Kaspersky has updated its Kaspersky Next Optimum offering with five security modules that let small and medium-sized businesses extend their protection without having to replace their entire cybersecurity infrastructure. The new options cover phishing awareness training, email, workloads, threat analysis, and vulnerability management.
Kaspersky Next Optimum in 20 seconds
- Kaspersky is adding five security modules that can be added based on each company’s needs.
- The new options cover employees, email, workloads, threat research, and vulnerabilities.
- A company study puts phishing among the most common incidents at SMBs, at 20%.
- The update also expands phishing simulations and compromised-credential analysis.
The move addresses a common problem for smaller companies: extending security as they grow without ending up with a pile of disconnected tools that are hard to manage. According to Kaspersky’s research center, 86% of the small and medium-sized businesses surveyed suffered some kind of cybersecurity incident over the past year, with an average of three different incident types.
Phishing is the most common external problem, cited by 20% of organizations, followed by exploitation of software vulnerabilities at 17% and external remote access at 16%. These figures come from the company’s own research and should be read in that context.
Tool complexity is also a factor. 26% of participating organizations pointed to compatibility and integration issues as one reason for switching cybersecurity vendors, while 23% wanted to consolidate several products onto a single platform.
Five Modules to Extend Security Across Different Areas
Kaspersky has built the new Next Optimum architecture around baseline endpoint protection that companies can extend with additional capabilities. The idea is that an SMB can add specific tools as its infrastructure, exposure, or internal resources change.
The first is Security Awareness, aimed at training employees against phishing, social engineering, and other human errors. This kind of protection matters more because many attacks still require some form of user interaction, from entering credentials on a fake page to opening a malicious file.
Email Security extends protection to email. The module is designed to catch threats before they reach the user and provide greater visibility into the email infrastructure and the communications flowing through it.
The third addition, Workload Security, targets workloads deployed in cloud and hybrid environments. Its inclusion reflects how a company’s protection can no longer be limited to computers and endpoints alone, now that applications, virtual machines, and services are spread across on-premises infrastructure and the cloud.
Threat Lookup & Analysis adds tools for investigating suspicious files and gathering additional information during incident analysis. It’s designed to speed up investigation and threat-hunting work when a team needs to figure out what’s behind an alert.
Finally, Vulnerability Management focuses on finding and managing vulnerabilities across the infrastructure. Managing these flaws ties directly to one of the findings from Kaspersky’s research: 17% of the SMBs surveyed reported incidents related to exploited software vulnerabilities.
The modules complement the various detection and response capabilities already available across the Kaspersky Next family, which includes EDR (Endpoint Detection and Response), XDR (Extended Detection and Response), and MXDR (Managed Extended Detection and Response) options.
More Phishing Simulations and Credential Monitoring
The update isn’t limited to the five modules. Kaspersky has also extended simulated phishing campaigns to Kaspersky Next EDR Foundations, a feature that was previously only available in Next XDR Optimum and Next MXDR Optimum.
Administrators can use ready-made templates to send simulated attacks and see how employees respond. The system generates reports to identify training gaps and track progress over time. These tests don’t prevent attacks on their own, but they can help spot risky behavior before a real attempt manages to trick an employee.
Meanwhile, Kaspersky Next MXDR Optimum adds new threat-hunting capabilities built on Kaspersky Digital Footprint Intelligence. The service links leaked credentials to alerts and suspicious login attempts to help spot potentially compromised accounts and prioritize incidents.
The company has also adapted some management functions for phones and tablets. Incident notifications sent through Telegram can now show priority, affected assets, recommendations, and a direct link to the incident.
Another change affects the management consoles. Organizations can start out with Pro View Console, designed to simplify management, and later move to Expert View Console when they need more detailed controls.
SMB Security Extends Beyond the Computer
The modular approach arrives as small businesses expand the number of digital services they use. Email, SaaS applications, cloud services, remote access, and corporate credentials are now all part of an attack surface that’s hard to protect just by installing security software on computers.
New lures are showing up too. Kaspersky reported in June that its solutions had detected more than 33,300 attacks against SMBs between January and April 2026 in which malicious or potentially unwanted software posed as popular AI services. That figure was nearly five times higher than the one recorded over the same period in 2025, according to the company’s own data.
The Next Optimum update tries to adapt to that same diversity. Instead of forcing customers to sign up for every available feature from day one, Kaspersky proposes adding modules around a common base. For a small company, that can mean starting with endpoint protection and phishing awareness training and later adding email protection, cloud workload coverage, or more advanced investigation tools.
How useful this model turns out to be will depend on each organization’s needs, its infrastructure, and the tools it already has in place. Modularity can make it easier to add new layers of security, but it doesn’t replace tasks like keeping software updated, reviewing permissions, controlling access, and having incident response procedures in place.
The new modules build on Kaspersky’s existing SMB lineup, which cloudnews.tech covered when the company first launched Next XDR Optimum and Next MXDR Optimum for SMEs.
Frequently Asked Questions
What new modules does Kaspersky Next Optimum add?
The update adds Security Awareness, Email Security, Workload Security, Threat Lookup & Analysis, and Vulnerability Management. Each addresses a different part of enterprise security.
Is Kaspersky Next Optimum aimed at small and medium-sized businesses?
Yes. Kaspersky positions Next Optimum as an offering specifically geared toward SMBs, with different tiers of EDR, XDR, and MXDR capabilities that can adapt to each organization’s resources and needs.
Can phishing simulations be run?
Yes. Kaspersky has extended simulated phishing campaigns to Next EDR Foundations. Administrators can use templates and review reports to spot gaps in employee training.
Does Kaspersky Next Optimum protect cloud workloads?
The new Workload Security module is designed to extend protection to workloads running in cloud and hybrid environments, particularly for organizations migrating to or expanding in the cloud.

