Embedded Systems Security
All-in-one security for ATMs, POS, and legacy embedded systems — down to Windows XP.
Kaspersky Embedded Systems Security is purpose-built protection for the embedded devices we rely on every day — ATMs, POS systems, ticketing machines, medical equipment, and legacy endpoints. It delivers system hardening, opt-in anti-malware with anti-cryptor, exploit prevention, and integrity monitoring, running effectively on low-power hardware and unsupported operating systems right down to Windows XP. Faltrox deploys and manages it across your device estate.
Overview
What Embedded Systems Security is
Embedded systems are uniquely hard to secure: long lifecycles leave them running out-of-support operating systems with unpatched vulnerabilities, patching windows are constrained because devices cannot be taken offline, and many operate in public spaces exposed to physical tampering. Over half of successful attacks on embedded systems involve insider activity. Network-level defences cannot protect against direct infection of the device itself.
Kaspersky Embedded Systems Security addresses that with multilayered, low-footprint protection specifically for embedded scenarios across Windows and Linux. It hardens the system with default-deny application, device, and update controls, adds opt-in anti-malware with specialised anti-cryptor technology, prevents exploits including fileless techniques, and monitors file and registry integrity. It tolerates poor connectivity, integrates with Kaspersky MDR, and is managed from the same unified console as the rest of the stack. Faltrox operates it so legacy and modern devices alike stay protected.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
ATMs & POS Systems
Purpose-built protection for the financial and retail devices attackers most often target.
Medical Equipment
Secures medical and other continuity-critical devices that cannot be taken offline to patch.
Legacy Operating Systems
Full functionality on Windows XP through 11 — protection for systems other vendors have dropped.
Linux Embedded
The same level of protection for modern Linux-based embedded devices attackers increasingly target.
Low-Power Hardware
Built to run effectively on underpowered, outdated hardware without degrading performance.
Physical Tampering
Device controls and integrity monitoring defend against direct-access and offline manipulation.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Harden
Default-deny application, device, and update controls allow only trusted software, peripherals, and update sources to run.
- 02
Detect
Opt-in anti-malware with heuristics, ML, and specialised anti-cryptor technology detects known, unknown, and advanced threats.
- 03
Prevent Exploits
Exploit prevention counters vulnerability exploitation and fileless techniques, including attempts to sidestep Default Deny.
- 04
Monitor Integrity
File integrity, registry access, and log inspection track changes to critical resources and flag abnormal behaviour.
- 05
Manage
A unified on-premises or cloud console manages the estate, tolerates poor connectivity, and integrates with Kaspersky MDR.
Capabilities
Key capabilities
System Hardening
Application, device, and update controls permit only trusted programs, peripherals, and update sources — blocking unauthorised launches.
Opt-In Anti-Malware & Anti-Cryptor
A precise detection layer catches known, unknown, and advanced threats, with anti-cryptor technology stopping ransomware.
Exploit Prevention
Prevents exploitation of Windows components and third-party apps, countering fileless and Default-Deny-bypass attacks.
Network Threat Protection
Blocks intrusion, port scanning, and brute-force attacks that exploit network vulnerabilities on the device.
Integrity Monitoring
File integrity and registry access monitoring detect malware and direct/offline modifications to critical resources.
Legacy & Low-Power Support
Runs on outdated hardware and unsupported OSs down to Windows XP SP2, so old devices stay secure until upgraded.
Poor-Connectivity Tolerance
Remains stable and protective at very low bandwidth and through prolonged periods of no connectivity.
MDR Integration
Integrates with Kaspersky’s SOC for 24/7 monitoring, early detection, and prompt containment of sophisticated attacks.
Works with
Part of the platform
Kaspersky products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Kaspersky Embedded Systems Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Can it really protect Windows XP devices?
Yes. It runs with full functionality on Windows XP through 11, and Kaspersky continues to support Windows XP for the foreseeable future — giving you time to upgrade while keeping legacy embedded devices protected that most vendors no longer cover.
02Will it slow down low-powered embedded hardware?
No — it is built to operate effectively even on low-end, outdated hardware, and remains stable at very low bandwidth, so it suits ATMs, POS terminals, and remote devices with constrained resources and connectivity.
03How does it defend against physical tampering?
Network-level defences cannot stop direct infection of a device, so it hardens the device itself: default-deny device controls block BadUSB and unauthorised peripherals, and integrity monitoring detects direct-access and offline modifications to critical files and registry keys.
04Does it cover Linux embedded devices too?
Yes. Alongside legacy and modern Windows, it protects Linux-based embedded systems — a segment attackers increasingly target and where specialised security options are otherwise limited.
05How does compliance factor in?
Embedded devices often process financial and personal data under strict regulations. Its integrity monitoring and hardening controls are the kind of countermeasures those regulations specifically recommend, and Faltrox configures them to support your compliance obligations.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us