Buyer fit
Good fit when
- ✓Organizations in Europe, the Middle East, Africa, Latin America, or Asia already running Kaspersky endpoint protection that want a managed SOC on top
- ✓Lean IT teams wanting turnkey detection and predefined response through the Optimum tier without hiring analysts
- ✓Industrial and critical-infrastructure operators that value Kaspersky's ICS and OT endpoint coverage and threat research
Watch out when
- ×US organizations and US persons, who are prohibited from buying or updating Kaspersky products since 2024
- ×Government, defense, and critical-infrastructure buyers in countries whose security agencies advise against Kaspersky, including Germany, the Netherlands, and the UK
- ×Teams that need fast English-only SOC support or want to keep a non-Kaspersky EDR
Coverage
1 of 6 attack surfaces in the base price; the rest are separately priced.
Platform
Additional capabilities
Incident response
Pricing
Per-node licensing sold in 2 tiers, MDR Optimum and MDR Expert.
Checked Aug 2026
Sourced figures
Self-managed Kaspersky Next Optimum EPP/EDR platform, entry per-node annual list…
TrustRadius, SelectHub · 2026
Aggregator's generic starting-price band for Kaspersky MDR, with no unit or node…
SelectHub · 2026
How pricing works+−
The managed service itself is quote-only through Kaspersky sales and partners. The self-managed Kaspersky Next platform tiers that MDR sits on top of carry published per-node prices through aggregators.
Cost caveats
- –Not available to US persons: the US Commerce Department prohibited new sales from July 2024 and product and signature updates from September 2024
- –Requires Kaspersky endpoint agents and cannot run on a competing EDR
- –Optimum lacks managed threat hunting, incident investigation, API export, and custom incidents, which require the Expert tier
2 more+−
- –Full forensic incident response is a separate Kaspersky Incident Response engagement, not included in MDR
- –Reviewers report SOC support in English and Russian only, with slow turnaround on non-emergency requests unless you buy premium support
What costs extra (4)+−
- –MDR Expert tier (managed threat hunting, incident investigation, API export, Threat Intelligence Portal access, custom incidents)
- –Kaspersky Incident Response and DFIR retainer (separate service)
- –Kaspersky Anti Targeted Attack sensors for network telemetry
- –Kaspersky Threat Intelligence feeds
Figures from named sources only (vendor pages, marketplaces, resellers, public procurement records, buyer reports), each dated. Nothing here is our estimate.
Team and access
Certifications
Reputation
Gartner Peer Insights rated Kaspersky MDR 5/5 across 33 reviews with 100% willing to recommend, though that snapshot dates to 2022. G2 sits at 4.1/5 from 14 reviews and PeerSpot at 4.0/5 from 5 reviews, and SoftwareReviews named it an Emotional Footprint Champion. Reviewers rate the detection expertise highly. The recurring frictions are English and Russian-only SOC support and slow non-emergency response.
What customers praise
- ✓Strong at finding evasive, sophisticated threats, with direct access to Kaspersky's SOC on the higher tiers (G2)
- ✓AI and machine learning triage speeds up analysis and detection (G2, PeerSpot)
- ✓Competitive, cost-effective pricing relative to peers (PeerSpot)
Common complaints
- ×SOC support offered in English and Russian only, creating language barriers for some buyers (G2)
- ×Slow response on non-emergency cases, with faster turnaround requiring paid premium support or incident response (G2)
- ×Console errors and a complex initial deployment, with no local on-site support presence (PeerSpot)
Reddit discussion of the Kaspersky MDR service specifically is sparse. Broader community conversation centers on the US ban and trust and geopolitical concerns rather than on SOC service quality.
Questions to ask
- 1.
Given the US prohibition, can you legally sell and support MDR in our specific country, and where will our telemetry be processed?
- 2.
What is the exact per-node price for MDR Optimum versus MDR Expert at our node count and contract term?
- 3.
Which response actions will your SOC execute automatically versus in coordination with our team, and how is that configured?
- 4.
What languages does the SOC communicate in, and what is the guaranteed response time for non-emergency versus high-priority incidents?
- 5.
What does Expert add over Optimum in practice, specifically managed threat hunting, investigation, API export, and custom incidents?
- 6.
Is forensic incident response included, or is that a separate Kaspersky Incident Response retainer?
- 7.
How is ICS, OT, and network telemetry collected, and does it require Kaspersky Anti Targeted Attack sensors or KICS agents on top of endpoint agents?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
- –MDR analyst headcount or analyst-to-customer ratio is not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
