What are the core benefits of Kaspersky Industrial CyberSecurity Integration Agent?
Central management – Configured and monitored through Kaspersky Security Center.
Host telemetry – Sends process, user and connection data to the network server.
Enriched alerts – Network detections gain host context for faster triage.
Asset accuracy – Protection status appears on the KICS network map.
Node auditing – Supports agent-based security audit of industrial hosts.
Important note – Telemetry only, no remote response or isolation actions.
Endpoint sensor link – Connects KICS for Nodes hosts to the KICS for Networks server.
Host telemetry transfer – Running applications, logged-in users and host network communications.
Event forwarding – KICS for Nodes security events reach the network console.
Asset enrichment – Device attributes and protection status shown on the network map.
Third-party AV reporting – Reports installed third-party anti-virus tools to the server.
Important – No own console, requires KICS for Nodes and KICS for Networks.
The Integration Agent is the licensed component that turns an industrial host already running Kaspersky Industrial CyberSecurity for Nodes into an endpoint sensor for the Kaspersky Industrial CyberSecurity for Networks server. It has no interface of its own and is rolled out and configured centrally from Kaspersky Security Center, where this integration role was previously filled by Kaspersky Endpoint Agent.
Faster incident triage – Network alerts arrive with process and user context.
Fewer blind spots – Protected hosts appear on the OT asset map automatically.
Agent-based audit – Supports node auditing without a traffic copy from switches.
One vendor stack – Reuses the existing Kaspersky Security Center deployment path.
Low change risk – Adds monitoring without altering the control system configuration.
Base licence type – A new purchase rather than a renewal or cross-grade.
This is not a starting point for a first OT security project. It only produces value where both platform components are already in place: KICS for Nodes on the industrial hosts and a KICS for Networks server collecting the alerts. That combination is typical for manufacturing sites, energy and water utilities and larger plant operators with a dedicated OT monitoring function, and rarely present in a small workshop.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| KICS for Nodes and KICS for Networks already running | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The revised Information Security Act obliges operators of critical infrastructure in Switzerland, among them energy and water suppliers, transport operators and certain industrial suppliers, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Such a report has to say what happened, when it was noticed and which systems are affected, and this is the point where the Integration Agent contributes: the process names, logged-in users and host network communications it forwards turn a bare network alert in the KICS for Networks console into an incident an engineer can actually describe. It does not write the report, does not decide whether a report is due, and does not store the evidence itself, because event storage and retention are properties of the KICS for Networks server rather than of the agent. It also sees nothing outside the hosts it is installed on, so office IT, cloud services, remote maintenance access and unmanaged field devices remain uncovered and need separate logging. This text is not legal advice, and the assessment of your own reporting obligations should be made with qualified legal support.
No software product makes a company compliant with the NIS 2 Directive, because the directive addresses the organisation and its processes rather than a single tool. NIS 2 requires essential and important entities to take risk-management measures covering incident handling, security monitoring and logging, business continuity, supply chain security, access control and staff training, and to report significant incidents to the responsible authorities within defined deadlines. The Integration Agent supports two of those categories in a concrete way: it feeds host-level monitoring data into the network detection layer, and it shortens the time needed to reconstruct what a detected event did on the affected machine. It contributes nothing to business continuity, backup and restore, access control, supplier management, training or governance documentation, and it does not perform the reporting itself. Buyers should treat it as one monitoring input inside a wider management system, not as a measure that closes a directive requirement on its own.
Germany's Federal Office for Information Security issued a public warning against Kaspersky virus protection software on 15 March 2022 and has confirmed since then that the warning remains valid, while stating that it has no legal basis to impose a ban. In the United States, the Department of Commerce Bureau of Industry and Security issued a Final Determination in June 2024 that prohibited new sales from 20 July 2024 and, from 29 September 2024, the delivery of signature and codebase updates and the operation of the Kaspersky Security Network on US systems. Kaspersky rejects the assessments, describes them as politically rather than technically motivated, points to its Global Transparency Initiative and to the relocation of data processing for several markets to Switzerland, and has publicly disputed the German warning. Switzerland has taken a different position: the federal cybersecurity body, now the Federal Office for Cybersecurity, has stated that no misuse of Kaspersky software has been reported to it and has not issued a warning, while noting that the choice of product and the associated risk assessment lie with each organisation. Independent laboratory results for Kaspersky detection products, where published by AV-TEST and AV-Comparatives, are unaffected by these administrative measures and continue to be issued. In practice this matters most for public sector contracts, for suppliers to German authorities and critical infrastructure operators, and for companies whose customers impose country-of-origin clauses on security software; for a privately held Swiss manufacturer without such clauses, it is a documentation question rather than a blocking one.
Partly, and only for a narrow set of items. It gives you a defensible answer to questions about endpoint telemetry collection, security event forwarding to a central monitoring system, asset inventory of protected industrial hosts, and whether the protection status of OT machines is visible centrally. It answers nothing about response capability, because within the KICS for Networks integration the agent transfers data only and does not perform remote response, host isolation or IOC scanning, so a questionnaire item asking whether you can isolate a compromised host will still be a no. It also leaves untouched the items on backup and restore, patch and vulnerability management, disk encryption, multi-factor authentication, mail security, log retention periods and supplier management, all of which are separate products or processes. Where the response gap is the blocking item, the cheaper route is usually the EDR variant within the same Kaspersky Industrial CyberSecurity family rather than adding a second vendor's agent to the same industrial hosts, since a second agent on an HMI or SCADA server brings its own compatibility testing effort.
The decisive difference is what happens after a detection. The plain Integration Agent is a one-way sensor: it moves host telemetry and KICS for Nodes events to the KICS for Networks server and stops there. The EDR variant is sold as a separate licence within the Kaspersky Industrial CyberSecurity Endpoint Detection and Response solution and is the one to choose when the security team needs to act on a host from the console rather than only observe it. Both are offered as Base, Renewal and Cross-grade licences, so a later move between them is a licensing decision rather than a re-deployment. Confirm the exact response scope for your platform version with Kaspersky before ordering, because it depends on which KICS components are installed.
| Capability | Integration Agent | EDR Integration Agent |
|---|---|---|
| Host telemetry to KICS for Networks | ✓ | ✓ |
| KICS for Nodes events forwarded | ✓ | ✓ |
| Agent-based node auditing | ✓ | ✓ |
| Remote response and host isolation | ✕ | With EDR licence |
| Intended role | Monitoring | Detection and response |
The clearest regional restriction concerns the United States: Kaspersky's own documentation states that update functionality, including anti-virus signature and codebase updates, and Kaspersky Security Network functionality are not available in the software in the U.S., following the Bureau of Industry and Security determination. For buyers in Switzerland and the European Union the product is available and updated normally, but companies with US subsidiaries or US-based service providers should check where the protected hosts physically sit before ordering. The second limitation is functional: within the KICS for Networks integration the agent transfers telemetry only, so response actions, network isolation and IOC scanning are not part of it, and that is the most frequent reason for a follow-up purchase. Third, it is a dependent component rather than a product that stands alone, so without KICS for Nodes on the host and a reachable KICS for Networks server it does nothing at all. Finally, platform coverage follows the endpoint product it attaches to, with Windows-based industrial hosts covered by KICS for Nodes and Linux hosts requiring Kaspersky Industrial CyberSecurity for Linux Nodes instead.
No. Malware detection, application launch control, device control and file integrity monitoring come from Kaspersky Industrial CyberSecurity for Nodes on the same machine. The Integration Agent adds visibility of that machine in the network console and nothing else.
Base identifies a new licence rather than an extension of an existing one. The same component is also offered as a Renewal licence, which continues an existing entitlement, and as a Cross-grade licence for a move from another Kaspersky product line.
No separate console is installed. Deployment and configuration run through Kaspersky Security Center, and the collected data is viewed in the Kaspersky Industrial CyberSecurity for Networks web interface.