Fix it now
Both platforms detect what a small business meets, and both publish a console you can run from a browser. For a UK or EU buyer the decision is usually settled before the console comparison begins, because the US Commerce Department prohibited the resale, licensing and integration of Kaspersky software from 29 September 2024, and that fact follows you into every security questionnaire you fill in.
- Buy ESET PROTECT Entry if you want the smallest thing that is still managed. ESET publishes exactly three components in it: the management console, endpoint protection, and file server security.
- Buy ESET if you answer security questionnaires, tender for public work, or sit in a supply chain with US customers. The procurement position settles it without a technical argument.
- Buy ESET if you may need to keep management traffic inside your network. ESET publishes the same console as either a cloud or an on-premises deployment, so the choice does not change product.
- Consider Kaspersky Next if none of that applies and you want more in the entry bundle. Kaspersky publishes endpoint applications for Windows, Linux, Mac and mobile plus Kaspersky Security Center in one licence.
- Skip both entry tiers if you actually want detection and response. Both vendors sell that higher up the range, and buying it without anyone to read the alerts is money spent on an unused capability.
- Skip consumer antivirus for an office regardless of which you choose. Neither vendor’s consumer SKU carries a console, and reading detections by walking to each desk is the problem you are trying to end.
Kaspersky’s small and medium business range is now sold as Kaspersky Next – EDR Foundations, EDR Optimum, XDR Optimum and MXDR Optimum. If a quotation in front of you says Endpoint Security for Business, check which of those it maps to before comparing it with anything.
If procurement decides it for you, stop here. Below is what each vendor publishes about its console and bundles, the dates behind the US prohibition, and what the entry tiers actually contain.
Why it happens
Endpoint software is invisible when it works. The part you touch weekly is the console: enrolling a laptop, working out why a machine has not checked in, pushing an exclusion for a line-of-business application, reading last night’s detections. A platform that detects well and administers badly ends up half deployed, and a half-deployed platform protects nobody. That is why the console is the right axis for this comparison, even though it is not the axis either vendor markets on.
ESET publishes its entry bundle with unusual clarity. ESET PROTECT Entry contains three things: the management console, described as available as a cloud or on-premises deployment; endpoint protection for computers, smartphones and virtual machines; and file server security for data passing through general servers. Three components, one seat-based licence, and the same web console whichever way you host it. Nothing is stranded if you start in the cloud and move on-premises later.
Kaspersky’s side has been restructured and the old names are still circulating. The current small and medium business range is Kaspersky Next, in four tiers: EDR Foundations, EDR Optimum, XDR Optimum and MXDR Optimum. The endpoint applications Kaspersky publishes under its business licensing are Kaspersky Endpoint Security for Windows, for Linux and for Mac, Kaspersky Security for Mobile, and Kaspersky Security Center, and management is offered either through the cloud console or as a traditional on-premises deployment, including in AWS or Azure. That is a wider platform reach than ESET publishes for its entry bundle, and it is the honest argument in Kaspersky’s favour.
You fill in security questionnaires or sell to public bodies
You have this one if Somebody upstream asks which endpoint product you run, and the answer goes into a supplier file you do not control.
- Choose ESET, and stop debating it. The US Final Determination prohibits the resale, licensing and integration of Kaspersky software from 29 September 2024, and prohibited new agreements from 20 July 2024.
- The same determination stopped Kaspersky providing antivirus signature updates and codebase updates to US persons from 29 September 2024, which is the part that turns it from a paperwork problem into an operational one for anyone with US exposure.
- None of that is a technical finding about the code, and Kaspersky disputes the reasoning. Arbitrating it is still not your job.
Check your own jurisdiction’s guidance as well. This article states only what is published in the US determination, because that is what could be sourced.
IT is one person who also owns the printers
You have this one if Nobody has time to design a policy hierarchy, and the last management console you deployed is still half configured.
- Take the cloud console. Both vendors publish one, and it removes the server, the database and the patching of both from your list.
- Start with ESET PROTECT Entry if the estate is computers and a file server. Three components is a shorter thing to learn than a four-tier platform.
- Get every machine reporting in before you tune anything. An estate that is 100 per cent enrolled on a default policy is worth more than a beautiful policy tree covering half of it.
Management traffic has to stay inside your network
You have this one if A policy, a regulator or a customer contract rules out a vendor-hosted console.
- ESET publishes the PROTECT console as available in cloud or on-premises form, and the same console, agent and bundles apply either way.
- Kaspersky publishes on-premises deployment of Security Center as well, including in AWS and Azure, so the requirement does not rule either vendor out on its own.
- Cost the infrastructure honestly. An on-premises console is a server you now own, patch, back up and eventually migrate.
One thing neither vendor’s marketing will tell you: the entry tiers are not where detection and response lives. ESET publishes EDR and cloud sandbox analysis in bundles above Entry, and Kaspersky’s tier names say the same thing out loud. If nobody in your organisation would investigate an alert beyond reading it, the entry tier is the honest purchase and the difference in price is better spent on backups.
Full reference
What each vendor publishes about the entry-level platform
| ESET PROTECT Entry | Kaspersky Next | |
|---|---|---|
| Console hosting | Cloud or on-premises, same console either way | Cloud console, or on-premises deployment including AWS and Azure |
| Components published in the bundle | Management Console, Endpoint Protection, File Server Security | Endpoint applications for Windows, Linux and Mac, mobile security, and Kaspersky Security Center |
| Range above the entry tier | Further PROTECT bundles adding cloud app protection, mail security, EDR and cloud sandboxing, and managed detection and response | EDR Foundations, EDR Optimum, XDR Optimum, MXDR Optimum |
| Endpoint platforms | Computers, smartphones and virtual machines | Windows, Linux, Mac, Android and iOS |
| Licence shape | Per seat, console included | Per node, console included |
| US availability | Sold normally | Resale, licensing and integration prohibited in the United States from 29 September 2024 |
Neither vendor charges separately for the console. In both products you buy seats and the tier they sit in, and the management platform comes with them. The real cost difference is the infrastructure behind an on-premises console and the hours spent administering it.
The procurement position, stated as published
This is the part of the comparison that has changed most, and it deserves dates rather than adjectives. The US Department of Commerce issued a Final Determination in case ICTS-2021-002 covering Kaspersky Lab, Inc. It prohibits transactions involving any cybersecurity product or service and any antivirus software designed, developed, manufactured or supplied in whole or in part by Kaspersky, and the integration of Kaspersky software into third-party products.
| Date | What became prohibited |
|---|---|
| 20 July 2024 | Entering into new agreements |
| 29 September 2024 | Resale, licensing and integration of Kaspersky software |
| 29 September 2024 | Providing antivirus signature updates and codebase updates to US persons |
Practically, that means three things for a UK or EU buyer. If you have US customers upstream, or you answer questionnaires, or you tender for public work, choosing Kaspersky costs you time repeatedly and may cost you a contract. If none of that applies, the exposure is smaller. Either way, satisfy yourself that you could replace the platform inside a licence term if guidance shifts where you are, because the cost of that migration is the real size of the risk.
Deployment effort in the first week
With a cloud console the shape is the same on both sides: create the tenant, get an installer or agent package, run it by hand or push it with Group Policy or a directory sync, and watch machines appear, land in a group and inherit a default policy. Most small teams have an estate reporting within a day. The work that takes longer is deciding what the policies should say, and that is a decision about your business rather than about the product.
An on-premises console changes the arithmetic. You provision a server, install it, put a database behind it, then discover the network and push agents. The payoff is that management traffic never leaves your network. The cost is a server you now own for the life of the platform. If a compliance requirement is not forcing it, the cloud console is the shorter road on either product.
Questions to settle before you sign anything
- Which bundle carries the components you actually need. Encryption, mail protection, cloud sandboxing and detection and response sit in different tiers in both ranges, and both vendors have renamed their packaging more than once.
- Whether servers are in scope. ESET publishes file server security inside PROTECT Entry; check what a Kaspersky quotation covers for the same money.
- Whether mobile devices are in scope, and whether anyone will actually enrol them.
- How many seats you need in twelve months, not today. Mixed terms across one estate create renewal admin nobody enjoys.
- Who reads the console on a Tuesday. If the answer is nobody, buy the entry tier and set up email alerts rather than paying for an investigation platform.
When a licence is the actual fix
If you are running unmanaged consumer antivirus across an office and reading detections by walking to each desk, the licence genuinely is the fix. ESET PROTECT Entry buys the management console, endpoint protection and file server security in one seat-based licence, and ESET publishes the console as available in cloud or on-premises form, so you are not choosing a hosting model at the same time as a product. Arco supplies ESET PROTECT seats and can confirm which bundle carries the components you need, because encryption, mail security, cloud sandbox analysis and the detection and response tooling sit in different bundles and the packaging has been renamed more than once. If Kaspersky is on your shortlist and you have no US or public-sector exposure, we will price it – and we will tell you where the prohibition dates sit so the decision is made with them in view rather than after.
Questions people ask about this
Does the management console cost extra?
Not in either product. The console comes with your endpoint seats; you pay for seats and the tier they sit in. The real cost difference is the infrastructure behind an on-premises console and the hours spent administering it.
Can I move seats when a laptop is replaced?
Yes, in both. Seat licensing is not tied to hardware; remove the machine from the console and the seat frees up. Watch the term rather than the device, because both vendors sell one, two and three year terms and mixed terms across one estate create renewal admin nobody enjoys.
Is Kaspersky software unsafe?
That is not what the published record says, and this article does not claim it. What is published is a US Commerce Department determination prohibiting resale, licensing and integration from 29 September 2024, along with signature and codebase updates to US persons from the same date. That is business exposure rather than a malware finding, and for many buyers it decides the matter on its own.
Do I need the detection and response tier?
If nobody in your organisation would investigate an alert beyond reading it, plain endpoint protection is the honest answer and the higher tier is money spent on an unused capability. Buy it when you have someone whose job includes looking at it, or when a managed service will look at it for you.
What happened to Kaspersky Endpoint Security for Business?
Kaspersky’s current small and medium business range is published as Kaspersky Next, in four tiers. Kaspersky Endpoint Security remains the name of the endpoint applications themselves, for Windows, Linux and Mac, so a quotation naming it is not necessarily out of date – but check which Next tier it maps to before you compare it against an ESET bundle.
