entities in scope of the Commerce determination; for a purely Swiss industrial operator with no such contractual exposure, no legal restriction currently applies.
Partly, and only in one section of a typical questionnaire. It gives you a concrete answer to the questions on vulnerability identification and threat intelligence sourcing: you can name a commercial ICS-specific feed, its update cadence, its CVE and patch context, and the research team behind it, which is stronger than answering that you monitor public advisories manually. It does not answer questions on endpoint protection, detection and response, patch deployment, encryption, multi-factor authentication, backup, log retention, access control, staff training or ISMS certification, and it produces no policy documents or audit reports. It also cannot answer the supplier country-of-origin question, which increasingly appears in questionnaires from customers in regulated or public sectors and which no Kaspersky edition can close. For the technical gaps, adding further feeds or Kaspersky CyberTrace from the same Threat Intelligence family is usually cheaper and less integration work than assembling equivalent coverage from several vendors; for the origin question, the answer has to be a procurement decision rather than a product one.
The decisive difference is what consumes the data. The standard ICS Vulnerability Feed delivers vulnerability records with hashes, CVEs, timestamps and patch context for ingestion by a threat intelligence platform or SIEM, where it is matched against your asset inventory and incoming events. The OVAL variant is a separate feed containing scanning rules for detecting vulnerable ICS software on Microsoft Windows systems using scanners that support the OVAL standard, which is a different workflow and a different purchase. The ICS Hash Feed is a third, distinct feed covering malicious files used to attack ICS infrastructure rather than vulnerabilities, so it answers a different question altogether.
| Property | ICS Vulnerability Feed | ICS Vulnerability Feed, OVAL | ICS Hash Feed |
|---|---|---|---|
| Content | Vulnerability records | Scanning rules | Malicious file hashes |
| Consumed by | SIEM or TIP | OVAL scanners | SIEM, NGFW, gateways |
| Answers: are we vulnerable | ✓ | ✓ | ✕ |
| Answers: are we under attack | ✕ | ✕ | ✓ |
| Scans Windows files directly | ✕ | ✓ | ✕ |
This is data, not a security product: without a SIEM, a threat intelligence platform or Kaspersky CyberTrace to ingest and match it, the feed produces nothing, so buying it before that layer exists is the most common wasted purchase in this category. Vendor coverage is driven by customer demand, with Siemens, Schneider Electric, Yokogawa and Emerson named by Kaspersky and further vendors added over time, which means you should check your own PLC, SCADA and DCS vendors against the current coverage before ordering rather than after. If your workflow is file-level scanning of Windows engineering workstations, the OVAL variant is a separate feed and this one will not do that job. On regional availability, no Swiss restriction applies and Kaspersky Threat Intelligence products are outside the scope of the United States prohibition, but the German BSI warning against Kaspersky software and country-of-origin clauses in customer or public sector contracts can still block procurement, so check contractual constraints before the technical evaluation.
No. The feed supplies knowledge about which software versions are vulnerable; it never touches your network and never interrogates a device. Matching that knowledge to your actual installed base requires an asset inventory from your SIEM, CMDB or OT monitoring tool.
No. The feed is delivered in JSON, CSV, STIX and OpenIoC and is designed for third-party platforms, with documented integrations including IBM QRadar, Splunk Enterprise Security, ArcSight ESM, RSA NetWitness, MISP, Anomali ThreatStream, ThreatQ, EclecticIQ and Microsoft Sentinel. Kaspersky protection software is not a prerequisite.
Kaspersky documents for its ThreatConnect integration that where an entitlement covers both the ICS Vulnerability Data Feed and the general Vulnerability Data Feed, only the ICS feed is processed. Check the behaviour of your own platform before licensing both, so you do not pay twice for data that is only consumed once.