What are the key advantages of Kaspersky Industrial CyberSecurity for Networks Standard Server?
Central console – Own web interface, plus Kaspersky Security Center integration.
Passive monitoring – Reads mirrored SPAN traffic without touching production.
Asset inventory – Discovers PLCs, HMIs and their firmware versions automatically.
Anomaly detection – Flags unauthorised commands, new devices and protocol anomalies.
SIEM export – Forwards events via syslog to your SIEM.
Important note – Endpoint protection is sold separately as KICS for Nodes.
Server component – Central node that collects and analyses mirrored industrial traffic.
Web interface – Dashboard, asset list, network map and event table.
Intrusion detection – Rule sets plus ARP spoofing, scan and brute-force detection.
Deep packet inspection – Monitors process tag values against user-defined thresholds.
Vulnerability detection – Matches discovered devices against the CVE database.
Important – No endpoint protection; KICS for Nodes covers workstations and servers.
Kaspersky Industrial CyberSecurity for Networks is the network component of the Kaspersky Industrial CyberSecurity (KICS) platform and analyses copied OT traffic taken from switch SPAN ports, so it sends no packets into the process network. It is operated from its own web console and reports into Kaspersky Security Center, where several servers across sites can be monitored together.
Zero production impact – Monitoring is passive; TAP or SPAN feeds copied traffic.
Learning mode – Builds a baseline of normal communication before raising alarms.
Command control – Detects PLC start, stop and project download commands.
Traffic evidence – Stores packet captures for selected event types.
Distributed sites – Sensors feed one server; monitoring points cover several segments.
Role-based access – Operator accounts see events without changing configuration.
The deciding factor is not headcount but whether you run a process network with managed switches that can mirror traffic, and whether someone reviews the events. A workshop with unmanaged switches and no OT engineer cannot feed the product; a utility, plant or building automation operator with a documented network design can.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | By exception | ✓ | ✓ |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Managed switches with SPAN ports | Often missing | ✓ | ✓ |
| This product fits | ✕ | ✓ | ✓ |
The reporting obligation under the revised Information Security Act (ISG) has applied since 1 April 2025, and operators of critical infrastructure must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. Affected are organisations such as energy and water utilities, transport companies, listed hospitals, data centre and cloud providers, and cantonal and municipal administrations; the Cybersecurity Ordinance sets sector thresholds that exempt many smaller organisations. The product supports that deadline in one concrete way: the event table records the detection time, the asset entries name the affected devices, and the stored packet capture for the event type gives you the technical evidence, which is what turns a 24-hour deadline from a scramble into a form-filling exercise. What it does not do is decide whether the obligation applies to you, submit the report, or see anything outside the network segments you have connected to a monitoring point, and it registers nothing that happens on an endpoint unless a Kaspersky endpoint agent is installed and integrated. This text is general information and not legal advice; whether the reporting obligation applies to your organisation should be clarified with qualified counsel.
No product makes an organisation NIS 2 compliant, because the directive addresses management responsibility and processes, not software. NIS 2 requires essential and important entities to implement risk analysis and security policies, incident handling, business continuity and backup, supply chain security, security in acquisition and maintenance, procedures to assess effectiveness, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This product contributes to three of those categories in a directly demonstrable way: asset management, through the automatic OT device inventory; incident detection and handling, through intrusion detection and command control events; and effectiveness assessment, through scheduled reports and recorded network sessions. It contributes nothing to backup and business continuity, cryptography, multi-factor authentication, secure acquisition and maintenance, training, or supplier risk assessment, and it does not protect a single endpoint. The evidence it produces still has to be carried into your incident process by people.
In Switzerland, the Federal Office for Cybersecurity (BACS) has issued no warning and no sales restriction concerning Kaspersky. BACS has stated that it does not use the software itself, that there is no internal directive prohibiting it, that no misuse in Switzerland has been reported to it, and that each organisation must make its own risk assessment. In Germany, the Federal Office for Information Security (BSI) issued a warning against Kaspersky products in March 2022; it has since confirmed that the warning remains in force because it does not regard the risk situation as having changed, and Kaspersky is the only manufacturer on that list. In January 2026 Kaspersky formally demanded the withdrawal of that warning and reserved the right to legal steps. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 that prohibited new sales from 20 July 2024 and prohibited updates and operation of the Kaspersky Security Network for US persons from 29 September 2024; three Kaspersky entities were added to the Entity List. Kaspersky denies the allegations, points to its data processing in Zurich and its Global Transparency Initiative, and has offered independent review of its code and update mechanisms. Independent technical assessments of this specific product are unaffected: Kaspersky Industrial CyberSecurity for Networks holds an IEC 62443-4-1 certification for its secure development lifecycle, assessed by TÜV AUSTRIA. In practice this matters most if you sell into public sector contracts, if you are part of a group with US entities, if a German parent applies BSI guidance internally, or if your customers ask about vendor country of origin in supplier questionnaires; for a Swiss plant with no such ties, it is a documentation point rather than a blocker.
Partly, and it is worth knowing exactly which half. It answers the OT visibility block: you can show a maintained inventory of industrial devices, a network map of who talks to whom, continuous monitoring of the process network, intrusion detection with documented rule sets, identification of known vulnerabilities against the CVE database, role-based access to the console, and forwarding of security events to a SIEM by syslog. It answers none of the following: malware protection on endpoints, patch management, encryption of data at rest, multi-factor authentication, backup and recovery, awareness training, and documented incident response procedures, which is usually the largest section of the questionnaire. It also does not answer the item that increasingly appears in questionnaires from large industrial customers, namely the country of origin of your security vendors. To close the technical gaps, the cheaper route is normally to stay inside the same family rather than mixing vendors, because the components are pre-integrated: KICS for Nodes for endpoint protection and compliance audit, and the separately licensed Active Polling and Device Security Audit modules for detailed device data and rule-based audit scans. The process gaps cannot be bought and have to be written down by your own team.
The decisive difference is where each one sits: KICS for Networks watches the wire, KICS for Nodes watches the machine. This licence covers the network side only, so it will show you that an engineering workstation sent a project download to a PLC, but it will not stop malware running on that workstation. Most plants end up running both, because the two are designed to feed each other: KICS for Nodes can act as an endpoint sensor and enrich network alerts with host, process and user data. If you have to choose one first, network monitoring is the usual starting point in environments where installing agents on legacy control machines is restricted by the automation vendor.
| Capability | KICS for Networks | KICS for Nodes |
|---|---|---|
| Protects | OT network traffic | Windows and Linux hosts |
| Installed on | Dedicated Linux server | Operator and engineering machines |
| Malware protection | ✕ | ✓ |
| Network map and asset inventory | ✓ | Feeds data only |
| PLC command detection | ✓ | ✕ |
| Included in this licence | ✓ | ✕ |
There is a hard regional restriction: since the US Department of Commerce determination, Kaspersky may not sell to US persons and may not deliver updates or operate the Kaspersky Security Network there, so a group with US sites cannot standardise on this product across all locations. On platform coverage, the Server and sensors run on Linux only and there is no Windows installation, while the endpoints themselves stay unprotected unless you add KICS for Nodes. Two capabilities that buyers often assume are included require separate licence keys: Active Polling, which queries devices directly for complete configuration data, and Device Security Audit, which runs rule-based audit scans. Response is the third common follow-up cost: isolating a compromised host requires Kaspersky Endpoint Agent on that host plus additional licensing, and blocking at network level requires vendor-specific connectors configured against your existing switches. Finally, the Server itself accepts only a limited number of monitoring points, so covering more network segments means adding sensors, which are a separate product in the same family.
Yes. Databases and modules can be updated directly from Kaspersky servers, from update files copied in manually, or from a Kaspersky Security Center repository. For isolated plants the usual route is the Kaspersky Update Utility on an internet-connected machine outside the OT environment, with the files carried across to the repository.
Where SPAN or port mirroring is unavailable, a hardware network TAP connected to the cable can supply the copied traffic instead. Kaspersky also documents an SD-WAN variant for small remote sites where installing dedicated sensor hardware is not economical.
The KICS platform is stated by Kaspersky to be tested against more than 200 industrial control systems and devices, and the network side reads traffic rather than installing anything on the controllers, so obsolete equipment is monitored without being touched. Support for legacy operating systems is a documented design goal of the platform.