What are the key advantages of Kaspersky Industrial CyberSecurity for Nodes Workstation Enterprise Base?
Central management – Policies and tasks via Kaspersky Security Center.
Industrial endpoints – Protects HMIs and engineering workstations in ICS networks.
Default deny – Applications Launch Control blocks unapproved executables.
Device control – Regulates USB and removable drive connections.
PLC integrity – Checks controller projects for unauthorised changes.
Important note – EDR and Linux nodes need separate licences.
Real-Time File Protection – Scans files on access, with Anti-Cryptor against remote encryption.
Applications Launch Control – Default deny rules limit which executables may start.
Device Control – Regulates USB and other external devices per policy.
PLC Project Integrity Check – Verifies controller projects against a stored reference state.
System Inspection – File Integrity Monitor, Registry Access Monitor and Log Inspection.
Important – EDR is a separate KICS for Nodes licence tier.
Kaspersky Industrial CyberSecurity for Nodes is the Windows endpoint agent of the KICS platform, and the Workstation licence covers operator stations, HMIs and engineering workstations rather than SCADA servers. It is managed centrally from Kaspersky Security Center, the same on-premises console used for other Kaspersky business products, and Base means a new licence rather than a Renewal or Cross-grade of an existing one.
Legacy Windows support – Covers embedded and IoT builds still running production lines.
ICS compatibility – Designed for use alongside SCADA, PLC and DCS.
Portable Scanner – Inspects isolated nodes from a prepared removable drive.
Network Attack Blocker – Stops port scans, brute force and exploit traffic.
Windows Firewall management – Enforces host firewall rules and blocks local changes.
SCADA status reporting – Kaspersky Security Gateway forwards protection status to SCADA.
The deciding factor is not headcount but whether you operate Windows-based control room or engineering workstations that a standard office endpoint product cannot be installed on without risking the process. Small workshops with a single unmanaged HMI usually cannot justify the management console; from a handful of nodes upwards, central policy control becomes the reason to buy.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | Increasing | ✓ | ✓ |
| Windows HMI or engineering nodes on site | Often | ✓ | ✓ |
| This product fits | Partly | ✓ | ✓ |
No security product on its own satisfies the revised Information Security Act, because the obligations attach to the organisation and not to the software. The reporting obligation applies to designated operators of critical infrastructure, who must submit an initial report of a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the practical question is whether you would notice an incident on a control room workstation in time to report it. Kaspersky Industrial CyberSecurity for Nodes supports that in three concrete ways: File Integrity Monitor and Registry Access Monitor record unauthorised changes on the node, Log Inspection evaluates Windows event logs, and every detection is written to Kaspersky Security Center, where it can be retrieved as a dated report for the reporting file. What it does not do is produce the report, establish an incident response process, monitor OT network traffic between controllers, or cover Linux nodes and the network layer, all of which need additional products and internal procedures. Determining whether your organisation falls under the reporting obligation at all is a legal question, and this text is not legal advice.
No product creates NIS 2 compliance, because the directive requires risk management measures at organisational level and holds management accountable for them. The measure categories it names include risk analysis and information system security policies, incident handling, business continuity and backup, supply chain security, security in acquisition and maintenance, cyber hygiene and training, access control and asset management, and multi-factor authentication. This product contributes to a defined subset: malware protection and application control on industrial endpoints, control of removable media, integrity monitoring of files, registry and PLC projects, and central evidence of policy enforcement. It contributes nothing to business continuity and backup, supplier assessment, staff training, cryptography, identity management or multi-factor authentication, and it does not monitor the industrial network itself. Buyers in listed sectors should treat it as one measure within a management system, not as a substitute for one.
Two official positions are relevant and both are still in force. The German Federal Office for Information Security has warned against the use of Kaspersky antivirus software since 15 March 2022; the warning is a recommendation, not a sales ban, and since 6 December 2025 it has been issued under Section 13 of the amended BSI Act. In the United States, the Department of Commerce Bureau of Industry and Security issued a Final Determination in June 2024 that has prohibited the sale and resale of Kaspersky software, the delivery of signature and codebase updates, and the operation of the Kaspersky Security Network on US systems since 29 September 2024. Kaspersky rejects both assessments as not based on technical evidence, points to its Global Transparency Initiative, its Zurich Transparency Center and the relocation of threat data processing for European users to two data centres in Switzerland, and has publicly pressed for the German warning to be withdrawn. In Switzerland, BACS has issued no warning and has stated that no misuse of Kaspersky software has been reported to it, while also confirming that federal offices no longer use the software; independent test institutes have continued to include Kaspersky endpoint products in comparative testing, although those tests cover the office endpoint range rather than the industrial product. In practice this matters most for public sector tenders, for companies with a German parent or German operations, for supply chains with US touchpoints, and for anyone whose customer contracts contain vendor origin clauses; for a privately held Swiss manufacturer with no such clauses it may not matter at all.
Yes, for the endpoint section, and not for most of the rest. It answers questions on malware protection of industrial endpoints, application whitelisting, removable media and USB control, host firewall enforcement, integrity monitoring of files and registry keys, and central policy management with role-based access, and Kaspersky Security Center can produce dated reports as evidence rather than a written assurance. It does not answer questions on patch status of third-party software, disk encryption, backup and restore testing, multi-factor authentication, mobile devices, email security, OT network monitoring, or log retention beyond what your console is configured to keep. It also does not help with the vendor origin question, which increasingly appears in questionnaires from customers with public sector or US exposure. Where the gaps matter, the cheaper route is usually to stay inside the same family: KICS for Networks covers the OT network layer, the EDR licence tier covers detection and response evidence, and Kaspersky Endpoint Security for Business covers patch and encryption management on the office side, all under the same console.
The decisive difference is detection and response: neither the Workstation nor the Server licence includes EDR, which is a separate licence tier of the same product. The Workstation and Server licences differ in the node type they cover, so a SCADA or historian server needs a Server licence even though the agent and the components are the same. All three are managed from Kaspersky Security Center, and the agent is the same installation package in each case. Buying Workstation licences for servers is the most common ordering mistake in this family.
| Capability | Workstation | Server | EDR tier |
|---|---|---|---|
| Covers | HMI and engineering nodes | SCADA and industrial servers | Nodes plus EDR |
| Protection and control components | ✓ | ✓ | ✓ |
| PLC Project Integrity Check | ✓ | ✓ | ✓ |
| Root-cause analysis and response actions | ✕ | ✕ | ✓ |
| Managed in Kaspersky Security Center | ✓ | ✓ | ✓ |
Regional availability is the first thing to check: the US Department of Commerce prohibition has blocked the sale, resale and updating of Kaspersky software and the operation of the Kaspersky Security Network in the United States since 29 September 2024, so a Swiss or EU parent company cannot roll this out to a US plant, while sale and updates in Switzerland and the European Union are unaffected. Platform coverage is Windows only; industrial Linux nodes require Kaspersky Industrial CyberSecurity for Linux Nodes, which is a separate product with its own licence, and server nodes require the Server licence rather than this one. The product covers the endpoint, not the network, so switch traffic, PLC-to-PLC communication and passive asset discovery need KICS for Networks alongside it. Three functions that buyers regularly assume are included and are not: third-party patch management, disk encryption management, and backup or restore of the node itself, which in an OT environment is usually the component that actually determines how long a line stays down after an incident.
For central operation, yes. The agent has a local Application Console for single-node configuration, but group tasks and group policies can only be created and applied through Kaspersky Security Center, which you install on-premises yourself.
Yes, and that is one of the main reasons it exists as a separate product. Supported systems include Windows XP SP2 and SP3, Windows 7 Embedded POSReady, Windows 8 and 8.1 Embedded Industry Professional and Windows 10 IoT Enterprise, although the oldest systems require specific Network Agent versions and some functions, such as blocking network sessions, are restricted on Windows XP SP2.
No. This is the industrial node product and is licensed per protected industrial node; office desktops, laptops and mail servers belong under Kaspersky Endpoint Security for Business, which shares the same management console.
Suspicious and unknown files voluntarily submitted to the Kaspersky Security Network by European users are processed in two data centres in Zurich, Switzerland, as part of the Global Transparency Initiative. Participation in the Kaspersky Security Network is a policy setting and can be switched off entirely for isolated networks.