Restricted software migration
Migration from Kaspersky and Dr.Web
We plan the replacement of endpoint and antivirus software while preserving required data, integrations and transition control.
Discuss your project →What the migration covers
We begin with an inventory of products, versions, servers, workstations, integrations and process owners. Inclusion in the official list is a reason to review the environment, but it does not automatically determine the target. Selection follows functional, security, operational and budget requirements.
- policies and device groups
- exceptions and scanning rules
- event logs where retention is required
- management servers and endpoint agents
How the target is selected
We create a vendor-neutral requirements matrix covering critical functions, formats, APIs, hosting, support, export and team capability. Alternatives are tested on a control set before bulk migration. No single product is presented as a universal replacement for every organisation.
Validation and handover
Validation covers asset coverage, policy updates, control detections and the absence of conflicts between old and new security agents.
Fit before scope
Is this the right starting point?
Use these criteria for an initial orientation. The final recommendation follows a review of your context, data and constraints.
A good fit when
- Software is restricted, unsupported or creates operational risk
- Data, history and integrations must be preserved
- Process and acceptance owners are available
Resolve this first when
- Only licence procurement is required without dependency analysis
- A target was selected without validating processes and data
- No one owns reconciliation and the cutover decision
A verifiable first stage
What you can use to make the next decision
The exact scope is agreed before work begins. These are typical decision artefacts, not promised business results.
Dependency inventory
Versions, users, processes, data, integrations and critical support dates.
Replacement-wave plan
Target options, sequence, parallel operation, training and rollback path.
Acceptance rules
Reconciliations, control operations and evidence your team will use to approve the result.
Five questions · no datasets or credentials
Answer first
How should you choose a replacement?
Replacing Kaspersky or Dr.Web must preserve actual security coverage, not merely install a new agent. Assets, policies, exceptions, integrations and log-retention needs are recorded first; the target environment is then tested on a control group.
Coverage
Workstations, servers and remote devices appear in one current asset register.
Management
Policies, updates, response, administrator roles and event export fit the security process.
Compatibility
The agent does not conflict with operating systems, VPN, encryption, EDR/SIEM or critical applications.
Evidence of completion: Acceptance uses the asset inventory, agent status, controlled detections and evidence that the old environment has been removed.
Support calendar
Examples from Ukraine's official list
| Product or group | Status |
|---|---|
| Kaspersky Premium / Plus / Standard | Listed |
| Kaspersky Endpoint Security | Listed |
| Dr.Web Security Space | Listed |
| Dr.Web Enterprise Security Suite | Listed |
Sources: Ukraine's State Service of Special Communications - open list, page dated 5 August 2026
Frequently asked questions
Frequently asked questions
Must everything be replaced at once?
No. Inventory defines waves based on criticality, dependencies, export feasibility and change windows.
Does listing mean a fine for every private business?
This page makes no such conclusion. Scope and obligations depend on the organisation and applicable rules. Seek qualified legal advice for a legal assessment.
How is migration completeness demonstrated?
Control samples, quantitative reconciliation, critical scenarios and an acceptance record are agreed before migration.
Ideas on this topic