What are the key benefits of “Kaspersky Industrial CyberSecurity for Nodes Portable Scanner Enterprise Base”?
Standalone tool – Runs on each device; no central console required.
Deployment via USB – Scans isolated OT devices without requiring any installation.
Audit scans – Includes inventory, vulnerability assessment, and security settings review.
Device-specific reports – A separate text report for each scanned computer.
Older Windows versions – Supports hosts dating back to Windows 2000 SP4.
Important note – On-demand only; requires a KICS for Nodes license.
Portable Scanner License – Activates the USB scanner integrated into KICS for Nodes.
On-Demand Malware Scan – Performs disinfection by default and removes the object if disinfection fails.
Host Assessment Scans – Inventory, vulnerability, compliance, and security settings checks per host.
Traffic Logging – Records incoming and outgoing traffic over a defined period.
Device-Specific Text Report – A report file is created for each scanned device.
Important – No central console and no real-time protection for scanned devices.
This is the license that unlocks the “Portable Scanner” component of “Kaspersky Industrial CyberSecurity for Nodes”: The scanner is copied from a host with “KICS for Nodes” installed to a USB flash drive and then transported to computers that are not accessible via the network. The scanner itself has neither an agent nor a management console, so each device is scanned locally via the command line and creates its own report file on the drive.
No installation required—Nothing is written to the HMI or SCADA host.
Works completely offline—Databases are updated from a local folder, not from the Internet.
Scanning of contractor laptops—Scan third-party devices before they enter the facility.
Support for older Windows versions – Anti-malware scans for hosts running as far back as Windows 2000 SP4.
Reusable across devices – A single USB drive scans multiple hosts in a single pass.
Written documentation – A time-stamped report file for each host for the audit file.
The size of the company is not the right first question to ask here. The key factors determining suitability are whether you’re already using KICS for Nodes and whether you have production hosts that cannot be reached by a network scan. A water utility with two employees and three air-insulated HMIs is better suited than an office-based company with 500 employees that doesn’t have such devices.
| Requirements | Small Business | Medium-Sized Company | Large enterprise |
|---|---|---|---|
| Reporting Requirement in Switzerland | By Industry | By Industry | By Industry |
| NIS 2 in the European Union | Rare | By sector | By sector |
| Security questionnaires from major clients | Increasingly | ✓ | ✓ |
| isolated OT hosts to be checked | Some | ✓ | ✓ |
| This product is suitable | Only with KICS | ✓ | ✓ |
Since April 1, 2025, the revised Information Security Act (ISG) requires operators of critical infrastructure to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of their discovery, with any missing information to be submitted within 14 days; as of October 1, 2025, failure to report may result in penalties. Affected organizations include energy and drinking water utilities, transportation operators, and cantonal and municipal administrations; thus, a facility operator with OT systems is likely to be subject to this requirement, whereas a general engineering firm generally is not. The Portable Scanner supports the reporting requirement in a limited but concrete way: If you suspect an incident on an isolated controller or an engineering workstation, it provides you with a dated, host-specific report detailing the findings—exactly the kind of concrete details required for a report within 24 hours. What it does not do, however, is detect the incident itself, since it only runs when someone connects and starts the drive, and does not send data to BACS, a SIEM, or an administrative console on its own. Detection, alerting, log retention, and the reporting process itself must be ensured through installed protective measures, network monitoring, and an internal procedure that specifies who is responsible for filing a report within 24 hours. This text does not constitute legal advice; have your specific reporting obligations reviewed by a qualified advisor.
No product ensures NIS 2 compliance on its own, and any vendor claiming otherwise is exaggerating. The NIS 2 Directive requires affected organizations to conduct a risk analysis and establish policies regarding information system security, incident response, business continuity, supply chain security, security in procurement and maintenance, vulnerability management, policies for evaluating the effectiveness of measures, basic cybersecurity hygiene, and asset management. The Portable Scanner contributes to some of these areas: Its inventory and vulnerability assessments support asset management and vulnerability management for hosts that a network scanner cannot reach, and its per-host reports are useful for assessing whether measures in production are actually working. It does not contribute to incident response, business continuity, access control, supply chain governance, or the management accountability expected by the policy, and it cannot serve on its own as a security measure for a device. Treat it as a tool for gathering evidence within a program, not as a standalone category of measures.
On March 15, 2022, the Federal Office for Information Security (BSI) issued a formal warning against the use of Kaspersky antivirus software and recommended replacing it with alternative products. The warning remains published and in effect; since the German NIS-2 Implementation Act took effect on December 6, 2025, it is subject to Section 13 of the BSIG and no longer to the former Section 7. Separately, in June 2024, the Bureau of Industry and Security of the U.S. Department of Commerce issued a final decision prohibiting Kaspersky from supplying software to U.S. persons and banning new contracts effective July 20, 2024, as well as signature and codebase updates effective September 29, 2024. Switzerland has not taken any comparable measures: BACS does not issue recommendations for or against individual products, has no internal policy banning Kaspersky, and has stated that no misuse of Kaspersky software has been reported to it in Switzerland. Kaspersky rejects the allegations, pointing to its “Global Transparency Initiative,” the relocation of customer data processing to Switzerland, and a transparency center in Zurich, and has proposed an independent third-party review of its products and updates. The independent tests continued in the AV-TEST and AV-Comparatives cycles of 2025 and 2026. In practice, this is particularly important if you sell to the German public sector, have contracts with a customer whose procurement guidelines exclude software of Russian origin, or operate in a jurisdiction subject to the U.S. decision; for a Swiss private-sector operator without such a clause, this is more of a documented risk that must be weighed than a legal hurdle.
To some extent, and even then only for a handful of points. It provides you with a solid answer to questions about how you scan systems on which no agent can run, how removable media and contractors’ devices are scanned before they enter production, and whether you maintain records of these scans per device—since each scan generates a dated report file that lists the host and the results. It also addresses questions regarding asset inventory and vulnerabilities on air-gapped hosts. However, there are no answers regarding real-time protection, centrally enforced policies, patch management, encryption, access control, log retention, SIEM export, or incident response times; and a questionnaire asking for centrally managed endpoint protection with reporting cannot be fulfilled by an on-demand USB tool. The more cost-effective way to close these gaps is typically to fully deploy “KICS for Nodes,” which you need anyway to use this license—managed via the Kaspersky Security Center—rather than adding an agent from a second vendor to the OT hosts, which would then have to be retested for process compatibility. If a questionnaire also asks about restrictions regarding the vendor’s country of origin or the country of development, answer this question separately and honestly, rather than referring to the product data sheet.
The key difference is that “KICS for Nodes” provides continuous protection, while the Portable Scanner only performs a scan when launched by a user. “KICS for Nodes” is installed on the industrial endpoint, performs real-time file protection, application launch control, device control, and integrity checks on PLC projects, and is centrally managed via the Kaspersky Security Center. The Portable Scanner does not install anything on the target system: It is copied to a USB drive from a computer already running KICS for Nodes, launched via the command line with local administrator privileges on the device to be scanned, and writes its results to a text file on the USB drive. These are not alternatives. The license for the Portable Scanner can only be used if a valid KICS for Nodes license is also available; therefore, it is purchased to extend an existing deployment to computers on which no agent can be installed.
| Features | Portable Scanner | KICS for Nodes |
|---|---|---|
| Protection Model | On-demand | Continuous |
| Installed on the scanned host | ✕ | ✓ |
| Real-time file protection | ✕ | ✓ |
| Central management console | ✕ | ✓ |
| Application and device control | ✕ | ✓ |
| Integrity checking of PLC projects | ✕ | ✓ |
| Can be used on agentless or air-gapped hosts | ✓ | Limited |
| Data traffic logging during verification | Partially | ✕ |
First, you should check the regional restrictions: According to the final decision by the U.S. Bureau of Industry and Security, Kaspersky software may not be supplied to U.S. persons and has not received any signatureor codebase updates, so this license is not an option for a U.S. company or a group with a U.S.-focused supplier policy. Platform support is limited to Windows; industrial Linux nodes are covered by the separate product “Kaspersky Industrial CyberSecurity for Linux Nodes,” and traffic logging is not available on every supported Windows version, including some Windows Server 2022 builds. The scanner cannot be used on its own, as it requires a valid KICS for Nodes license; this is the most common reason why a single purchase ends up becoming two. There is no central console for the scanner and no automatic collection of results, so someone must go through the drive and manually collect the report files—which is manageable with a dozen hosts but becomes tedious with a hundred. Finally, the antivirus databases must be up to date before a scan can be run, which means an offline update must be scheduled as part of the routine, rather than assuming the drive will be ready for use immediately when needed.
“Base” refers to Kaspersky’s method of issuing a new license, as opposed to “Renewal,” which extends an existing license for the same product, and “Cross-grade,” which migrates a customer from a competing product. Select “Base” if you are licensing the Portable Scanner for the first time.
The scanner is launched via a command-line interpreter with local administrator privileges on the target device. If the drive was created as a secure removable storage drive, the administrator password specified during creation is also required before the scan begins.
The scanner has a special update mode that retrieves database updates from a specified local folder instead of from the Internet. In practice, you update the drive from a connected computer on the office network before taking it to the factory.