What are the key advantages of Kaspersky Industrial CyberSecurity for Networks Additional Sensor Base?
Central management – Configured from the KICS for Networks Server console.
Segment coverage – Monitors an OT segment the Server cannot reach.
Passive monitoring – Analyses mirrored traffic without touching control system operation.
Protocol visibility – Reads PLC commands and process parameters from traffic.
SIEM export – Events can be forwarded to a SIEM system.
Important note – Add-on; requires an existing KICS for Networks Server.
One additional sensor – Extends an existing KICS for Networks deployment by one node.
Eight monitoring points – One sensor can serve up to eight network interfaces.
Deep Packet Inspection – Reads industrial protocol commands and process parameters from traffic.
Asset discovery – Identifies devices and their parameters from mirrored network traffic.
Intrusion Detection rules – Flag attack indicators and anomalies in industrial network traffic.
Important – No separate console; the KICS for Networks Server is required.
This is an add-on for an existing Kaspersky Industrial CyberSecurity for Networks installation: it adds a sensor node that analyses a copy of industrial network traffic and forwards the analysis results to the KICS for Networks Server. Management is central, not per device: the sensor has no interface of its own and is configured from the Server web interface, which can also be reached through the Kaspersky Security Center Web Console.
Segment coverage – Monitors plants or lines the Server cannot reach directly.
Passive monitoring – Works from mirrored traffic without touching control system operation.
Central correlation – Sensor findings land in one Server database and console.
Remote site option – Traffic from remote sites can reach a central node.
SIEM export – Registered events can be forwarded to a SIEM system.
Attack technique mapping – Incidents map to MITRE ATT&CK for ICS techniques.
Company size matters less here than plant topology. The decisive question is whether you operate OT segments whose traffic cannot be mirrored to the existing KICS for Networks Server, for example a second production hall, a substation, or a remote pumping station.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | Often yes |
| NIS 2 in the European Union | Rarely | By sector | Often yes |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Several separate OT segments to monitor | Rarely | Sometimes | ✓ |
| This product fits | ✕ | Limited | ✓ |
The Swiss obligation applies to operators of critical infrastructure named in the revised Information Security Act (ISG), such as energy and drinking water supply, transport companies, hospitals on the cantonal lists, data centres, and cantonal and municipal administrations, not to every industrial company. Since 1 April 2025 those operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. An additional sensor supports that deadline in one concrete way: the monitored segment produces time-stamped events, device identification and stored traffic on the KICS for Networks Server, which is the material an initial report needs, namely when the activity started, which devices were involved, and which protocol commands were sent. It does not decide whether an incident is reportable, does not submit the report, and covers only the network segments where a monitoring point actually receives mirrored traffic. Endpoints, office IT and any segment without traffic mirroring stay outside its scope and need separate components. This text is not legal advice; whether your organisation falls under the reporting obligation should be assessed with your own legal counsel.
No product creates NIS 2 compliance, because the directive addresses organisational risk management, not a software feature list. The NIS 2 Directive requires categories of measures including risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, procedures to assess the effectiveness of measures, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. An additional sensor contributes to three of these: incident handling, through detection and event data from a segment that was previously unmonitored; asset management, through automatic device identification from traffic; and vulnerability handling, through per-device vulnerability data drawn from Kaspersky ICS CERT together with NVD and US-CERT sources. It contributes nothing to cryptography, multi-factor authentication, backup and continuity, staff training, supplier assessment, or the written policies and effectiveness reviews the directive expects. Those gaps have to be closed by other measures and other products.
Two official measures concerning the vendor are published and still in force. The German Federal Office for Information Security (BSI) has warned against the use of Kaspersky anti-virus software since 15 March 2022; the warning was originally issued under Section 7 of the BSI Act and has been regulated under Section 13 BSIG since 6 December 2025. The reasoning is jurisdictional rather than a finding of a specific technical defect: the BSI argues that a Russian IT manufacturer could itself act offensively, could be forced to act against its own intent, or could be compromised and used as a tool against its own customers. The United States Department of Commerce, Bureau of Industry and Security, issued a Final Determination on 20 June 2024 prohibiting Kaspersky and its affiliates from providing cybersecurity and anti-virus products or services to US persons; new agreements were barred from 20 July 2024, and resale, integration and updates from 29 September 2024. Kaspersky rejects the BSI warning, stating that it was not based on an objective technical analysis of the risks of using the company's software. In practice this affects buyers in three situations: German public sector bodies and organisations that follow BSI recommendations, any deployment involving US persons or entities, and supply chains where a customer contractually excludes security software of Russian origin. In Switzerland and the European Union the practical effect usually arrives through customer requirements and tender conditions rather than through a sales ban, so the decision belongs to the buyer and should be checked against your own contracts before purchase.
Partly, and only for the network monitoring block of a questionnaire. It lets you answer that OT assets are inventoried automatically from traffic rather than from a spreadsheet, that industrial network traffic is monitored for intrusion indicators and unauthorised interactions, that events are logged centrally and can be forwarded to a SIEM, and that known vulnerabilities are identified per device. It does not answer questions on endpoint anti-malware, patch management, disk or removable media encryption, multi-factor authentication and access control, backup and restore testing, awareness training, or a documented incident response process, because it performs none of those functions. It also cannot evidence coverage of segments where no monitoring point receives mirrored traffic, which is the point auditors probe most often. Where the gaps are on the OT side, adding Kaspersky Industrial CyberSecurity for Nodes within the same platform is usually the cheaper route than introducing a second vendor, because endpoint and network events then arrive in the same console and one export answers both question blocks.
The decisive difference is that KICS for Networks never touches the protected device: it analyses a copy of network traffic, while KICS for Nodes runs as software on the endpoint itself. That makes an additional sensor the right choice for controllers, IEDs and equipment where no agent may be installed, and the wrong choice if the actual gap is malware on engineering or operator workstations. The two are components of the same Kaspersky Industrial CyberSecurity platform and are designed to be used together, with endpoint telemetry from KICS for Nodes enriching the asset data that KICS for Networks builds from traffic. Buying one does not include the other.
| Property | KICS for Networks | KICS for Nodes |
|---|---|---|
| Software runs on the protected device | ✕ | ✓ |
| Requires mirrored traffic | ✓ | ✕ |
| Sees PLC commands and process parameters | ✓ | Limited |
| Anti-malware protection on endpoints | ✕ | ✓ |
| Covers devices that allow no agent | ✓ | ✕ |
This is an add-on and not a starting point: it requires an existing Kaspersky Industrial CyberSecurity for Networks deployment, only one Server is used per deployment, and a sensor cannot be installed on the machine that performs Server functions. It sees only what is mirrored to it, so every monitoring point has to be attached to a network interface that actually receives a copy of industrial traffic; a segment without a SPAN port or TAP produces no data at all, which is the most frequent cause of a follow-up purchase of network hardware rather than software. The architecture is also capped: up to eight monitoring points can be added on a sensor and up to four on the Server, and the deployment as a whole has an upper limit that depends on the version, so very large plants need several sensors rather than one. Regionally, the product is not available to buyers in the United States, where the Commerce Department prohibition has covered resale, integration and updates of Kaspersky cybersecurity software since 29 September 2024; German public sector buyers should also read the BSI section above before ordering. Finally, this component detects and records, it does not protect endpoints and does not block, so it never replaces endpoint software in the OT network.
In Kaspersky's business naming, Base marks an initial licence type, in contrast to the renewal and successive types the vendor uses for continuing an existing entitlement. It says nothing about the feature set: a Base sensor and a renewed sensor deliver identical functionality.
No. Kaspersky Industrial CyberSecurity for Networks can be monitored centrally from the Kaspersky Security Center Web Console through an administration plug-in, and the sensor's data appears there once that integration exists. The additional sensor itself provides no console and does not establish that integration.