What are the key advantages of Kaspersky Industrial CyberSecurity for Nodes Server Enterprise?
Central management – Policies and tasks run from Kaspersky Security Center.
Server nodes – Covers SCADA, historian and gateway server roles.
Launch control – Default deny stops unapproved software on nodes.
PLC integrity – Checks controller projects against a stored benchmark.
Legacy support – Runs on Windows versions back to XP SP2.
Important note – Network monitoring needs KICS for Networks, sold separately.
Anti-malware protection – Real-time file protection plus anti-cryptor defence on server nodes.
Application Launch Control – Default deny rules limit which executables may start.
Device and Wi-Fi control – Governs USB media and wireless connections on protected nodes.
PLC Project Integrity Check – Compares controller projects with a previously uploaded reference copy.
System monitoring tools – File integrity control, Windows log inspector and registry monitor.
Important – Network traffic monitoring requires KICS for Networks, sold separately.
Kaspersky Industrial CyberSecurity for Nodes, usually shortened to KICS for Nodes, is the industrial endpoint component of the KICS platform, and this variant is licensed for server-class nodes such as SCADA servers, historian servers and gateways. It is not a standalone tool: policies, tasks and reports are administered through a Kaspersky Security Center administration server.
OT-aware presets – Ships with verified exclusions and settings for common ICS software.
No reboot needed – Installation, updates and upgrades run without restarting the node.
Statistics-only mode – Runs non-blocking first so rules are tuned before enforcement.
Air-gapped updates – Databases can be updated on networks without internet access.
Modular installation – Select only the components a given server role needs.
Legacy Windows coverage – Protects older server systems, with support starting at Windows XP SP2.
The deciding factor is not headcount but whether you operate separately administered production servers. A single plant with two SCADA servers can use this product, but it only pays off once an administration server exists to distribute policies and collect logs.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Server-class ICS nodes to protect | Few | ✓ | ✓ |
| This product fits | Limited | ✓ | ✓ |
No software product meets these requirements on its own. Under the revised Information Security Act, operators of critical infrastructure in Switzerland have been obliged since 1 April 2025 to report significant cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which affects energy, water, transport and comparable operators rather than every manufacturer. For that obligation the product supplies the raw material for a report: the Windows log inspector, file integrity control, registry monitor and the EDR agent record what happened on a node, and Kaspersky Security Center holds these events centrally so the 24-hour window is spent writing the report rather than collecting evidence. What it does not do is decide whether an incident is reportable, generate a BACS report, or see anything on the industrial network outside the protected nodes, which means detection of an attack that never touches a Windows server depends on other tools. Reporting also assumes the administration server retains events long enough, which is a configuration decision on your side, not a product property. This description is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No product creates compliance with the NIS 2 Directive, because the directive addresses organisational risk management rather than a software feature list. NIS 2 requires measures in categories including incident handling, business continuity and backup, supply chain security, access control policies, cryptography, security in system acquisition and maintenance, cyber hygiene and training, and procedures to assess whether the measures work. This product contributes to incident handling through detection, logging and response actions on protected nodes, to access control through Application Launch Control and Device Control, and to security in maintenance through PLC project integrity checks and file integrity control. It contributes nothing to backup and restore, encryption, staff training, supplier assessment or multi-factor authentication, and it produces no evidence that the measures were reviewed. Treat it as one technical control inside a management system, not as a substitute for one.
Switzerland has issued no warning and no ban. The Federal Office for Cybersecurity has stated that it warns only about products where it has confirmed technical indications of a security risk, that no misuse of Kaspersky software in Switzerland has been reported to it, and that no internal federal directive prohibits the products; Kaspersky also operates a transparency centre in Zurich. In Germany, the Federal Office for Information Security issued a public warning on 15 March 2022 recommending that the vendor's antivirus software portfolio be replaced with alternative products, stated at the time that it made no statement about the vendor's other products, and has confirmed that the warning remains in force, now under Section 13 of the BSI Act; it is a recommendation, not a sales ban, and Kaspersky has publicly demanded its withdrawal. In the United States the Department of Commerce prohibited new sales from 20 July 2024 and Kaspersky has stated that software updates including antivirus databases became unavailable there from 10 September 2024, a restriction that applies only to the United States. Kaspersky's position is that the decisions are political rather than the result of a technical assessment and that the company has no ties to any government; the authorities' stated concerns relate to jurisdiction and origin, not to measured detection performance in independent test series. In practice this matters most if you bid for public-sector contracts, supply German or US customers, or answer supply chain questionnaires that ask about vendor country of origin, and it is your risk decision to make.
Yes, for a defined block of items, and it is worth knowing which ones before you promise anything. It answers questions on malware protection for production servers, application allowlisting through Application Launch Control, removable media and wireless control, integrity monitoring of files and PLC projects, endpoint logging with central retention, and the ability to isolate a node or terminate a process during an incident. It does not answer questions on backup and restore, disk or file encryption, patch deployment, multi-factor authentication, awareness training, network segmentation evidence, or vulnerability scanning of network equipment, and the vendor's country of origin is itself a recurring questionnaire item you should expect. Where a customer insists on network-side evidence, the cheaper route is usually to extend within the same family, since KICS for Networks adds traffic analysis, asset discovery and the security audit against OVAL and XCCDF standards and integrates with the node agents you already run, rather than introducing a second vendor whose data you then have to correlate manually.
The most important regional point is the United States: Kaspersky has stated that updates including antivirus databases stopped being available there on 10 September 2024, while the products are sold and updated normally in Switzerland and the European Union, so a Swiss company with a US plant cannot standardise on this product across both sites. This licence covers a server-class node, and workstation nodes such as operator or engineering workstations are licensed separately, which is the single most common cause of a follow-up order. The application protects Windows nodes; Linux servers require Kaspersky Industrial CyberSecurity for Linux Nodes, a separate application, and PLC project integrity checks, exploit prevention, the log inspector and the registry monitor are documented as Windows-only. Kaspersky ties the available functions to the licence type and lists them on the licence certificate, so check that certificate against the components you plan to deploy rather than against a marketing page. Finally, this is protection and response for nodes, not backup: there is no restore path if ransomware reaches a historian database.
Kaspersky lists Siemens SIMATIC S7-300, S7-400, S7-400H, S7-1200 and S7-1500 as well as SIPROTEC 4, Schneider Electric Modicon M340 and M580, CODESYS V3 devices and Fastwel CPM723-01. The check works in two steps: a project is first uploaded from the controller as a benchmark, then a scheduled task compares the live project against it.
Yes. Kaspersky documents air-gapped database updates for KICS for Nodes, so signature and module updates can be brought into an isolated segment and distributed from the administration server. This is the normal deployment pattern in OT networks and does not require opening an outbound path from the production zone.
No. Kaspersky lists the KICS Portable Scanner, the installation-free variant used to scan isolated equipment and devices brought onto the site, as a separate item in the KICS line. This licence applies to a managed server node, so plan the portable scanning use case separately.