What are the key advantages of Kaspersky CyberSafety for IT Online Base?
Central administration – An administrator invites staff and assigns modules.
Six modules – Malware, unwanted programs, investigation, phishing, servers, Active Directory.
Hands-on exercises – Practical tasks simulating real tools and incidents.
SCORM delivery – Runs in the cloud or your own LMS.
Module certificates – Each completed module issues a personal certificate.
Important note – Training only, includes no antivirus or agent.
Download: Kaspersky CyberSafety for IT Online Base
Six training modules – Malware, unwanted programs, investigation basics, phishing, servers, Active Directory.
Practical exercises – Each module holds four to ten hands-on exercises.
Administrator portal – Invite trainees by email and assign modules individually.
Progress statistics – Administrators track assignments, trainees see their own results.
Cloud or SCORM – Run the course hosted or inside your own LMS.
Important – No antivirus, no agent, no phishing simulation included.
Kaspersky CyberSafety for IT Online Base is a browser-based training course that teaches general IT staff and service desks first-line incident response; Kaspersky documents the same course as Cybersecurity for IT Online (CITO). Training is managed centrally, because an administrator creates trainee accounts and assigns modules, and Base marks the initial purchase rather than a renewal of an existing licence.
Closes the skills gap – Between basic awareness training and expensive expert courses.
Faster incident handover – The service desk collects evidence before it disappears.
Fewer premature all-clears – Staff stop closing suspicious tickets with a reboot.
Real tool practice – Exercises use Autoruns, Process Hacker, Nmap and Autopsy.
Paced over a year – Kaspersky recommends roughly one exercise per week.
Documented completion – A personal certificate follows each finished module.
The deciding factor is not headcount but whether you employ IT staff who handle the first look at a suspicious machine. A company whose IT is fully outsourced trains nobody with this course; a company with a service desk or two system administrators gets the most out of it.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Mostly excluded | By sector | By sector |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Own IT staff or service desk to train | Often none | ✓ | ✓ |
| This product fits | Limited | ✓ | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so the first question is whether your sector is named at all. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and that clock starts with whoever first looks at the affected machine. This course supports exactly that step: the investigation module teaches staff to collect volatile and non-volatile evidence and to read event logs instead of rebooting, which is what keeps a report factual rather than speculative. What it does not do is detect the incident, produce the telemetry, hold logs for later analysis, or file anything with BACS, and it contains no technical control that a supervisory review would count. It also does not define who inside your organisation is allowed to declare an incident, which is an organisational decision the training assumes has already been made. This is general product information and not legal advice; assess your own reporting duties with qualified advisors.
No product creates NIS 2 compliance, because the directive addresses organisations and their risk management, not the software they buy. NIS 2 requires a set of measure categories: risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, procedures to assess how well the measures work, cryptography, access control and asset management, and basic cyber hygiene together with cybersecurity training. This course maps to the training category and, in part, to incident handling, because it builds the practical skill of recognising and documenting an incident at the point where it first surfaces. It does not address risk analysis, business continuity, supply chain security, cryptography, access control or multi-factor authentication in any form, and it produces no technical evidence for the effectiveness review. The directive also expects management bodies themselves to be trained, and this course is aimed at IT staff rather than at leadership.
Germany's Federal Office for Information Security (BSI) issued a warning about Kaspersky virus protection software on 15 March 2022 and recommended replacing it with alternative products. The warning is still in force and has been governed by Section 13 of the BSI Act since 6 December 2025, following the German law implementing the NIS 2 Directive. The BSI limited the warning to the antivirus portfolio and stated that it made no assessment of other Kaspersky products, which matters here because this course installs nothing and includes no scanning engine. In the United States, the Department of Commerce issued a final determination in June 2024 that prohibits Kaspersky from providing cybersecurity and antivirus products and services to US persons, effective 29 September 2024. Kaspersky rejects the BSI warning as not based on an objective technical analysis of its software and has continued to contest it. In Switzerland, the Federal Office for Cybersecurity has issued neither a warning nor a ban and has stated that no misuse of Kaspersky software has been reported to it, leaving the decision with each organisation. In practice this affects buyers who bid for public sector contracts, who supply German or US customers, or whose group parent maintains a vendor exclusion list; for other buyers the decisive question is whether a Russian-headquartered vendor is acceptable in their supply chain documentation.
Partly, and only in one section of a typical questionnaire. It answers the items asking whether IT personnel receive role-specific security training beyond general awareness, whether that training covers incident recognition and escalation, and whether completion is documented, since a certificate is issued for each finished module and the administrator view shows who was assigned what. It does not answer anything about all-employee awareness training, phishing simulation results, endpoint protection, patch levels, encryption, multi-factor authentication, log retention, backup testing, or an information security management system, and none of those gaps can be closed by adding more trainees to this course. If the questionnaire fails on the awareness items rather than the IT items, the cheaper route is usually another product in the same Kaspersky Security Awareness family instead of a second vendor, because you keep one contract and one reporting model. If it fails on technical controls, no training product will help and you need the corresponding endpoint or management product.
The decisive difference is the audience: this course trains the people who investigate an incident, while the Automated Security Awareness Platform trains everyone who might cause one. That also decides which questionnaire items each one answers. Phishing simulation is part of the Automated Security Awareness Platform and is not part of this course, which teaches phishing analysis instead, meaning how to read a message header and remove a confirmed phishing mail from mailboxes. Companies that need both usually buy both; neither replaces the other.
| Property | Cybersecurity for IT Online | Automated Security Awareness Platform |
|---|---|---|
| Target audience | IT staff, service desk | All employees |
| Main goal | First-line incident response | Everyday cyber hygiene |
| Covers non-IT employees | ✕ | ✓ |
| Phishing simulation | ✕ | ✓ |
| Delivery | Cloud or SCORM | Cloud platform |
The current edition of the training is built around the Windows corporate environment, so teams running mainly macOS or Linux endpoints will find parts of the exercises, particularly the Active Directory and server modules, of limited use. Regional availability is restricted: the retail packages sold in this region are the European Edition, and the United States prohibition on Kaspersky cybersecurity products and services means this is not an option for organisations that must be able to supply US entities from the same contract. Trainees need internet access and the Chrome browser, and a module in progress does not save its state if the window is closed or left inactive for two hours before all sections are finished, which is worth telling people before they start a 45-minute exercise. The two limitations that most often trigger a follow-up purchase are the absence of any protection software, since this is a course and not an agent, and the absence of awareness training for non-IT employees, which is where most security questionnaires actually fail.
Each module contains between four and ten exercises, and a single exercise takes between 5 and 45 minutes. Kaspersky designs the programme to be spread across a year at roughly one exercise per week, so it is planned as continuing education rather than a one-off workshop day.
Yes. Kaspersky delivers the training either from its own cloud platform or in SCORM format. If you take the SCORM route, assignment and completion tracking live in your own LMS, which is usually the better choice when your training evidence has to come out of one system for an audit.
Kaspersky makes the training available to Kaspersky Endpoint Security Cloud Pro users directly from the Business Hub. It is otherwise independent, and buying it does not require or activate any other Kaspersky product.