What are the core benefits of Kaspersky Endpoint Detection and Response Expert Base?
Cloud console – Centrally managed from Kaspersky Security Center Cloud Console.
Threat hunting – Query builder searches stored endpoint telemetry for suspicious behaviour.
Network isolation – Cuts a compromised device off the network.
Custom rules – YARA and IoA detections mapped to MITRE ATT&CK.
Telemetry retention – Thirty days of stored events by default.
Important note – Requires Kaspersky Endpoint Security on every protected device.
Cloud management console – Managed through Kaspersky Security Center Cloud Console.
Endpoint telemetry storage – Process, file and network events kept centrally for thirty days.
Threat hunting queries – Flexible query builder searches stored telemetry across all assets.
Response actions – Network isolation, quarantine, execution prevention, process termination and file retrieval.
Custom detection rules – Customisable YARA rules and IoA detections mapped to MITRE ATT&CK.
Important – Requires supported Kaspersky Endpoint Security applications installed on protected assets.
Kaspersky Endpoint Detection and Response Expert is the detection, investigation and response layer that Kaspersky sells today as Kaspersky Next EDR Expert, the expert tier of the Kaspersky Next business line introduced in 2024. It is managed from the Kaspersky Security Center Cloud Console, while an on-premises deployment of the same engine is delivered inside Kaspersky Anti Targeted Attack Platform.
Retrospective investigation – Telemetry survives even when the endpoint is encrypted or unreachable.
Alert consolidation – Related alerts are merged automatically into single incidents.
One-click containment – Isolate a host from the console without physical access.
API-driven response – Response actions on hosts can be triggered via API.
Regional data handling – Telemetry goes to dedicated KPSN servers, not public KSN.
Extendable retention – Extension Modules raise telemetry storage to sixty or ninety days.
The deciding factor is not headcount but whether someone in the organisation actually works the alert queue. Kaspersky positions this tier for teams with established security processes, and its value comes from threat hunting and investigation tools that only pay off when a person uses them.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Sometimes | Often | Standard |
| Own staff to triage EDR alerts | ✕ | Partial | ✓ |
| This product fits | ✕ | Limited | ✓ |
The Swiss obligation applies to operators of critical infrastructure, not to every company: since 1 April 2025 the revised Information Security Act requires the bodies it names, such as energy and water utilities, transport operators, listed hospitals and cantonal and communal administrations, to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with fourteen days to complete an incomplete first report. What this product contributes to that deadline is detection time and evidence: continuously collected endpoint telemetry, alerts merged into incidents, and MITRE ATT&CK-mapped detail showing which host was hit first and how the process chain ran, which is the substance a first report has to contain. It does not decide whether an incident is reportable, does not produce or submit the report, and sees only devices running a supported Kaspersky agent, so network equipment, cloud services and mailboxes stay outside its telemetry. Its default retention of thirty days is also shorter than the window many incident reviews reach back into, so organisations in scope should plan for the retention Extension Module or an export into their own log storage. This text is general product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No software product makes an organisation NIS 2 compliant, because the directive addresses the organisation and its management, not a feature list. NIS 2 requires essential and important entities to take risk-management measures in defined categories, among them incident handling, risk analysis, business continuity, supply chain security, access control and cryptography, together with an obligation to report significant incidents to the responsible national authority. This product maps to the incident-handling category and to part of risk analysis: it detects, records and contains endpoint incidents, and it preserves the telemetry an incident review needs even when the affected device is no longer usable. It contributes nothing to business continuity, supply chain security, governance, staff training or cryptography, and it collects no network, identity, mail or cloud telemetry. Buyers in scope should treat it as one measure among several rather than as a compliance package.
Two official measures concerning the vendor are verified and still in force. Germany's Federal Office for Information Security has warned against the use of Kaspersky antivirus software since 15 March 2022 and recommends replacing it with alternative products; that warning remains published and, following the amendment of the German BSI Act that took effect on 6 December 2025, is now issued under Section 13 of that act. The United States Department of Commerce issued a final determination on 20 June 2024 prohibiting Kaspersky from new transactions with U.S. persons from 20 July 2024 and from supplying signature and codebase updates or operating the Kaspersky Security Network from 29 September 2024; this is reflected directly in the product, which Kaspersky documents as unavailable in the United States or to U.S. persons. Kaspersky's own position is that the German warning is not justified and was not based on an objective technical analysis of the risks of using its software, and the company points to its Global Transparency Initiative, under which suspicious files submitted by European users are processed in two data centres in Zurich. In Switzerland the position is different: the Federal Office for Cybersecurity has issued no warning and no ban, has no internal directive against the software, states that no misuse of Kaspersky antivirus software has been reported to it in Switzerland, and confirmed that its technical assessment is not influenced by the US prohibition. Independent testing is unaffected where verified, and AV-Comparatives included Kaspersky Endpoint Detection and Response Expert in its 2023 Endpoint Prevention and Response test. In practice this matters most to public-sector tenders, to suppliers whose customers or parent companies apply German procurement rules, and to any organisation with US entities, US persons or staff travelling to the United States; for other Swiss and European buyers it is a documented risk factor to weigh, not an automatic disqualifier.
Partly, and only for the endpoint section. It answers with evidence the questions on whether an EDR solution is deployed, how long endpoint telemetry is retained, whether a compromised host can be isolated on demand or automatically, whether detections are mapped to MITRE ATT&CK, whether custom detection rules can be written, which response actions are available, and whether console access is role-based. It answers none of the questions on patch and vulnerability status, notebook encryption, mail and phishing protection, backup and recovery, multi-factor authentication, network and cloud logging, SIEM correlation, or round-the-clock monitoring, because no managed detection service is included and alerts are worked by your own staff. It also cannot answer supplier-origin questions, which increasingly appear in questionnaires from public-sector and German-owned customers, and the vendor assessments above are the honest input for that field. To close the technical gaps, the cheaper route is usually a higher tier of the same family, since Kaspersky Next XDR Expert extends the same console to further data sources and Kaspersky Next MXDR Optimum adds a managed service; mixing a second vendor in means a second agent, a second console and a second answer set for every questionnaire.
The decisive difference is who operates it: Optimum gives an IT team guided, alert-driven investigation, while Expert gives a security team the raw telemetry, a query builder and its own detection rules. Kaspersky positions Optimum as essential EDR with advanced controls, patch management and cloud security for IT departments, and Expert for organisations with established IT security processes. Expert also cannot be activated on top of an existing Optimum deployment, so moving between the two is a licence change, not a switch inside the console. Both tiers are unavailable in the United States and to U.S. persons.
| Capability | EDR Optimum | EDR Expert |
|---|---|---|
| Intended operator | IT department | Security team |
| Central telemetry retention | ✕ | 30 days |
| Threat hunting query builder | ✕ | ✓ |
| Custom YARA rules | ✕ | ✓ |
| On-premises deployment | Security Center | Via Anti Targeted Attack Platform |
| Available in the United States | ✕ | ✕ |
The regional restriction is the one to check first: Kaspersky documents that this solution is not available in the United States or to U.S. persons, and that use must be suspended on the assets of non-U.S. persons while they are temporarily in the United States, which is a hard constraint for anyone with American entities, American staff or regular business travel there. On the platform side, integration with the solution is not supported on Arm-based computers, and it needs Kaspersky Endpoint Security with the built-in agent from version 11.8.0 onwards, since the older separate Kaspersky Endpoint Agent is not supported. It also cannot be activated on top of an existing Kaspersky EDR Optimum deployment, so an Optimum estate has to be migrated rather than upgraded in place. Telemetry is kept for thirty days by default and longer periods require a separate Telemetry Retention Extension Module for sixty or ninety days, with the periods not adding up if both are added. Finally, no managed detection service is included: the tool surfaces and contains incidents, but someone has to work the queue, and it neither patches nor encrypts anything and does not restore data after a successful ransomware attack.
In Kaspersky retail naming, Base marks a new licence, as distinct from a Renewal, which requires an existing licence of the same product, and from a Cross-grade, which is intended for customers switching from another vendor's product. Choose Base if you are not currently licensed for this product.
Activation switches the endpoints from the public Kaspersky Security Network to the Kaspersky Private Security Network, so telemetry is sent to dedicated regional servers rather than to KSN, and a Data Processing Agreement has to be accepted during setup. The data centre region for the Kaspersky Security Center Cloud Console workspace is determined by the country specified when the workspace is registered, and Kaspersky processes suspicious files submitted by European users in two data centres in Zurich.