What are the core benefits of Kaspersky Digital Footprint Intelligence?
Portal delivered – Runs in the Kaspersky Threat Intelligence Portal.
Dark web – Monitoring of forums, ransomware blogs and messengers.
Leak detection – Finds exposed credentials, cards and employee data.
Attack surface – Flags internet facing assets and their vulnerabilities.
MSSP ready – Separate tenants and dashboards for each customer.
Important note – No endpoint protection, blocking or agent included.
Download: Kaspersky Digital Footprint Intelligence
Dark web monitoring – Tracks forums, ransomware blogs, Tor sites and messenger channels.
External attack surface – Finds internet exposed assets, misconfigured services and known vulnerabilities.
Data leak discovery – Detects compromised credentials, payment cards and exposed employee details.
Threat Intelligence Portal – Real time alerts, dashboards, search and REST API access.
Multitenancy for providers – Separate tenants, access control and per tenant threat statistics.
Important – No endpoint agent, no blocking and no antivirus component.
Kaspersky Digital Footprint Intelligence is a digital risk protection service in the Kaspersky Threat Intelligence family that watches your external exposure instead of your endpoints. It is delivered entirely through the Kaspersky Threat Intelligence Portal, so there is nothing to install and no device management console.
Analyst verified alerts – Kaspersky analysts filter, prioritise and enrich every notification.
Faster breach response – Leaked credentials surface before criminals use them.
Shadow IT visibility – Forgotten domains and exposed services appear in the inventory.
Existing tool integration – REST API and connectors for common SIEM platforms.
Board level reporting – Dashboards show threat categories, criticality and trends over time.
Provider ready delivery – Tenant centre gives MSSPs one view per customer.
Company size matters less here than whether anyone reads the alerts. The service produces analyst-verified notifications, not blocked threats, so the value depends on a named person owning the follow-up. A ten-person firm without IT staff will not act on a report that a forgotten subdomain exposes an outdated service. A company with a security lead, an MSP contract or its own SOC will.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | Often |
| NIS 2 in the European Union | Rarely | ✓ | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Own capacity to act on alerts | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company: energy and drinking water suppliers, transport operators, cantonal and communal administrations, and IT service providers and hardware or software manufacturers serving those sectors. Since 1 April 2025 an initial report must reach the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a cyberattack, with a further 14 days to complete it. Kaspersky Digital Footprint Intelligence supports the discovery half of that duty: an alert that your credentials appeared in a leak set, or that your company name showed up on a ransomware blog, often arrives before anything is visible internally, and each notification carries a timestamp you can attach to the initial report. It does not detect the attack inside your own network, it does not submit the report to BACS, and it produces no evidence of the technical protection measures on your systems, because there is no agent on any device. Anyone in scope still needs endpoint or server protection, logging and a documented internal escalation path before the 24-hour clock becomes manageable. This information is general orientation and does not replace legal advice on your specific obligations.
No product makes a company compliant with the NIS 2 Directive, because compliance follows from documented processes, organisational measures and management accountability. The directive requires categories of measures including risk analysis and information system security policies, incident handling, business continuity, supply chain security, vulnerability handling and disclosure, and the use of cryptography. This service contributes to two of them in a concrete way: supply chain security, because dark web monitoring covers references to your partners and clients alongside your own organisation, and vulnerability handling, because the external attack surface module scores internet-facing findings using the CVSS base score together with the availability of public exploits and the hosting location of the resource. It contributes nothing to incident handling on endpoints, business continuity, cryptography, access control or staff training, and it carries no certification an assessor can accept as proof of those measures. Whether your organisation is in scope depends on its sector and size as defined in the directive and in the law that transposes it.
Two official measures concerning the vendor are in force. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky virus protection software since 15 March 2022; the warning was issued under section 7 of the BSI Act and has been regulated under section 13 since the amended act took effect on 6 December 2025. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from supplying anti-virus software and cybersecurity products or services to US persons, blocking new agreements from 20 July 2024 and signature and codebase updates from 29 September 2024. Both measures target software that runs with deep system privileges on protected machines. The US determination explicitly does not apply to Kaspersky Threat Intelligence products and services, security training, or consulting and advisory services that are purely informational or educational in nature, which is the category this service belongs to, and Kaspersky states these remain available to US customers. Kaspersky rejects the assessments as driven by the geopolitical climate rather than a technical evaluation, points to its Transparency Centers where code and update procedures can be reviewed by governments and partners, and has publicly demanded the withdrawal of the German warning. Independent analyst evaluations of the threat intelligence portfolio are separate from these measures: QKS Group named Kaspersky a leader in its 2025 SPARK Matrix for Digital Threat Intelligence Management, and Frost & Sullivan positioned the company as a leader in the 2024 Frost Radar for Cyber Threat Intelligence. In practice this matters most if you supply US federal customers, bid for German public-sector contracts, or answer supply chain questionnaires that ask whether any vendor is subject to a government warning; for a privately owned Swiss or EU company without those requirements it is primarily a question of documenting the decision.
Yes, for one block of questions, and not for the rest. It answers the items on external monitoring: whether you monitor the dark web for leaked employee and customer credentials, whether you maintain an inventory of internet-facing assets and track their vulnerabilities, whether you monitor abuse of your brand and phishing domains, and whether you receive threat intelligence with analyst verification rather than raw feeds. The alerts carry timestamps, criticality ratings and status handling, which is usually enough for the evidence column. It answers nothing on endpoint and server protection, EDR, patch management, encryption, multi-factor authentication, backup, access control, staff awareness training or certification status, and a questionnaire that asks for an ISO 27001 certificate will not accept this service as a substitute. If those gaps are the ones blocking you, adding an endpoint tier from the same vendor family is usually cheaper and easier to document than adding a second vendor with its own console, its own reporting format and its own review cycle.
The decisive difference is who asks the question. Digital Footprint Intelligence watches assets you register in advance and pushes an alert when something changes; Threat Lookup answers a question you type in about a single IP address, domain, URL or file hash during an investigation. Both are reached through the same Kaspersky Threat Intelligence Portal, which is why they are regularly confused at purchase. A Digital Footprint Intelligence subscription already contains a search quota in the Kaspersky threat database including Research, so most buyers do not need to add Threat Lookup separately at the start.
| Capability | Digital Footprint Intelligence | Threat Lookup |
|---|---|---|
| Monitors your registered assets | ✓ | ✕ |
| Alerts without a query | ✓ | ✕ |
| Lookup of a single indicator | Included quota | ✓ |
| Leaked credential detection | ✓ | ✕ |
| Takedown of phishing domains | Add-on | ✕ |
This is intelligence, not protection: there is no agent, nothing is blocked, quarantined or rolled back, and every endpoint, server and mailbox in your environment still needs its own security product. Three capabilities buyers often assume are included are sold as add-on modules and cause follow-up purchases: the Takedown Service that removes malicious domains, fake social media accounts and fake mobile apps, Brand Monitoring, and the expert analytical reports. Coverage is only as good as the asset list you register, so IP ranges, domains, brand names, card BIN or IIN numbers and employee details have to be maintained as the company changes, and a subsidiary nobody entered stays invisible. On regional availability, the relevant finding runs the other way to most products: the US prohibition on Kaspersky cybersecurity products does not extend to the Threat Intelligence line this service belongs to, while the German BSI warning is aimed at virus protection software and can still surface in public-sector procurement. Finally, the alerts arrive verified but unresolved, and an organisation with nobody assigned to triage them gets a portal full of findings and no change in risk.
No. The service is delivered through the Kaspersky Threat Intelligence Portal in the browser, with notifications also available through a REST API for export into a SIEM or ticketing system. Nothing is installed on your machines and no network appliance is required.
IP addresses, network ranges, domain names, card BIN and IIN numbers, keywords, brand names, employee information, social account links and mobile app links. Assets can be added individually in the portal or uploaded as a file when the list is long.
Yes, but through the Takedown Service, which is a separate add-on module rather than part of the base service. It covers malicious and phishing domains, fake social media accounts and fake applications in mobile marketplaces, and Kaspersky manages the removal process end to end.