What are the core benefits of Kaspersky Industrial CyberSecurity for Networks Standard Server Updates and Support Enterprise Base?
Central console – On-premises web interface, plus Kaspersky Security Center integration.
Passive monitoring – Reads mirrored SPAN traffic without touching control processes.
Asset inventory – Automatic OT device discovery, passive and active methods.
Rule updates – Keeps intrusion detection and SCADA vulnerability data current.
Vendor support – Direct manufacturer assistance for covered Server nodes.
Important note – No endpoint protection; KICS for Nodes needed separately.
Download: Kaspersky Industrial CyberSecurity for Networks Standard Server Updates and Support Enterprise Base
Passive traffic analysis – Deep packet inspection of mirrored industrial network traffic.
Automatic asset inventory – Discovers OT devices using passive and active collection methods.
Intrusion detection rules – Updated attack signatures plus the ICS CERT vulnerability database.
Command control – Inspects commands sent over industrial protocols between devices.
SIEM and API export – Forwards events via Syslog, CEF, OPC and IEC 104.
Important – No endpoint protection; that requires KICS for Nodes separately.
Kaspersky Industrial CyberSecurity for Networks is the network monitoring component of the KICS platform, shipped as software or as a virtual appliance and run on premises from its own web interface or through Kaspersky Security Center. The Standard Server Updates and Support Enterprise Base package covers the update and technical support component for KICS for Networks Server nodes and is the initial purchase rather than a renewal.
No process impact – Monitoring runs on mirrored traffic, never inline.
Detection stays current – New attack rules reach the Server without manual research.
OT risk scoring – Ranks device vulnerabilities and suggests concrete remediation steps.
Network topology maps – Replaces hand-drawn diagrams with a live communications map.
Agentless node auditing – Checks network hardware against OVAL and XCCDF baselines.
Single vendor stack – Shares telemetry with KICS for Nodes endpoint agents.
The deciding factor is not headcount but whether you run an Ethernet-based automation network with managed switches that can mirror traffic. A single production line with unmanaged switches has nowhere to attach a monitoring point, which rules the product out regardless of company size.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | ✓ |
| NIS 2 in the European Union | Rare exceptions | By sector | ✓ |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Mirrored OT traffic available | Rarely | Partial | ✓ |
| This product fits | ✕ | Larger sites | ✓ |
The obligation applies to operators of critical infrastructure named in Article 74b of the revised Information Security Act, including energy and water supply, transport, healthcare and communication providers, not to industrial companies in general. Since 1 April 2025 these operators must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. KICS for Networks supports that deadline in one specific way: it timestamps detected anomalies, intrusion signatures and unauthorised device communications in the OT network and exports them via Syslog or CEF, so the initial report can be based on recorded events instead of operator recollection, and the topology and communications map shortens the impact assessment for the follow-up report. What it does not do is decide whether an incident is reportable, submit the report, or cover any endpoint, server or IT-side event, because it only sees what appears in mirrored network traffic. It also provides no incident response process, no business continuity documentation and no evidence of organisational measures, all of which the Act expects alongside the technical detection. This overview is for orientation only and does not replace legal advice.
No product creates NIS 2 compliance, because the Directive addresses organisational risk management rather than a list of approved tools. NIS 2 requires essential and important entities to implement measures across defined categories, among them risk analysis, incident handling, supply chain security, vulnerability handling, asset management, access control and procedures to assess whether the measures actually work. KICS for Networks contributes to four of those categories in a directly demonstrable way: automatic asset inventory for asset management, OT-specific vulnerability and risk scoring for vulnerability handling, network anomaly and intrusion detection for incident handling, and OVAL and XCCDF audit reports as evidence when effectiveness has to be assessed. It contributes nothing to cryptography, access control for user accounts, human resources security, multi-factor authentication, business continuity planning or backup, and it does not assess your suppliers. Entities that treat the network monitor as their NIS 2 answer will fail on the organisational categories, which is where most of the Directive's weight sits.
Two official measures are in force and both are relevant to procurement. Germany's Federal Office for Information Security (BSI) issued a product warning on 15 March 2022, originally under Section 7 of the BSI Act and, since the amendment that took effect on 6 December 2025, regulated under Section 13. The BSI recommends replacing applications from Kaspersky's antivirus software portfolio with alternative products, and states explicitly that it made no assessment of the manufacturer's other products, which means KICS for Networks was not the subject of that warning. Separately, the US Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from supplying cybersecurity products and services to US persons; new agreements were barred from 20 July 2024, and from 29 September 2024 signature and codebase updates and operation of the Kaspersky Security Network in the United States were prohibited. This measure is worded broadly enough to cover cybersecurity products generally, not only antivirus. Kaspersky rejects both measures as politically motivated, points to its Global Transparency Initiative with threat data for European customers processed in two data centres in Zurich, Transparency Centres for source code review, ISO 27001 certification of its data services and a SOC 2 Type II audit, and holds more than 100 interoperability certificates from automation vendors. No comparable Swiss federal sales ban or product warning has been published. In practice this matters most to public-sector tenders, to groups with US entities or US-person staff, to organisations whose German parent or customers apply BSI guidance, and to anyone answering supply chain questionnaires that ask about vendor jurisdiction; for a privately held Swiss manufacturer with no such exposure it may not matter at all. The decision is yours to make against your own contract and tender requirements.
Yes, for the OT visibility and detection sections, and not at all for the rest. It answers questions on OT asset inventory and how it is kept current, on whether network segmentation is monitored and verified in practice, on OT vulnerability identification and prioritisation, on detection of unauthorised devices and unauthorised communications, on logging and whether security events reach a SIEM, and on documented audit of network hardware against OVAL and XCCDF baselines. It answers nothing on endpoint anti-malware, on host-level response such as isolation or process termination, on patch deployment, on disk or removable media encryption, on multi-factor authentication, on backup and restore testing, on mobile device management, on identity and access governance, or on staff awareness training. Those are usually more than half of a large customer's questionnaire. The cheapest way to close the largest of these gaps is to add KICS for Nodes from the same family, which brings anti-malware, device and application control, file and PLC integrity control and EDR response to the automation endpoints and feeds its telemetry back into the same KICS for Networks asset base, rather than introducing a second vendor's endpoint agent that will need its own console, its own exclusions and its own compatibility testing against your automation software.
The decisive difference is that KICS for Networks installs nothing on your automation equipment and KICS for Nodes does. KICS for Networks watches a copy of the network traffic and can therefore cover PLCs, IEDs and embedded controllers that will never accept an agent, but it can only see what those devices transmit. KICS for Nodes runs as an agent on Windows and Linux workstations, servers, gateways and historians and is the only one of the two that can block malware or stop a process. They are designed to run together: the endpoint agent acts as a sensor and sends host telemetry into the same asset base the network monitor maintains.
| Capability | KICS for Networks | KICS for Nodes |
|---|---|---|
| Deployment model | Passive sensor | Endpoint agent |
| Covers agentless OT devices | ✓ | ✕ |
| Deep packet inspection | ✓ | ✕ |
| Command control over industrial protocols | ✓ | ✕ |
| Anti-malware protection | ✕ | ✓ |
| Response actions on hosts | ✕ | ✓ |
| OVAL and XCCDF compliance audit | ✓ | ✓ |
The most important regional restriction is that Kaspersky may not supply cybersecurity products or services to US persons, and the Kaspersky Security Network may not be operated on US systems, so a group with US entities cannot standardise on this product worldwide. Technically, the product only sees traffic you can mirror to it: unmanaged switches, serial links and point-to-point connections without a mirror port stay invisible, and covering several plants or remote substations means adding sensors or remote collectors on top of the Server licence, which is the most common follow-up purchase. It runs on premises on Linux and is administered through its own web interface or Kaspersky Security Center, so there is no cloud-managed or vendor-hosted option and someone in the team has to be comfortable with Linux operations. Detection is passive by design, which is why it does not disrupt processes but also means it will not block an attack; anything on the endpoint itself, from malware execution to USB usage, is outside its scope and needs KICS for Nodes.
No. Application components receive a copy of industrial network traffic from monitoring points, typically a switch mirror port, so no traffic passes through the Server and a failure of the monitoring system cannot interrupt the process.
Yes. Kaspersky Industrial CyberSecurity for Networks can receive updates from a Kaspersky Security Center Administration Server, so the monitoring Server in the OT segment does not need its own route to Kaspersky update servers.
Yes. Asset inventory uses both passive and active data gathering, so PLCs, IEDs and embedded controllers are identified from their network activity, and network hardware can additionally be audited agentlessly for vulnerabilities and configuration compliance.