What are the core benefits of Kaspersky Industrial CyberSecurity for Networks Standard Server Upd&Sup Security Audit Enterprise Base?
Central console – Own web interface, optional Kaspersky Security Center integration.
Passive monitoring – Analyses mirrored traffic without touching control systems.
Asset inventory – Discovers OT devices automatically from network packets.
Security audit – Active polling checks devices against security standards.
Intrusion detection – Flags attacks, anomalies and unauthorised controller commands.
Important note – No endpoint anti-malware, KICS for Nodes required.
Server licence – The licensed unit is the KICS for Networks Server node.
Asset management – Automatic OT device discovery from analysed network traffic.
Security audit – Active polling of devices against defined security standards.
Intrusion detection – Rule-based detection of network attacks and traffic anomalies.
Updates and support – Database and module updates plus vendor technical support.
Important – Endpoint anti-malware and extra sensors are licensed separately.
Kaspersky Industrial CyberSecurity for Networks, listed by the vendor and by resellers under the short form KICS for Networks, analyses industrial network traffic to detect attacks, deviations in process parameters and changes to device state, and acts as the site-level central server of the Kaspersky Industrial CyberSecurity platform. It is operated through its own web interface, with optional central administration through Kaspersky Security Center using the KICS for Networks administration plug-in.
No process impact – Reads mirrored traffic, never sits inline.
Complete asset list – Builds an OT inventory from observed network packets.
Audit without agents – Polls devices actively and checks them against standards.
Controller command visibility – Logs read and write operations on programmable controllers.
SIEM handover – Forwards registered events to SIEM systems for correlation.
Evidence for auditors – Reports on device status, security and audit results.
This is an OT product, so the deciding factor is not headcount but whether a separate production network exists with managed switches that can mirror traffic. A workshop with a flat office network cannot deploy it; a mid-sized water utility or plant builder usually can.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Rarely | Often | ✓ |
| Separate OT network with mirror-capable switches | ✕ | Often | ✓ |
| This product fits | ✕ | Partly | ✓ |
The reporting obligation under the revised Information Security Act (ISG) has applied since 1 April 2025 and covers operators of critical infrastructure such as energy and drinking water supply, transport companies, listed hospitals, data centre and cloud providers, and cantonal and communal administrations, while the Cybersecurity Ordinance exempts smaller organisations below the sector thresholds. Those affected must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery and have 14 days to complete the report. This product supports that duty on the content side: registered events are timestamped, the stored traffic can be exported as PCAP files for a chosen node, protocol and time range, and the asset table shows which controllers, HMIs and engineering stations were involved. What it does not do is decide whether an incident is reportable, submit the report, or see anything that never crosses a monitored network segment. It also delivers no host-level forensics on its own, because process and user data from an endpoint only arrive when KICS for Nodes is licensed separately and used as an endpoint sensor. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.
No software product creates NIS 2 compliance, because the directive places its duties on the organisation and its management, not on a tool. NIS 2 requires measure categories including risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and maintenance including vulnerability handling, procedures to assess whether measures work, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. Against that list, this product contributes to asset management through automatic OT device discovery, to incident handling through detection and event forwarding, to vulnerability handling through the active security audit, and to the effectiveness assessment through its device and audit reports. It contributes nothing to cryptography, multi-factor authentication, staff training, business continuity planning or backup. Supply chain security is supported only indirectly, by making visible which external devices and remote connections exist inside the OT segment.
The German Federal Office for Information Security (BSI) published a warning against the use of Kaspersky antivirus software in March 2022. The warning is still in force in 2026 and now rests on § 13 BSIG after the amendment that entered into force on 6 December 2025. In 2024 the US Department of Commerce prohibited the sale of Kaspersky products and the supply of updates in the United States. In Switzerland the situation differs: the Federal Office for Cybersecurity (BACS) has issued no warning, has stated that no misuse has been reported to it and that there is no internal directive against the products, while noting that federal offices no longer use them. Kaspersky rejects the assessment, describes the BSI decision as political rather than technical, states that it has no ties to any government, points to the processing of European customer data in its Zurich data centre operating since 2020, and announced in early 2026 that it would take legal steps if the BSI warning were not withdrawn. In practice this matters most for public-sector tenders, for German critical infrastructure operators, and for suppliers whose customers apply country-of-origin rules to their supply chain; a Swiss plant operator without German public-sector business is in a different position from a supplier to a German utility. Note also that the BSI warning names antivirus software, whereas procurement questionnaires usually ask about the vendor rather than the individual product.
Yes, for the OT visibility and detection items, and not for the rest. It answers questions on asset inventory of the production network, on network monitoring and intrusion detection in OT, on logging and event forwarding to a SIEM, on user activity auditing inside the tool, and on regular technical security checks of devices, because the audit results and device reports can be exported as evidence. It does not answer questions on endpoint anti-malware, on patch deployment, on disk or removable media encryption, on multi-factor authentication, on backup and restore, or on mobile device management, since none of these functions exist in the product. It also does not answer organisational questions on policies, training records or supplier management. Where those gaps are blocking a contract, the cheaper route is usually to stay inside the same family and add KICS for Nodes for endpoint protection and endpoint telemetry rather than to introduce a second vendor into an OT network that then needs two sets of exclusions and two consoles.
The decisive difference is that only the Security Audit variant covers the active side of the product, meaning the polling of devices through connectors and the check of those devices against security standards; the plain Updates and Support variant stays with passive traffic analysis. The second difference is the licensed unit: Standard Server licences apply to a Server node, while the Additional Sensor licence applies to a sensor node that collects traffic at a further location and reports back to a Server. A sensor is therefore an extension of an existing installation and not a standalone product. All three are sold as Base, Renewal and Cross-grade variants, and this listing is the Base variant, which is the one to choose when no licence of the same product exists yet.
| Capability | Standard Server, Upd&Sup | Standard Server, Upd&Sup, Security Audit | Additional Sensor |
|---|---|---|---|
| Passive traffic analysis | ✓ | ✓ | ✓ |
| Asset management and intrusion detection | ✓ | ✓ | Via Server |
| Active polling and device security audit | ✕ | ✓ | ✕ |
| Runs without another KICS licence | ✓ | ✓ | ✕ |
| Endpoint anti-malware | ✕ | ✕ | ✕ |
The product detects and reports, it does not block: monitoring points must be connected to the industrial network in a way that excludes any possibility of influencing it, so nothing here stops a malicious controller write in progress. Deployment depends on infrastructure you may not have, because traffic has to reach the Server or a sensor through port mirroring, and the vendor documents this for Cisco, Hirschmann, Siemens SCALANCE and Siemens RUGGEDCOM switches; unmanaged switches leave blind segments. Coverage is limited to what crosses a monitored segment, which means serial links, USB transfers and engineering laptops connected directly to a controller stay invisible. The two most common follow-up purchases are additional sensors for further plant locations and KICS for Nodes for endpoint protection and endpoint telemetry, and both are separate licences. Note finally that this is a Base licence, so it is the wrong choice if a licence for the same product already exists and a Renewal or Cross-grade applies.
The vendor documents handling of IEC 60870-5-101 and IEC 60870-5-104, including supported ASDU types, and of IEC 61850 with loading and management of device and tag configurations. In addition the application can identify individual application-layer protocols from the contents of network packets for network control and event registration.
Yes. Registered event types can be configured for transmission to recipient systems such as a SIEM and to Kaspersky Security Center, and the vendor documents the verification of event forwarding using an ArcSight system as a worked example. An API is also available to retrieve event and tag data from external applications.
No. The application has its own web interface for assets, events, process parameters and configuration. Kaspersky Security Center with the KICS for Networks administration plug-in is the option for organisations that want several Servers and locations administered centrally.