What are the key advantages of Kaspersky Industrial CyberSecurity for Nodes Workstation EDR Enterprise Base?
Central management – All nodes managed from Kaspersky Security Center.
Industrial EDR – Telemetry, root cause and response on workstations.
ICS controls – Device, application launch and PLC project integrity.
Low interference – No reboot for install, update or upgrade.
Legacy compatibility – Runs on Windows XP SP2 and later.
Important note – Server nodes and Linux need separate products.
ICS endpoint protection – Anti-malware, anti-cryptor and exploit prevention for Windows nodes.
EDR agent – Telemetry, attack spread path and response actions per node.
Application and device control – Launch control, USB rules, Wi-Fi and firewall management.
PLC project integrity check – Detects changes to Siemens, Schneider Electric and CODESYS projects.
Central management – Policies and tasks from Kaspersky Security Center on premises.
Important – Workstation nodes only; ICS servers and Linux need separate licences.
Kaspersky Industrial CyberSecurity for Nodes Workstation EDR Enterprise is the endpoint protection, detection and response layer of the Kaspersky Industrial CyberSecurity platform, licensed for Windows workstation-class nodes such as operator panels, HMIs and engineering workstations. It is managed centrally from Kaspersky Security Center, which you run on your own infrastructure, and Base identifies a new licence rather than the Renewal or Cross-grade variant of the same product.
Response without process risk – Actions do not touch the industrial process without operator intervention.
Root cause in hours – Attack spread path replaces manual log reconstruction after incidents.
Cross-endpoint IoC scan – One indicator checks every licensed node instead of individually.
No reboot rollout – Install, update and upgrade without a maintenance window reboot.
Air-gapped updates – Databases can be updated in networks without internet access.
Legacy node support – Runs on Windows XP SP2 machines still driving production.
Headcount is the wrong measure here. What decides it is whether you operate a Windows-based ICS or SCADA environment, and whether someone in your organisation will actually open and work the EDR alerts it produces.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | Rarely | ✓ | ✓ |
| Security questionnaire from large customers | Rarely | ✓ | ✓ |
| Staff available to triage EDR alerts | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The reporting obligation applies to operators of critical infrastructure, not to every industrial company: energy and water suppliers, transport operators, cantonal and communal authorities, and certain suppliers of hardware and software used by those operators. Since 1 April 2025 the revised Information Security Act requires an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a significant cyberattack, with a full report following within 14 days, and failure to report has been sanctionable since 1 October 2025. The EDR agent supports that deadline in one specific way: the collected telemetry and the attack spread path let an OT team establish what executed, on which node and in what order, which is exactly what the 24-hour decision depends on. File integrity monitoring, Windows event log inspection and the PLC project integrity check add the evidence that the 14-day follow-up report needs. What the product does not do is decide whether an incident is reportable, cover the network side of an attack, cover ICS servers or Linux nodes under this licence, or watch anything outside your own team's working hours. This description is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No product creates NIS 2 compliance, because the directive places obligations on the organisation and its management body, not on the software it buys. NIS 2 requires risk management measures across defined categories, among them risk analysis and information system security policies, incident handling, business continuity, supply chain security, security in acquisition and maintenance including vulnerability handling, basic cyber hygiene, cryptography, access control and multi-factor authentication. This product contributes to incident handling through detection, root-cause reconstruction and documented response actions on covered workstations, to cyber hygiene through application launch control and removable-device rules, and to vulnerability handling through the OVAL-based security audit, which identifies and reports weaknesses but does not remediate them. It contributes nothing to cryptography, access control, multi-factor authentication, business continuity, backup or supply chain security, and each of those needs a separate measure. Network-level detection and OT asset inventory, which several of these categories assume, come from Kaspersky Industrial CyberSecurity for Networks, a separate product that is not part of this licence.
On 20 June 2024 the US Department of Commerce, through its Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from entering into new transactions with US persons from 20 July 2024, and from providing signature or codebase updates or operating the Kaspersky Security Network in the United States from 29 September 2024. Reselling Kaspersky software or integrating it into other products was prohibited from the same date. That determination remains in force. Germany's Federal Office for Information Security has warned against the use of Kaspersky virus protection since March 2022 and confirmed that its warning stood after the US measures; it is a recommendation, not a sales ban. There is no sales ban in Switzerland or the European Union, where the products continue to be sold and updated. Kaspersky rejects these assessments as based on the geopolitical situation rather than on evidence of wrongdoing in its products, and points to its Global Transparency Initiative, which includes data processing and source code review facilities in Zurich. The authority measures rest on the vendor's jurisdiction and the risk that follows from it, not on published findings of malicious code. In practice this matters if your group has a US entity or US staff, if you bid for German public-sector contracts, or if your customers apply procurement rules that exclude vendors under Russian jurisdiction, which is common in exactly the critical-infrastructure supply chains this product is built for. No edition of the product changes that item.
Yes for the endpoint items, and it will also raise one item that no product can answer. It answers questions on malware protection for ICS nodes, application allowlisting, removable media and Wi-Fi control, host firewall management, file and registry integrity monitoring, Windows event log inspection, central policy management with role-based access in Kaspersky Security Center, and recurring vulnerability and configuration auditing against OVAL content. It also answers the detection and response question with something concrete: per-node telemetry, a reconstructed attack path and a record of the response actions taken. It does not answer questions on network monitoring or OT asset inventory, patch management, disk or removable-media encryption, multi-factor authentication and identity management, backup and restore, or continuous monitoring outside your own working hours, and under this licence it does not answer coverage questions for ICS servers or Linux nodes. It also does not close the vendor-jurisdiction and sanctions-exposure question described in the section above. To close the technical gaps, staying inside the same family is normally the cheaper route: the Server node licence covers ICS and SCADA servers, Kaspersky Industrial CyberSecurity for Linux Nodes covers Linux, and Kaspersky Industrial CyberSecurity for Networks covers the network and asset inventory items. Continuous monitoring has to be solved with people, either your own shift coverage or a managed service.
The decisive difference is the EDR agent: only the EDR variant collects endpoint telemetry, so only it lets you reconstruct how an incident developed and run response actions on the node from the console. Both variants install the same protection and control components, so the anti-malware, application launch control, device control and PLC project integrity capabilities are identical. Choose the non-EDR variant if you only need to prevent and block, and the EDR variant if you also have to explain afterwards what happened, which is what a reporting obligation or a customer incident review will ask for. Neither variant covers ICS or SCADA servers, which are licensed separately as Server nodes.
| Capability | Workstation | Workstation EDR |
|---|---|---|
| Anti-malware and exploit prevention | ✓ | ✓ |
| Application launch and device control | ✓ | ✓ |
| PLC project integrity check | ✓ | ✓ |
| Endpoint telemetry and root-cause analysis | ✕ | ✓ |
| Response actions from the console | ✕ | ✓ |
| Cross-endpoint IoC scan | ✕ | ✓ |
| ICS and SCADA servers covered | ✕ | ✕ |
The sharpest limitation is regional: under the US Department of Commerce prohibition the product cannot be supplied to or updated for US persons, which matters if your industrial group has a US site, a US parent or US staff on the plant network. The licence covers workstation-class Windows nodes only, so ICS and SCADA servers need the Server node licence and Linux nodes need Kaspersky Industrial CyberSecurity for Linux Nodes, and this is by far the most common cause of a follow-up purchase. Central management requires you to operate Kaspersky Security Center yourself, since there is no vendor-hosted cloud console for this product, so someone has to own and maintain that server. The product sees the endpoint only, which means network anomaly detection, traffic analysis and OT asset inventory come from Kaspersky Industrial CyberSecurity for Networks. There is no patch management, no encryption management, no mobile or email protection and no backup, and no managed monitoring service is included, so every alert is worked by your own team.
Kaspersky lists Siemens SIMATIC S7-300, S7-400, S7-400H, S7-1200 and S7-1500 as well as SIPROTEC 4, Schneider Electric Modicon M340 and M580, devices based on CODESYS V3, and Fastwel CPM723-01. The check detects changes to the PLC projects used in the industrial system, which is how unauthorised engineering changes become visible.
Yes. A detection-only mode is available, which lets you run the agent on sensitive nodes and collect findings before any blocking rule is switched on. Combined with the modular installation, where you select only the components you want, this is the usual way of introducing the product on a running line.