Installing Kaspersky Is the First Step, Not the Last
Installed is not configured, and configured is not protected. Across the Kaspersky assessments Menshen runs for Angolan organisations, about 41% of the protection already being paid for is actually switched on. The real danger is not being undefended, it is believing you are protected.
Installed is not the same as protected
Most organisations in Angola that run Kaspersky believe they are protected because the product is installed and the console shows green. In practice, installing and protecting are different things. Installing puts the agent on the machine. Protection depends on the next step: the right defences switched on, the whole estate covered, and someone watching the alerts.
When the product was never properly configured, the very signals that reassure you stop being trustworthy. No alerts: is that because there are no threats, or because nobody ever set up alerting and email integration? A green console: is everything fine, or does the console not see half the estate? No malware: is it clean, or did a poorly built policy switch off the protection that would catch it? Without a verified configuration, you have no way to tell. That is the difference between having the product and being protected.
Silence is not safety. It is what you get when the alarm was never configured.
The most dangerous state is not being undefended
It is believing you are protected while half the defences are switched off, part of the estate was never covered, and nobody is watching. That false sense of security is worse than having no protection at all, because it switches off the alarm: you do not seek help for a problem you believe is solved, you do not test a defence you assume is active, and you do not question a screen that stays green.
What the assessments keep finding
Across the assessments our certified team runs, a clear pattern repeats in very different environments, from around twenty devices to close to a thousand, and across several industry sectors.
- On average, about 41% of the protection an organisation already pays for is actually active. None passed 60%.
- In every assessment, critical protections were switched off without the team knowing.
- In every one, we found active threats left unremediated and data-protection compliance gaps.
None of this means the products are weak. It means powerful tools were deployed once and left on their defaults, while the threat landscape, the organisation, and the people managing it all moved on.
Three ways to be exposed without knowing
What the assessments measure sorts into three states, and most environments are in all three at once.
- Switched off. Components you already pay for, sitting beside a switch in the off position. Anti-ransomware, advanced remediation, and machine learning inactive, policies on their defaults, and more than once the protection itself removable without a password: any user, or any malware, could uninstall it.
- No coverage. Devices the console never saw. Machines with no agent installed, equipment discovered on the network but never verified, and mobile devices outside any policy. You cannot protect what you cannot see.
- Unwatched. Alerts sent to a mailbox nobody reads. Active threats left untreated, notifications that were never configured, and a screen that keeps showing green while the incident unfolds in silence.
Why it happens
Security software is usually installed during a project, validated on day one, and then assumed to be working. Policies are never revisited. New features that ship with later versions are never switched on. Staff change. Two years later the console still shows green, but the protection in place no longer matches the way the organisation actually works.
The regulatory weight has changed
Since 2024, Angola’s Data Protection Agency (APD) has been active in penalising inadequate security, and it has done so even where the organisation was itself the victim of an attack. The test the APD applies is whether the protective measures in place were adequate, not simply whether an incident occurred. Disabled protections and misconfigurations count against the organisation. Angola’s data-protection framework (Lei 22/11 and Lei 7/17) makes this a board-level concern, not just an IT one.
What good looks like
A licence you have already bought is worth using in full. The starting point is to measure. Menshen’s Kaspersky security assessment works through six pillars, from the state of each component to network coverage, and delivers a report with risks ranked by severity, utilisation measured pillar by pillar, and prioritised fixes. Collection takes about two hours and does not change the configuration of the environment, so operations do not stop.
From there, the path is the same one we take with any Kaspersky environment: fix what the assessment finds, build on best practice when there is a new deployment or migration, and keep the environment tuned over time. As a Kaspersky Platinum Partner with a certified team based in Angola, Menshen can tell you, quickly and concretely, the real state of your environment, and close the distance between the licence you pay for and the protection you expected.
If you want to know that real state, talk to us or write to [email protected].