What are the core benefits of Kaspersky Managed Detection and Response Optimum Add-on?
Central console – Managed from Kaspersky Security Center and MDR portal.
Managed SOC – Kaspersky analysts watch your telemetry around the clock.
Automated hunting – Detections use over 700 proprietary indicators of attack.
Guided response – Analysts propose actions, your team keeps final control.
No infrastructure – Service needs no additional on-premises servers.
Important note – Endpoint protection not included, base product required.
Round-the-clock SOC monitoring – Kaspersky analysts review your security telemetry day and night.
Automated threat hunting – Detections built on over 700 proprietary indicators of attack.
Alert triage – Analysts validate and prioritise alerts before your team sees them.
Guided and remote response – Response scenarios run by Kaspersky or by your own administrators.
MDR web console – Incidents, asset status and analyst findings in one place.
Important – No endpoint protection and no EDR Optimum component are included.
Kaspersky MDR Optimum is a subscription service in which Kaspersky's own security operations centre monitors the telemetry your existing Kaspersky agents already produce, managed through Kaspersky Security Center together with the MDR web console. Kaspersky sells the same managed monitoring model to mid-sized companies inside the Kaspersky Next MXDR Optimum package, so buyers comparing offers will meet both names.
No SOC to build – Night and weekend coverage without hiring shift analysts.
Fewer false alarms – The service is tuned to your environment over several weeks.
Faster containment – Hosts can be isolated and processes stopped remotely.
Uses existing agents – Telemetry comes from Kaspersky software already on your endpoints.
Written incident findings – Analyst reports feed your internal reporting and audit files.
No extra servers – The service needs no additional on-premises infrastructure.
The deciding factor is not headcount. It is whether anyone in your organisation looks at security alerts at three in the morning, and whether an alert seen at that hour would lead to a decision. Companies with an established internal security operations centre usually need this service less than companies whose IT is one administrator or an external provider.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Sometimes | Often | Standard |
| Alert monitoring outside office hours | Not staffed | Not staffed | Often in-house |
| This product fits | ✓ | ✓ | Partial |
The revised Information Security Act obliges operators of critical infrastructure in Switzerland to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and most small and mid-sized companies outside those sectors are not covered by it. The hard part of that obligation is not the form, it is noticing the attack and knowing what happened in time to describe it. Kaspersky MDR Optimum supports this directly: analysts detect and triage the incident around the clock and hand over written findings on affected assets and attacker activity that you can use as the basis of a first report. What it does not do is file anything for you, decide whether your organisation is subject to the obligation, or cover systems that run no supported Kaspersky software, and it produces no report template matching the BACS form. It also does not replace the internal process that has to decide, within those 24 hours, who reports and with what authority. This text is product information and not legal advice.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational risk management, not software features. NIS 2 requires measures in categories such as incident handling, incident reporting to the competent authority, business continuity, supply chain security, and the assessment of how effective the measures are. Kaspersky MDR Optimum contributes to incident handling and to the detection and analysis step that reporting depends on, and its written analyst findings support the effectiveness review. It contributes nothing to business continuity planning, backup, supplier assessment, access management, staff training or the governance documentation that the directive expects. The reporting deadlines themselves remain your responsibility, and national implementation differs between member states.
In June 2024 the US Department of Commerce, through its Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from providing antivirus and cybersecurity products or services in the United States or to US persons; sales and updates stopped on 29 September 2024, and the prohibition remains in force. Germany's Federal Office for Information Security published a warning in March 2022 recommending that Kaspersky products be replaced, which is a recommendation rather than a sales ban. Some European countries restrict Kaspersky in public sector procurement without restricting commercial sale. Kaspersky rejects the allegations, states that it has never assisted any government in cyberespionage, and has offered independent third-party review of its code and updates; threat data from European customers has been processed in two data centres in Zurich since the Global Transparency Initiative relocation. Independent laboratory test results for detection performance are a separate matter and are unaffected by these decisions. In practice this affects you if you sell to US customers, work under a supply chain clause that names country of origin, bid for public sector contracts, or answer questionnaires that ask about the origin of your security vendors; for a Swiss or EU company with none of those exposures, the products remain available and supported.
Yes, for a specific block of questions, and it is worth knowing exactly which. It answers the items on 24/7 security monitoring, on who performs alert triage, on documented incident detection and analysis, on threat hunting, and on whether incident findings are recorded in writing, because a named external SOC is a stronger answer there than an internal process that exists only on paper. It does not answer questions on backup and restore testing, vulnerability and patch management, disk encryption, access control and privileged accounts, staff security awareness training, penetration testing, or an information security management system certified to a standard. It also does not answer the question on log retention periods across non-Kaspersky systems, because the service reads telemetry from supported Kaspersky products, not arbitrary third-party log sources. To close the technical part of those gaps, a higher edition in the same family is normally the cheaper route than adding a second vendor: patch management, encryption management and vulnerability assessment sit in Kaspersky Next EDR Optimum, and broader correlation across sources sits in Kaspersky Next XDR Expert. The organisational items, training and the management system, cannot be bought as software at all.
The decisive difference is who does the hunting. In MDR Optimum, threat hunting is automated: detections come from Kaspersky's proprietary indicators of attack applied to live and historical telemetry, and SOC analysts then validate and investigate what those rules surface. In MDR Expert, human threat hunters work against your specific infrastructure and look for attacker techniques that no existing rule catches; when they find one, the resulting indicator is added for both tiers. MDR Expert includes everything in Optimum and is aimed at organisations that already have security staff and want to hand over triage and investigation rather than acquire it.
| Capability | MDR Optimum | MDR Expert |
|---|---|---|
| Round-the-clock SOC monitoring | ✓ | ✓ |
| Automated threat hunting on indicators of attack | ✓ | ✓ |
| Human-led hunting for unknown techniques | ✕ | ✓ |
| Guided and remote response scenarios | ✓ | ✓ |
| Suited to teams with own security staff | Not required | Assumed |
This is an add-on and not a standalone product: it needs an existing licence for a supported Kaspersky base product, and it adds no protection component of its own, so an endpoint with no Kaspersky agent produces no telemetry and stays invisible to the service. Telemetry sources are limited to supported Kaspersky software, including Kaspersky Endpoint Security for Windows, Linux and Mac, Kaspersky Security for Windows Server, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Detection and Response, and Kaspersky Anti Targeted Attack, which means firewalls, network appliances and cloud services from other vendors are not read. The MDR add-on does not include the EDR Optimum component, and the two cannot be run side by side as two separate add-ons, so companies that want both need the combined EDR Optimum plus MDR add-on instead. Detection quality also depends on a settling-in period of roughly two to four weeks, during which normal activity in your environment is confirmed as legitimate, so the first weeks are not representative of steady-state alert volume. Finally, the US prohibition described above means this is not a viable choice for US entities or for suppliers bound by contracts that exclude the vendor.
Kaspersky lists Kaspersky Endpoint Security for Windows, Linux and Mac, Kaspersky Security for Windows Server, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Detection and Response, and Kaspersky Anti Targeted Attack as supported sources. Coverage of your estate is therefore only as wide as your deployment of those products.
No. Kaspersky analysts detect, triage and investigate, and they can execute or recommend response actions, but decisions about isolating production systems, informing management, notifying authorities and restoring operations stay with you. Companies without any internal owner for those decisions gain less from the service than companies with one named responsible person.
Kaspersky relocated the storage and processing of threat-related data for European customers to two data centres in Zurich, Switzerland, as part of its Global Transparency Initiative, completing the move in 2020. For Swiss buyers this is usually the more relevant fact in a data protection review than the vendor's country of origin.