KasperskyEndpoint Security

    Embedded Systems Security

    All-in-one security for ATMs, POS, and legacy embedded systems — down to Windows XP.

    Kaspersky Embedded Systems Security is purpose-built protection for the embedded devices we rely on every day — ATMs, POS systems, ticketing machines, medical equipment, and legacy endpoints. It delivers system hardening, opt-in anti-malware with anti-cryptor, exploit prevention, and integrity monitoring, running effectively on low-power hardware and unsupported operating systems right down to Windows XP. Faltrox deploys and manages it across your device estate.

    Overview

    What Embedded Systems Security is

    Embedded systems are uniquely hard to secure: long lifecycles leave them running out-of-support operating systems with unpatched vulnerabilities, patching windows are constrained because devices cannot be taken offline, and many operate in public spaces exposed to physical tampering. Over half of successful attacks on embedded systems involve insider activity. Network-level defences cannot protect against direct infection of the device itself.

    Kaspersky Embedded Systems Security addresses that with multilayered, low-footprint protection specifically for embedded scenarios across Windows and Linux. It hardens the system with default-deny application, device, and update controls, adds opt-in anti-malware with specialised anti-cryptor technology, prevents exploits including fileless techniques, and monitors file and registry integrity. It tolerates poor connectivity, integrates with Kaspersky MDR, and is managed from the same unified console as the rest of the stack. Faltrox operates it so legacy and modern devices alike stay protected.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    ATMs & POS Systems

    Purpose-built protection for the financial and retail devices attackers most often target.

    02

    Medical Equipment

    Secures medical and other continuity-critical devices that cannot be taken offline to patch.

    03

    Legacy Operating Systems

    Full functionality on Windows XP through 11 — protection for systems other vendors have dropped.

    04

    Linux Embedded

    The same level of protection for modern Linux-based embedded devices attackers increasingly target.

    05

    Low-Power Hardware

    Built to run effectively on underpowered, outdated hardware without degrading performance.

    06

    Physical Tampering

    Device controls and integrity monitoring defend against direct-access and offline manipulation.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Harden

      Default-deny application, device, and update controls allow only trusted software, peripherals, and update sources to run.

    2. 02

      Detect

      Opt-in anti-malware with heuristics, ML, and specialised anti-cryptor technology detects known, unknown, and advanced threats.

    3. 03

      Prevent Exploits

      Exploit prevention counters vulnerability exploitation and fileless techniques, including attempts to sidestep Default Deny.

    4. 04

      Monitor Integrity

      File integrity, registry access, and log inspection track changes to critical resources and flag abnormal behaviour.

    5. 05

      Manage

      A unified on-premises or cloud console manages the estate, tolerates poor connectivity, and integrates with Kaspersky MDR.

    Capabilities

    Key capabilities

    System Hardening

    Application, device, and update controls permit only trusted programs, peripherals, and update sources — blocking unauthorised launches.

    Opt-In Anti-Malware & Anti-Cryptor

    A precise detection layer catches known, unknown, and advanced threats, with anti-cryptor technology stopping ransomware.

    Exploit Prevention

    Prevents exploitation of Windows components and third-party apps, countering fileless and Default-Deny-bypass attacks.

    Network Threat Protection

    Blocks intrusion, port scanning, and brute-force attacks that exploit network vulnerabilities on the device.

    Integrity Monitoring

    File integrity and registry access monitoring detect malware and direct/offline modifications to critical resources.

    Legacy & Low-Power Support

    Runs on outdated hardware and unsupported OSs down to Windows XP SP2, so old devices stay secure until upgraded.

    Poor-Connectivity Tolerance

    Remains stable and protective at very low bandwidth and through prolonged periods of no connectivity.

    MDR Integration

    Integrates with Kaspersky’s SOC for 24/7 monitoring, early detection, and prompt containment of sophisticated attacks.

    Works with

    Part of the platform

    Kaspersky products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Kaspersky Embedded Systems Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Can it really protect Windows XP devices?

    Yes. It runs with full functionality on Windows XP through 11, and Kaspersky continues to support Windows XP for the foreseeable future — giving you time to upgrade while keeping legacy embedded devices protected that most vendors no longer cover.

    02Will it slow down low-powered embedded hardware?

    No — it is built to operate effectively even on low-end, outdated hardware, and remains stable at very low bandwidth, so it suits ATMs, POS terminals, and remote devices with constrained resources and connectivity.

    03How does it defend against physical tampering?

    Network-level defences cannot stop direct infection of a device, so it hardens the device itself: default-deny device controls block BadUSB and unauthorised peripherals, and integrity monitoring detects direct-access and offline modifications to critical files and registry keys.

    04Does it cover Linux embedded devices too?

    Yes. Alongside legacy and modern Windows, it protects Linux-based embedded systems — a segment attackers increasingly target and where specialised security options are otherwise limited.

    05How does compliance factor in?

    Embedded devices often process financial and personal data under strict regulations. Its integrity monitoring and hardening controls are the kind of countermeasures those regulations specifically recommend, and Faltrox configures them to support your compliance obligations.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us