What are the key advantages of Kaspersky Industrial CyberSecurity for Networks Additional Sensor?
Centrally managed – Controlled from the existing KICS for Networks server.
Add-on licence – Requires an existing KICS for Networks server.
Passive monitoring – Reads mirrored traffic without touching the process network.
Wider coverage – Extends visibility to additional OT network segments.
Monitoring points – Up to eight per sensor node.
Important note – No endpoint protection; KICS for Nodes covers that.
Additional sensor licence – Adds one more sensor node to an existing deployment.
Database and module updates – Keeps traffic analysis and detection rules current.
Manufacturer technical support – Support entitlement at the Enterprise product level.
Passive traffic analysis – Reads mirrored OT traffic without touching the process network.
Monitoring point capacity – Up to eight monitoring points per sensor node.
Important – No management console of its own; the server holds it.
This is an add-on licence for one further sensor node in an existing Kaspersky Industrial CyberSecurity for Networks system, which analyses a copy of industrial network traffic to detect device activity, system commands to controllers and deviations in process parameters. Sensors have no console of their own: they forward analysis results to the single KICS for Networks Server, which is monitored through the Kaspersky Security Center web console.
Remote segment coverage – Reaches OT segments the central server cannot see.
No process interference – Analyses copied traffic, so controllers and PLCs stay untouched.
Automatic asset discovery – Devices on the new segment appear in the network map.
PLC project tracking – Records controller project reads and writes for later comparison.
One policy set – All sensors stay under the same server configuration.
Traffic kept as evidence – Stores the traffic belonging to registered events.
The deciding factor is not headcount but topology: this licence only makes sense if an OT network already exists, a KICS for Networks Server is already licensed, and there is at least one production segment whose traffic cannot physically reach that server. A single-site workshop with one switch does not need a second sensor. A plant with separate lines, a substation, a pumping station or a remote utility area does.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Rare | ✓ | ✓ |
| OT segments unreachable by the server | ✕ | Sometimes | ✓ |
| This product fits | ✕ | Partial | ✓ |
In Switzerland the reporting duty under the revised Information Security Act applies to operators of critical infrastructure, not to every company that runs an industrial network, so the first question is whether your organisation falls into one of the named sectors at all. Operators who are covered must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. The sensor supports that deadline in one concrete way: it registers events with timestamps and stores the traffic belonging to them, so the initial report can name the affected segment and the observed activity instead of describing a suspicion. What it does not deliver is the organisational half of the obligation, namely a defined incident response process, named reporting roles, the assessment of whether an incident is reportable, and evidence from workstations and servers, which would require an endpoint product. It also produces no report template and no legal classification of the event. This text is informational and does not constitute legal advice.
No product creates NIS 2 compliance, because the directive addresses entities and their management processes rather than software. NIS 2 requires risk analysis and security policies, incident handling, business continuity, supply chain security, security in network and information systems including vulnerability handling, access control and asset management, cryptography, and human resources security. This add-on contributes to two of those categories: security in network and information systems, through continuous analysis of industrial traffic on the additional segment, and asset management, through automatic discovery of the devices communicating there. It contributes nothing to business continuity, cryptography, access control across the organisation, human resources security or supplier assessment. Incident reporting under the directive also stays organisational, since the sensor supplies the technical evidence but not the decision to report, the deadlines or the recipients.
Germany's Federal Office for Information Security has warned against the use of Kaspersky virus protection software since 15 March 2022. The warning remains in force; it was archived after six months, which does not invalidate it, and the office has stated it sees no reason to change it. Its wording refers to antivirus software, and the office has not publicly clarified whether OT monitoring products are covered. In the United States, the Department of Commerce issued a Final Determination in June 2024: Kaspersky has been prohibited from new sales to US persons since 20 July 2024 and from supplying signature and database updates since 29 September 2024, and that prohibition is still in force. Kaspersky rejects the assessments as political rather than technical, points to its Global Transparency Initiative including data processing in Switzerland, and has publicly demanded that the German warning be withdrawn. The assessments concern the manufacturer's country of origin and legal jurisdiction, not a published technical defect in the products. In Switzerland, the Federal Office for Cybersecurity has issued no warning and has stated that it does not issue recommendations on the use of individual products. In practice this matters most for public sector tenders, for organisations with a German parent company or German customers, for group structures with a US entity, and for supplier questionnaires that ask about vendor origin.
Partly, and only for the network section. It answers questions about whether OT traffic is monitored continuously, whether an inventory of industrial devices exists, whether communication between controllers is checked against defined rules, whether anomalies in process parameters are detected, whether events are logged with the associated traffic retained, and whether events can be forwarded to a central system. It answers none of the following: malware protection and detection and response on OT hosts, patch and vulnerability status of endpoints, backup and restore testing, encryption of data at rest or in transit, multi-factor authentication and privileged access management, security awareness training, and the assessment of your own suppliers. It also cannot be used to prove that a control is enforced, since it observes rather than blocks. The cheapest route to closing the endpoint gap is usually to stay inside the same family and add Kaspersky Industrial CyberSecurity for Nodes, which delivers protection and response on industrial workstations and servers and feeds its data back into the same server, rather than introducing a second vendor and a second console.
The decisive difference is that only one server exists per deployment, while sensors are the part you scale. The server receives, processes and stores data and provides it to users; a sensor receives and analyses traffic from the network interfaces of its own node and forwards the results to that server. A sensor cannot be installed on a node that performs server functions, so each additional sensor occupies a separate node. This listing is the sensor licence, not the server.
| Property | Standard Server | Additional Sensor |
|---|---|---|
| Role in the deployment | Central server | Traffic collector |
| Number per deployment | One only | Several |
| Monitoring points per node | Up to 4 | Up to 8 |
| Stores events and device data | ✓ | ✕ |
| Contained in this listing | ✕ | ✓ |
The most important regional limitation is the United States: since the Final Determination of the US Department of Commerce, Kaspersky may not sell to US persons and may not deliver database updates there, so a US site inside an international group cannot be covered by this licence and needs a different product. This is an add-on and does nothing on its own, because sensors are managed by the server and forward their analysis results to it. It detects rather than prevents, so it will register an unauthorised command to a controller but will not stop it, and any response on the endpoints requires Kaspersky Industrial CyberSecurity for Nodes. Traffic also has to physically reach the sensor through port mirroring or a network tap, and a segment without that infrastructure stays invisible no matter how many licences are purchased. Finally, when events are transmitted to recipient systems other than Kaspersky Security Center, the application does not guarantee the security of that transfer, so a protected path to a SIEM has to be provided separately.
No. A sensor cannot be installed on a node that performs server functions, so every additional sensor occupies its own node. Plan the node before ordering the licence.
Base is the licence for a sensor that is not yet covered, which is the variant listed here. Renewal continues an existing entitlement for the same product and is the wrong choice if you are adding a sensor for the first time.
No. It analyses a copy of the traffic for signs of attacks without affecting the industrial network, registers events and saves the associated traffic. Blocking has to come from network controls or from endpoint protection.